Live data from Hacker News

Flashback trojan reportedly controls half a million Macs and counting

arstechnica.com

51–60 of 125 posts

Re: Flashback trojan reportedly controls half a million Macs and counting

#51
post #26

Earlier quoted context omitted.

I don't think small market share was ever really a reason that Mac OS X didn't get traditional viruses. UNIX-based servers have always had a huge market share, and since servers are presumably a more desirable target of infection and cracking than home computers are, we would have seen traditional viruses hit UNIX machines a long time ago if it were realistically doable. Also, before Mac OS X became as popular as it…

This virus spreads from visiting malicious websites or websites with malicious ads. Since not much browsing happens on servers, there is no reason to target them. >lso, before Mac OS X became as popular as it is now, there were lots of Windows users who hated Apple fanboys and would have loved to write a wide-spread virus that targeted Mac OS X if possible What? Does that mean that some Windows viruses were written b…

> This virus spreads from visiting malicious websites or websites with malicious ads. Since not much browsing happens on servers, there is no reason to target them.

Servers have a lot more information (thousands of credit cards, email addresses, passwords, etc.) than desktops. Criminals who seek personal gain rather than just mayhem would target servers.

> Does that mean that some Windows viruses were written by Mac fanboys to make Windows look bad?

No. To use sociological terms, Windows was the dominate group, Mac OS X the subordinate. When Mac OS X was starting to come into vogue in the first half of the 2000s, there were many fanboys that kept bragging about how their computers were infinitely better than "PCs", and everyone who grew up in the 90s and 2000s has surely had conversations with Windows users, often gamers or early /b/ users, who had almost a religious vitriolic hatred towards every aspect of Apple--Mac OS X, Mac computers, fanboys, "one-button mice", etc. Now that Mac OS X is accepted as a well designed OS, those fanboys and that hatred seem to be much less visible, although now lots of people dislike Apple for becoming the new Microsoft with regards to patent lawsuits, but I digress. The point is that whenever such vitriol exists, there are people dying to prove that they're right, in this case that Mac OS X wasn't immune to viruses like the "mactards" (that's one of the terms they called Apple fanboys) claimed. Did you really not witness this phenomenon of hatred in the early 2000s?

> How? Can you explain what you mean by Windows having a unique vulnerability that is not present on a Mac?

Mac OS X is essentially the Aqua window system atop Darwin, the OS's underlying system that descends from FreeBSD. As a form of UNIX, it does not give non-root users direct kernel access. Windows doesn't have this very logical restriction, and more and more ways are discovered to exploit this. Windows Vista and 7 have tried to mend this flawed infrastructure by asking users to explicitly authorize everything, but we all know how that's worked out.

> Again, this is a drive by exploit from a web page, not social engineering.

Escalation was allowed from the JRE vulnerability, but it was my understanding that initial authorization had to be given to run it. Edit: I just reread the article and it appears that this was a self-installing trojan. If that's the case, that certainly shows that vulnerabilities that allow self-installation as opposed to just privilege escalation do show up in Mac OS X from time to time, but from my limited experience, the main way to make use of trojans targeting Mac OS X is to use social engineering to install them (e.g. take advantage of the fact that Finder hides file extensions by default, and then change an executable's icon to that of an image, and then preserve the metadata in an archive) and then take advantage of a security vulnerability that allows privilege escalation. Such vulnerabilities are incredibly rare in Mac OS X since unlike Windows, kernel space is isolated from users.

Re: Flashback trojan reportedly controls half a million Macs and counting

#52

Earlier quoted context omitted.

Whoa, no kidding. The majority of people are not going to stop on those two letters and consciously differentiate "virus" from "PC virus."

"A Mac isn’t susceptible to the thousands of viruses plaguing Windows-based computers." Pretty clear.

It's not at all clear. It's deliberately ambiguous. If they wanted it to be clear they would have said "Macs are only susceptible to a fraction of the number of viruses plaguing Windows-based computers."

Re: Flashback trojan reportedly controls half a million Macs and counting

#53

Earlier quoted context omitted.

Viruses are not a fact of life for Mac users. Neither are trojans, and that is exactly why this trojan has manifested so successfully. Windows users are mostly hardened to the basic threats of the internet (don't open a random exe etc), and are cognizant of the reality that malicious software does target them. Non-technical Mac users have been lulled into a false sense of security that will eventually make them a mor…

I've done ~15 Windows reinstalls in the last few years, and every single one of them was malware masquerading as anti-virus software. OSX's reputation may make Mac users feel invincible, but Windows users' knowledge of their vulnerability opens them to pretty effective scare tactics. In fact, it hit my house twice, and I'm not exactly incompetent: Win7, Security Essentials, kept on top of Windows Update, no admin pri…

I've done ~15 Windows reinstalls in the last few years

So what? I've reinstalled Windows three times since Windows 7, and it's never been due to a virus. The last company I worked at was a Windows shop that also had 0 malware problems. Anecdotes are pointless in this discussion.

I didn't know about that until I was in the room while my brother was using the machine and I saw a dialog that looked an awful lot like Windows reminding you to install AV but not quite right. No way anyone else would have noticed that the background gradient was just a bit off.

Yes, your brother was the victim of a social engineering attack, the exact technique used to infect these Mac users. Windows systems aren't inherently less secure, and every terrible ailment described in your post is the result of voluntary action taken by the user.

I don't have statistics, but if you're going to claim OSX has fallen as far as Windows in terms of infection rate, I think the burden is on you to show some data.

No. The onus is on you to demonstrate how Windows 7 is inherently less secure than OSX. You're making vague assertions about how Windows is less secure but you haven't given specific examples of why that is true, only anecdotes that anyone can counter (or bolster) with personal exeprience.

The bottom line is, short of 0-days, both systems are equally secure.

Re: Flashback trojan reportedly controls half a million Macs and counting

#54
post #22

Earlier quoted context omitted.

My guess is it will be a 3 ghz quad-core android phone that docks on your monitor & wirelessly connects to everything else.

At the risk of perhaps angering the Linux community here (I work on a Linux box too), may I suggest that's where Windows 8/WP7 is going? And at further risk of anger, I will suggest that Android has reached its peak. Evidence for point 1: Windows has such a large base of "desktop" applications with a larger base of active developers. Not only that, the majority of the world uses their standards for word processing, s…

> Windows has such a large base of "desktop" applications

Unfortunately, Windows 8 tablets and the hypothetical Windows 8 phone that turns into a full desktop when you hook it into a monitor will both run on the ARM architecture. These are not binary compatible with existing Windows executables.[1] This means that any advantage that Windows has in quantity of applications does not translate to new types of devices. When it comes to phones and tablets, unless Windows gets the market share first, there will not be (m)any "killer apps" for the new platform that aren't first-party Microsoft apps. I'm not sure that Microsoft Office is important enough on mobile devices to convince everyone to switch.

The largest advantage that Windows traditionally had (almost all the apps are written for it) is gone as soon as you make the switch to ARM.[1]

[1] https://en.wikipedia.org/wiki/Windows_8#Software_compatibili...

Re: Flashback trojan reportedly controls half a million Macs and counting

#55

Earlier quoted context omitted.

Whoa, no kidding. The majority of people are not going to stop on those two letters and consciously differentiate "virus" from "PC virus."

"A Mac isn’t susceptible to the thousands of viruses plaguing Windows-based computers." Pretty clear.

Clear? One possible interpretation of just that statement alone could easily give the impression that viruses in general are therefore not an issue for Macs.

Re: Flashback trojan reportedly controls half a million Macs and counting

#56
post #42
post #9

Earlier quoted context omitted.

Didn't Apple used to claim that Macs didn't get viruses? I can't remember. (This would be at least several years ago, when Mac malware was still fully theoretical.) It's possible they never stated it directly, and the phrase was spread by fans. To be fair, their slogan is currently "Macs don't get PC viruses" [1]. Which is true. Although, devilishly close enough to blur the two in somebody's mind. [1] http://www.appl…

Given that macs are PCs, being personal computers, it's not true that macs don't get PC viruses.

I believe "PC" has historically meant (or often been used to imply) "IBM PC compatible" (http://en.wikipedia.org/wiki/IBM_PC_compatible) which Apple/Mac was not, until they switched to x86.

Re: Flashback trojan reportedly controls half a million Macs and counting

#57
post #37

Of note — if Java is the attack vector, new Macs were not vulnerable by default as they don’t ship with Java installed anymore a/o 10.7 Lion. AFAIK, the biggest reason anyone would have Java is if you’re running Adobe products.

Or LibreOffice, or Eclipse, or...

Java is plenty widespread. It's a good bet that most systems are going to end up with a JVM on disk somewhere after 6 mo - 1 yr of usage.

Re: Flashback trojan reportedly controls half a million Macs and counting

#58
post #5

Earlier quoted context omitted.

The interesting part is that I still haven't seen one traditional "virus" — even is thing appears to still be just social engineering users to install it, by pretending to be Flash Player. I can't imagine it's that much more difficult to actually find an OS X vulnerability to propagate with, but I still haven't seen any. Edit: It appears this uses a Java vulnerability, rather than the fake-Flash Player-installer that…

And almost no Windows "malware" in the last decade has been a traditional "virus" either. Trojans, social engineering, all so much easier.

I would consider the series of Sasser and Bagle worms during 2004 to be a traditional virus.

Re: Flashback trojan reportedly controls half a million Macs and counting

#59
post #51

Earlier quoted context omitted.

This virus spreads from visiting malicious websites or websites with malicious ads. Since not much browsing happens on servers, there is no reason to target them. >lso, before Mac OS X became as popular as it is now, there were lots of Windows users who hated Apple fanboys and would have loved to write a wide-spread virus that targeted Mac OS X if possible What? Does that mean that some Windows viruses were written b…

> This virus spreads from visiting malicious websites or websites with malicious ads. Since not much browsing happens on servers, there is no reason to target them. Servers have a lot more information (thousands of credit cards, email addresses, passwords, etc.) than desktops. Criminals who seek personal gain rather than just mayhem would target servers. > Does that mean that some Windows viruses were written by Mac…

> Such vulnerabilities are incredibly rare in Mac OS X since unlike Windows, kernel space is isolated from users.

That's just flat wrong and hasn't been true for an OS Microsoft has supported for mainstream use since 2003 [1]. Windows XP and all current Windows releases are based on the protected NT kernel which debuted in 1993 (with Windows NT 3.1). In fact, Microsoft and Apple stopped shipping OSes with unprotected kernels in the same year (2001) with Windows XP and OS X "Cheetah", respectively.

Look, Microsoft has made a lot of mistakes with respect to security (bad defaults, running as Administrator too often, too many low-level bugs, ...). Since OS X, Apple has had a much better security track record. That's why it is so frustrating to see people criticize Microsoft for mistakes they fixed a long time ago instead of focusing on current (or at least recent) issues.

[1] When Microsoft downgraded Windows 98/98SE/ME to paid support and critical security fixes only: http://support.microsoft.com/gp/lifean18

Re: Flashback trojan reportedly controls half a million Macs and counting

#60

Earlier quoted context omitted.

I've done ~15 Windows reinstalls in the last few years, and every single one of them was malware masquerading as anti-virus software. OSX's reputation may make Mac users feel invincible, but Windows users' knowledge of their vulnerability opens them to pretty effective scare tactics. In fact, it hit my house twice, and I'm not exactly incompetent: Win7, Security Essentials, kept on top of Windows Update, no admin pri…

I've done ~15 Windows reinstalls in the last few years So what? I've reinstalled Windows three times since Windows 7, and it's never been due to a virus. The last company I worked at was a Windows shop that also had 0 malware problems. Anecdotes are pointless in this discussion. I didn't know about that until I was in the room while my brother was using the machine and I saw a dialog that looked an awful lot like Win…

You are constraining your discussing to Windows 7. I am not. XP may have disappeared from the life of a non-corporate programmer, it's still everywhere for me. Hence the impedance mismatch. Most of our shop's customers did not see a business need to upgrade, and acquaintances that can afford to buy new computers while their old ones are still running (however poorly) tend to be Mac users anyway.

>every terrible ailment described in your post is the result of voluntary action taken by the user.

No, it was a remote Java exploit. The dialog was to get you to pay for it after it had already installed.

The point is that despite all this talk about OSX viruses, malware is still not a part of day-to-day life with Macs to anywhere near the extent it is with Windows (when you include XP).

Post reply on HN