Live data from Hacker News

Mac malware evolves to no longer require users to enter their password

nakedsecurity.sophos.com

31–40 of 49 posts

Re: Mac malware evolves to no longer require users to enter their password

#31
I believe only a recent Windows emigrant would fall for the "your computer is infected" trick.

Oh, and wow! It evolved and now installs in a part of the system that makes the malware easily detectable and removable.

I wonder what Sophos is trying to sell... Oh yes! Anti-malware for a platform that really doesn't need it nearly as badly as that other competing platform.

Flagged because it's actually an ad.

Re: Mac malware evolves to no longer require users to enter their password

#32
Just to be clear, the article is written by someone associated with Sophos, a commercial anti-malware firm. ClamXav for Mac OS X is free, the engine is open source, it has regular malware definition updates, and monitors any directory or directories the user specifies. Well written, powerful, open source, free software. www.clamxav.com

Re: Mac malware evolves to no longer require users to enter their password

#34
Without wanting to sound condescending, I'm not sure that the average Mac user is sophisticated enough (in terms of technical expertise) to detect interaction that has been initiated by malware.

So many years of being told that there's no such thing as malware for OSX (and so no need for anti-malware) may have produced fertile ground for it. Of all the people with Macs I know, just one has an anti-virus installed.

Re: Mac malware evolves to no longer require users to enter their password

#36
post #30

* Requires user interaction, so it doesn't count. * Doesn't work if you aren't an admin. * The OS is just installing what the user agreed to install. Seems like Mac users are regurgitating Windows users' excuses from years ago. It's a problem. Rather than make excuses, we should be expecting Apple and others to be actively working toward a solution.

If I trick a GNU/Linux or UNIX user into running a "sudo rm -rf /" command and entering a password, did I create malware?

No, you didn't create software, but you effectively distributed a trojan.

Re: Mac malware evolves to no longer require users to enter their password

#37
post #29

* Requires user interaction, so it doesn't count. * Doesn't work if you aren't an admin. * The OS is just installing what the user agreed to install. Seems like Mac users are regurgitating Windows users' excuses from years ago. It's a problem. Rather than make excuses, we should be expecting Apple and others to be actively working toward a solution.

So, you expect the operating system do disobey the user when it determines the user actions could be harmful? If I tell my machine to do something, I want it to carry my orders.

>If I tell my machine to do something, I want it to carry my orders.

I downloaded this 'Free Screensaver Pack' and I want to run it! Who does this virus scanner think it is? Quit telling me that its a bad idea and just goddamn do what I want you to.

If bad software exists I don't want my computer to warn me that it might be a bad idea to run it, I'd rather apple just creates a walled garden so I can don't even have the option to command my computer to do something bad.

Re: Mac malware evolves to no longer require users to enter their password

#38
post #24
post #9

Earlier quoted context omitted.

Security experts generally agree that there are more exploits on Mac. It's easier to run arbitrary code without permission. The only thing is, nobody has bothered to write that code yet.

One question that is worth asking is how many of these exploits can be done remotely, and how many of these exploits require physical permission to a system? It is worth noting that there is a difference between exploits that require physical access and those that can be conducted remotely. Speaking just for myself, I am not certain which operating system is more or less secure, but I do not think that operating syst…

Many of them can be done remotely, as has been done at Pwn20wn for several years on OSX.

But to actually create a weaponized attack that can get on a lot of machines requires a fair bit of work. If you're going to do that, it's probably worth going the extra mile and attacking a much larger installed user base.

But, what's even easier is just doing malware that the user installs. You can write it in a fraction of the time, and you probably get similar infection rates.

Re: Mac malware evolves to no longer require users to enter their password

#39
post #11

In other words: it still falls into the "you have to be stupid enough to allow total strangers behind the wheel of your car" category, they just don't need you to hand over the keys anymore. Got it. Stupidity is not a problem that can be solved through technology. At least Apple now has a service to protect stupid people against themselves, it's called the "App Store". You know, with the kind of approval system we've…

Stupidity is not a problem that can be solved through technology.

My reaction is: Never say Never.

However, if you are going to try and solve stupidity through technological or scientific means, beware. A half-baked understanding of science can be a dangerous thing.

Example: At Enron, the policy was to fire those who evaluated in the bottom 10% of the company. Jeffrey Skilling thought he was using the miraculous power of evolution to create a company of super-employees. What he actually did was to create a company of those skilled at gaming the system.

This was like another attempt to evolve chickens to be super egg-layers. Instead of increasing the egg-laying of the whole population, only the egg laying of the dominant females was increased and overall productivity was decreased.

http://lesswrong.com/lw/l8/conjuring_an_evolution_to_serve_y...

Re: Mac malware evolves to no longer require users to enter their password

#40
post #29

* Requires user interaction, so it doesn't count. * Doesn't work if you aren't an admin. * The OS is just installing what the user agreed to install. Seems like Mac users are regurgitating Windows users' excuses from years ago. It's a problem. Rather than make excuses, we should be expecting Apple and others to be actively working toward a solution.

So, you expect the operating system do disobey the user when it determines the user actions could be harmful? If I tell my machine to do something, I want it to carry my orders.

These are the same arguments Windows users used for years, and Linux and Mac users mocked them for it.

Regardless, you've presented a false dichotomy. That the only way to combat the risk is to prevent users from using their operating system as they see fit. That's not what I suggested, at all, and trying to frame an argument around it is dishonest.

Post reply on HN