Live data from Hacker News

Mac malware evolves to no longer require users to enter their password

nakedsecurity.sophos.com

41–49 of 49 posts

Re: Mac malware evolves to no longer require users to enter their password

#41
post #37
post #29

Earlier quoted context omitted.

So, you expect the operating system do disobey the user when it determines the user actions could be harmful? If I tell my machine to do something, I want it to carry my orders.

>If I tell my machine to do something, I want it to carry my orders. I downloaded this 'Free Screensaver Pack' and I want to run it! Who does this virus scanner think it is? Quit telling me that its a bad idea and just goddamn do what I want you to. If bad software exists I don't want my computer to warn me that it might be a bad idea to run it, I'd rather apple just creates a walled garden so I can don't even have t…

The problem is, people confuse prevention and warning. They complain about the exception, rather than the rule. Oddly, I see few complaints about browsing implementing phishing site protection and warnings about bad SSL certs, etc. After all, the browser should just take me to where I want to go and shouldn't get in the way. Right? =)

Re: Mac malware evolves to no longer require users to enter their password

#42
post #29

Earlier quoted context omitted.

So, you expect the operating system do disobey the user when it determines the user actions could be harmful? If I tell my machine to do something, I want it to carry my orders.

These are the same arguments Windows users used for years, and Linux and Mac users mocked them for it. Regardless, you've presented a false dichotomy. That the only way to combat the risk is to prevent users from using their operating system as they see fit. That's not what I suggested, at all, and trying to frame an argument around it is dishonest.

Nothing will protect a computer from a determined user. The OS may even warn the user the action he is about to take can harm the computer, but the decision rests with the user.

What you can do is to keep ZFS-like file snapshots and allow the user to return to a moment in time previous to the infection.

Re: Mac malware evolves to no longer require users to enter their password

#43
post #30

* Requires user interaction, so it doesn't count. * Doesn't work if you aren't an admin. * The OS is just installing what the user agreed to install. Seems like Mac users are regurgitating Windows users' excuses from years ago. It's a problem. Rather than make excuses, we should be expecting Apple and others to be actively working toward a solution.

If I trick a GNU/Linux or UNIX user into running a "sudo rm -rf /" command and entering a password, did I create malware?

No, modern rm implementations disallow that by default. You need to override it with a switch.

Re: Mac malware evolves to no longer require users to enter their password

#44
post #42

Earlier quoted context omitted.

These are the same arguments Windows users used for years, and Linux and Mac users mocked them for it. Regardless, you've presented a false dichotomy. That the only way to combat the risk is to prevent users from using their operating system as they see fit. That's not what I suggested, at all, and trying to frame an argument around it is dishonest.

Nothing will protect a computer from a determined user. The OS may even warn the user the action he is about to take can harm the computer, but the decision rests with the user. What you can do is to keep ZFS-like file snapshots and allow the user to return to a moment in time previous to the infection.

> Nothing will protect a computer from a determined user.

But their are numerous things you can do to protect a computer from your average user. Not doing these things because of exceptions is wrong.

Re: Mac malware evolves to no longer require users to enter their password

#45
post #42

Earlier quoted context omitted.

Nothing will protect a computer from a determined user. The OS may even warn the user the action he is about to take can harm the computer, but the decision rests with the user. What you can do is to keep ZFS-like file snapshots and allow the user to return to a moment in time previous to the infection.

> Nothing will protect a computer from a determined user. But their are numerous things you can do to protect a computer from your average user. Not doing these things because of exceptions is wrong.

I think we would be more productive if we focused our energy on educating the users instead of disobeying them.

Re: Mac malware evolves to no longer require users to enter their password

#46
post #45

Earlier quoted context omitted.

> Nothing will protect a computer from a determined user. But their are numerous things you can do to protect a computer from your average user. Not doing these things because of exceptions is wrong.

I think we would be more productive if we focused our energy on educating the users instead of disobeying them.

Abstinence-only eduction v.s education and protection. Right. Good policy.

Re: Mac malware evolves to no longer require users to enter their password

#47
post #45

Earlier quoted context omitted.

I think we would be more productive if we focused our energy on educating the users instead of disobeying them.

Abstinence-only eduction v.s education and protection. Right. Good policy.

I never said protection should be abandoned. I said education is more important because it allows users to use protective measures correctly.

And may render a lot of protective measures unnecessary.

Re: Mac malware evolves to no longer require users to enter their password

#48
post #47

Earlier quoted context omitted.

Abstinence-only eduction v.s education and protection. Right. Good policy.

I never said protection should be abandoned. I said education is more important because it allows users to use protective measures correctly. And may render a lot of protective measures unnecessary.

> I never said protection should be abandoned.

It didn't sound like it.

Education is great. However, no amount of education will remove the need for real protections. This doesn't mean you disobey a you keep trying to suggest.

Look to the real world of examples. Education doesn't trump protection. Take anything you need to pass a test for or need a license for. Their are still protections put into place to prevent abuse. Hunting license, gun license, driver's license. All have protections on top of education because people make mistakes.

Finally, quit trying to suggest that protection means it prevents a user from doing what they want. Again, it's a false dichotomy and continuously trying to argue it devalues any point you are trying to make.

Re: Mac malware evolves to no longer require users to enter their password

#49
post #47

Earlier quoted context omitted.

I never said protection should be abandoned. I said education is more important because it allows users to use protective measures correctly. And may render a lot of protective measures unnecessary.

> I never said protection should be abandoned. It didn't sound like it. Education is great. However, no amount of education will remove the need for real protections. This doesn't mean you disobey a you keep trying to suggest. Look to the real world of examples. Education doesn't trump protection. Take anything you need to pass a test for or need a license for. Their are still protections put into place to prevent ab…

> it prevents a user from doing what they want

Have you ever seen a false positive report from an anti-malware application? I have.

Post reply on HN