Live data from Hacker News

Flashback trojan reportedly controls half a million Macs and counting

arstechnica.com

61–70 of 125 posts

Re: Flashback trojan reportedly controls half a million Macs and counting

#61

I seriously doubt that 600,000 macs were infected... How do we know this number is correct? Because a completely unknown security firm that sells Mac antivirus software ("Dr. Web", a russian antivirus company) tweeted about it!

Fair enough, with one caveat: Everyone who trumpets security/anti-virus company press releases about Android should be required to shout about 600k Macs just as loudly. I wonder how many will.

Re: Flashback trojan reportedly controls half a million Macs and counting

#62

Earlier quoted context omitted.

I've done ~15 Windows reinstalls in the last few years, and every single one of them was malware masquerading as anti-virus software. OSX's reputation may make Mac users feel invincible, but Windows users' knowledge of their vulnerability opens them to pretty effective scare tactics. In fact, it hit my house twice, and I'm not exactly incompetent: Win7, Security Essentials, kept on top of Windows Update, no admin pri…

I've done ~15 Windows reinstalls in the last few years So what? I've reinstalled Windows three times since Windows 7, and it's never been due to a virus. The last company I worked at was a Windows shop that also had 0 malware problems. Anecdotes are pointless in this discussion. I didn't know about that until I was in the room while my brother was using the machine and I saw a dialog that looked an awful lot like Win…

Your attempts at maintaining blissful ignorance of the probability of attack are very sweet and your final sentence could perhaps hold up as logically holding some water (I'd argue that you, like the poster to whom you are replying, have taken a very narrow view to support your position) ...the fact is that in practice and for the average user your assertion is flat out false.

Re: Flashback trojan reportedly controls half a million Macs and counting

#63
post #30

Earlier quoted context omitted.

And almost no Windows "malware" in the last decade has been a traditional "virus" either. Trojans, social engineering, all so much easier.

I disagree. Visiting a malicious website or opening an email that exploits a vulnerability in your os or software is very common.

Citation? The last thing along those lines I'd heard of was the PNG(?) exploit.

Re: Flashback trojan reportedly controls half a million Macs and counting

#64
Apple includes a lot of third-party software in OS X, and if they don't start patching those packages as promptly as the software maintainers do, exploiting these non-Apple or open source packages could become a common strategy. Attackers can watch other platforms roll out updates before Apple and then target the same software in OS X. Not that the same vulnerabilites will always work, but it's certainly a worry.

This particular exploit is not a great example, since they removed Java by default. But all the other cross-platform software that is included is worrisome if not prompty updated.

Re: Flashback trojan reportedly controls half a million Macs and counting

#65
post #59
post #51

Earlier quoted context omitted.

> This virus spreads from visiting malicious websites or websites with malicious ads. Since not much browsing happens on servers, there is no reason to target them. Servers have a lot more information (thousands of credit cards, email addresses, passwords, etc.) than desktops. Criminals who seek personal gain rather than just mayhem would target servers. > Does that mean that some Windows viruses were written by Mac…

> Such vulnerabilities are incredibly rare in Mac OS X since unlike Windows, kernel space is isolated from users. That's just flat wrong and hasn't been true for an OS Microsoft has supported for mainstream use since 2003 [1]. Windows XP and all current Windows releases are based on the protected NT kernel which debuted in 1993 (with Windows NT 3.1). In fact, Microsoft and Apple stopped shipping OSes with unprotected…

That can't be true. If NT-based versions of Windows implemented a system call mechanism that protected the kernel from users, XP wouldn't have been ridden with viruses, and there would have been no purpose in giving Vista and 7 the access control mechanism to warn users of potentially harmful system calls. By the way, Cheatah just refers to the original Mac OS X. Your phrasing "stopped shipping OSes with unprotected kernels ... [starting with] Cheetah" makes it sound like Mac OS X initially didn't have this protection, which is not the case.

Re: Flashback trojan reportedly controls half a million Macs and counting

#66

Earlier quoted context omitted.

Whoa, no kidding. The majority of people are not going to stop on those two letters and consciously differentiate "virus" from "PC virus."

"A Mac isn’t susceptible to the thousands of viruses plaguing Windows-based computers." Pretty clear.

No, it's not clear. It implies that the Mac can't get any viruses.

Re: Flashback trojan reportedly controls half a million Macs and counting

#67
post #37

Of note — if Java is the attack vector, new Macs were not vulnerable by default as they don’t ship with Java installed anymore a/o 10.7 Lion. AFAIK, the biggest reason anyone would have Java is if you’re running Adobe products.

Or LibreOffice, or Eclipse, or... Java is plenty widespread. It's a good bet that most systems are going to end up with a JVM on disk somewhere after 6 mo - 1 yr of usage.

I don’t know — those aren’t apps normal people install.

(And: The same people who install Eclipse, Minecraft, LibreOffice, or Photoshop are also more likely to have one of the apps that Flashback avoids co-habitating with: Little Snitch, Xcode, etc.)

Re: Flashback trojan reportedly controls half a million Macs and counting

#68
post #56
post #42

Earlier quoted context omitted.

Given that macs are PCs, being personal computers, it's not true that macs don't get PC viruses.

I believe "PC" has historically meant (or often been used to imply) "IBM PC compatible" ( http://en.wikipedia.org/wiki/IBM_PC_compatible ) which Apple/Mac was not, until they switched to x86.

The problem is that viruses don't relate to the architecture - otherwise linux and *bsd (on the x86 platform) would have also been windows-like with their malware.

I know I'm playing semantic games here, but so is Apple with this slogan :)

Re: Flashback trojan reportedly controls half a million Macs and counting

#69
post #64

Apple includes a lot of third-party software in OS X, and if they don't start patching those packages as promptly as the software maintainers do, exploiting these non-Apple or open source packages could become a common strategy. Attackers can watch other platforms roll out updates before Apple and then target the same software in OS X. Not that the same vulnerabilites will always work, but it's certainly a worry. Thi…

That's a good observation. Avoiding GPL3 software, like newer versions of bash and gcc, might have the unintended consequence of putting their users at risk.

Re: Flashback trojan reportedly controls half a million Macs and counting

#70

Earlier quoted context omitted.

I've done ~15 Windows reinstalls in the last few years So what? I've reinstalled Windows three times since Windows 7, and it's never been due to a virus. The last company I worked at was a Windows shop that also had 0 malware problems. Anecdotes are pointless in this discussion. I didn't know about that until I was in the room while my brother was using the machine and I saw a dialog that looked an awful lot like Win…

You are constraining your discussing to Windows 7. I am not. XP may have disappeared from the life of a non-corporate programmer, it's still everywhere for me. Hence the impedance mismatch. Most of our shop's customers did not see a business need to upgrade, and acquaintances that can afford to buy new computers while their old ones are still running (however poorly) tend to be Mac users anyway. >every terrible ailme…

You are constraining your discussing to Windows 7. I am not. XP may have disappeared from the life of a non-corporate programmer

Well what version of OSX are you using to make your comparison? SP3 to 10.8? Either way, there isn't some nebulous security gap between OSX and Windows, vulnerabilities exist in all systems and a responsible vendor patches them when they're discovered.

Please show me how to remotely compromise an up to date SP3 machine. Yes, there are exploits that exist at points in time, but the same is true of OSX, just google "OSX exploit".

malware is still not a part of day-to-day life with Macs to anywhere near the extent it is with Windows

All that proves is that there is more malware targeting Windows, it speaks nothing to the inherent security of the system since malware can't install itself.

Post reply on HN