Live data from Hacker News

Mac malware evolves to no longer require users to enter their password

nakedsecurity.sophos.com

11–20 of 49 posts

Re: Mac malware evolves to no longer require users to enter their password

#11
In other words: it still falls into the "you have to be stupid enough to allow total strangers behind the wheel of your car" category, they just don't need you to hand over the keys anymore. Got it.

Stupidity is not a problem that can be solved through technology.

At least Apple now has a service to protect stupid people against themselves, it's called the "App Store". You know, with the kind of approval system we've all been bitching about.

As far as I'm concerned, self-inflicted malware is about as big a security issue as running with scissors. To treat it as some external force that needs to be dealt with by manufacturers, OS-makers, anti-virus producers or even legislators just perpetuates the real problem, turning it into a perpetual arms race that can not possibly be won, but at some point may cost us the freedom to install anything we want on our computers.

Re: Mac malware evolves to no longer require users to enter their password

#12
post #11

In other words: it still falls into the "you have to be stupid enough to allow total strangers behind the wheel of your car" category, they just don't need you to hand over the keys anymore. Got it. Stupidity is not a problem that can be solved through technology. At least Apple now has a service to protect stupid people against themselves, it's called the "App Store". You know, with the kind of approval system we've…

Exactly, Mac users have so far been very safe from actual virusses and worms, and other malicious stuff sneaking onto your computer through security holes, however, this type is something you can't do anything against. It's the user consciously downloading and running a program.

For this type of inexperienced users Symantec and McAfee make Mac products.

Re: Mac malware evolves to no longer require users to enter their password

#13
post #10

Earlier quoted context omitted.

Right, but the point of this article is that it no longer needs the admin password. If you're running in a non-admin account (like I am), it'll still need the password, and thus user interaction, so it'll be trivial to stop.

Even without the password you still need user interaction, the user has to click next multiple times during install.

True. Somewhere I thought I read that the installer ran without user interaction in this variant, but thinking about it, that doesn't make much sense.

Though, if you're concerned about having to give an admin password (as evidently some people are), running in a non-admin account would solve that. (Also, if you have write privileges to /Applications, it's possible to write a script overwriting the contents of a trusted executable with malicious code, but that isn't how this works so it's slightly irrelevant.)

Re: Mac malware evolves to no longer require users to enter their password

#15
post #11

In other words: it still falls into the "you have to be stupid enough to allow total strangers behind the wheel of your car" category, they just don't need you to hand over the keys anymore. Got it. Stupidity is not a problem that can be solved through technology. At least Apple now has a service to protect stupid people against themselves, it's called the "App Store". You know, with the kind of approval system we've…

[deleted]

Re: Mac malware evolves to no longer require users to enter their password

#16
post #12
post #11

In other words: it still falls into the "you have to be stupid enough to allow total strangers behind the wheel of your car" category, they just don't need you to hand over the keys anymore. Got it. Stupidity is not a problem that can be solved through technology. At least Apple now has a service to protect stupid people against themselves, it's called the "App Store". You know, with the kind of approval system we've…

Exactly, Mac users have so far been very safe from actual virusses and worms, and other malicious stuff sneaking onto your computer through security holes, however, this type is something you can't do anything against. It's the user consciously downloading and running a program. For this type of inexperienced users Symantec and McAfee make Mac products.

Just as a thought: if there was an "Only run Mac App Store-distributed applications" switch somewhere in OSX's System Preferences, off by default, I know several people for whom I (as their tech-guy-cum-sysadmin) would flip it on in a heartbeat, and then never likely hear about this particular flavor of PEBKAC again.

Re: Mac malware evolves to no longer require users to enter their password

#18
I like how they make it look like a passive process, except for the fact that at every screen shot you would have to run the application or click "next". This is social engineering. You were tricked into installing it. There's not way to stop that if it's an open system.

Re: Mac malware evolves to no longer require users to enter their password

#19
* Requires user interaction, so it doesn't count.

* Doesn't work if you aren't an admin.

* The OS is just installing what the user agreed to install.

Seems like Mac users are regurgitating Windows users' excuses from years ago.

It's a problem. Rather than make excuses, we should be expecting Apple and others to be actively working toward a solution.

Re: Mac malware evolves to no longer require users to enter their password

#20
post #16
post #12

Earlier quoted context omitted.

Exactly, Mac users have so far been very safe from actual virusses and worms, and other malicious stuff sneaking onto your computer through security holes, however, this type is something you can't do anything against. It's the user consciously downloading and running a program. For this type of inexperienced users Symantec and McAfee make Mac products.

Just as a thought: if there was an "Only run Mac App Store-distributed applications" switch somewhere in OSX's System Preferences, off by default, I know several people for whom I (as their tech-guy-cum-sysadmin) would flip it on in a heartbeat, and then never likely hear about this particular flavor of PEBKAC again.

System preferences > accounts > parental controls > limit programs > allow app-store programs > all

Deny all the rest.

Post reply on HN