Live data from Hacker News

Apple Quietly Pulls Claims of Virus Immunity

pcworld.com

111–120 of 154 posts

Re: Apple Quietly Pulls Claims of Virus Immunity

#111
post #27

Apple tried to claim Apple PCs were special, but it didn't remove the single biggest hazard to any claim of security. PC means personal computer, which means a system owned by millions of people without the technical skill to assess whether or not that attachment (whether it's birthday_card.dmg or birthday_card.exe) really came from grandma. All PCs are vulnerable to users. I'm glad Apple figured it out a few years s…

>> I'm glad Apple figured it out a few years sooner than Microsoft did.

When exactly are you claiming that Apple "figured it out"? Because Microsoft's Trustworthy Computing Initiative kicked off in 2002 http://en.wikipedia.org/wiki/Trustworthy_computing#Microsoft...

From what I've seen inside of MS security trumps everything else. Want to change an API? You can't...unless it has a security issue in which case go right ahead.

Re: Apple Quietly Pulls Claims of Virus Immunity

#112

Earlier quoted context omitted.

I was under the impression that since Macs went over to x86, they were capable of running Windows. They are IBM PC compatible.

If we're going to be technical, since they don't run a PC BIOS (they use the newer EFI), they're not compatible with the original IBM PC.

EFI is not exclusive to Macs. It was developed by Intel and has been deprecated in favor of UEFI. Most UEFI images will have legacy support for BIOS services.

There is basically no difference between a modern Mac and a PC - except for Mac OS X, which can be run on "Hackintoshes".

Re: Apple Quietly Pulls Claims of Virus Immunity

#113
post #98

Earlier quoted context omitted.

> not finally getting around to stop lying about security through obscurity as a positive feature because they're no longer obscure enough. That isn't what happened. It used to be true, now it's not so they changed it. Security through obscurity was a positive feature, there is little denying it. Just because it wasn't going to last doesn't make it positive and just because you think it's not something they should be…

> That isn't what happened. It used to be true Stop drinking the kool aid. It was never true. OS X was exploit central for years. It was only the BSD base that stopped it from being exploitable from the network. All the client side stuff Apple added for years was RCE-you-like. Also a fundamental thing about security is the acceptance that security by obscurity is not a defensive measure. Genuine security doesn't rely…

I'll be the first to point out that OS X was never _fundamentally_ more secure than Windows, and, to some degree was demonstrably _less_ secure than Windows 7.

But, " It was never true. OS X was exploit central for years." is hyperbole. The OS X platform has been remarkably free of exploits, for a system that didn't go out of it's way to enhance security.

I think most of us would agree that the greatest security feature of OS X was it's niche presence - just wasn't an attractive target, so nobody targeted it.

Re: Apple Quietly Pulls Claims of Virus Immunity

#114
post #27

Apple tried to claim Apple PCs were special, but it didn't remove the single biggest hazard to any claim of security. PC means personal computer, which means a system owned by millions of people without the technical skill to assess whether or not that attachment (whether it's birthday_card.dmg or birthday_card.exe) really came from grandma. All PCs are vulnerable to users. I'm glad Apple figured it out a few years s…

>> I'm glad Apple figured it out a few years sooner than Microsoft did. When exactly are you claiming that Apple "figured it out"? Because Microsoft's Trustworthy Computing Initiative kicked off in 2002 http://en.wikipedia.org/wiki/Trustworthy_computing#Microsoft... From what I've seen inside of MS security trumps everything else. Want to change an API? You can't...unless it has a security issue in which case go righ…

Apple took the claim down less than a year after a big malware outbreak. 2002 is quite a few years after malware authors started targeting Windows.

Re: Apple Quietly Pulls Claims of Virus Immunity

#115

Can anyone here speak to the risk to FreeBSD (or other BSDs)? As MacOS becomes more of a target, how much more vulnerable does FreeBSD become?

Most BSDs aren't running stuff like Bonjour which increases exposure to the network.

Bonjour is just Apple's name for zero config networking which most Linux and BSD distributions do support to various degrees.

Re: Apple Quietly Pulls Claims of Virus Immunity

#116
post #92

Earlier quoted context omitted.

Wow! 10 years of only using computers operated and actively maintained by users who can stay up-to-date on security best practices. You made it from before XP until now without ever dealing with Windows malware! You're pretty damn lucky - I sometimes use computers that belong to laypeople :-(

It really doesn't take state of the art security, it just takes some healthy skepticism when browsing the web. If you know not to click on flashing red banners, you'll be okay. I went without antivirus for years, but now I just run MSSE in the background as it's so light. It's only alerted me to false positives so far, but they're few and far between. I will say that if I'm suspicious of a file (say, a dll I had to g…

So nobody has ever successfully done anything wrong on any Windows computer you've used in 10 years.

Gotcha.

Re: Apple Quietly Pulls Claims of Virus Immunity

#117
post #92

Earlier quoted context omitted.

Wow! 10 years of only using computers operated and actively maintained by users who can stay up-to-date on security best practices. You made it from before XP until now without ever dealing with Windows malware! You're pretty damn lucky - I sometimes use computers that belong to laypeople :-(

It really doesn't take state of the art security, it just takes some healthy skepticism when browsing the web. If you know not to click on flashing red banners, you'll be okay. I went without antivirus for years, but now I just run MSSE in the background as it's so light. It's only alerted me to false positives so far, but they're few and far between. I will say that if I'm suspicious of a file (say, a dll I had to g…

The sarcasm isn't helpful, guy.

Re: Apple Quietly Pulls Claims of Virus Immunity

#118
post #98

Earlier quoted context omitted.

> not finally getting around to stop lying about security through obscurity as a positive feature because they're no longer obscure enough. That isn't what happened. It used to be true, now it's not so they changed it. Security through obscurity was a positive feature, there is little denying it. Just because it wasn't going to last doesn't make it positive and just because you think it's not something they should be…

> That isn't what happened. It used to be true Stop drinking the kool aid. It was never true. OS X was exploit central for years. It was only the BSD base that stopped it from being exploitable from the network. All the client side stuff Apple added for years was RCE-you-like. Also a fundamental thing about security is the acceptance that security by obscurity is not a defensive measure. Genuine security doesn't rely…

I wish to debate for a bit. You're technically right on so much of this but keep coming to Apple-sucks conclusions that I don't feel are warranted.

Let's grant this: if malicious code can start executing on OS X as a regular user, it's game over. There are so many ways through the floor it's almost trivial. (the presence of BSD tools being largely irrelevant since there were far easier ways in the door that are guaranteed to be installed)

And let's grant this: Apple has been very late in rolling out an explicit malware detection and removal systems.

And let's grant this: Microsoft understands what they're up against when it comes to security. Malware damaged the Windows XP install base to the point where it was necessary to stop production on their #1 moneymaker in order to rescue it.

I can't support your assertion that Gatekeeper is a power grab. The defaults on 10.8 allow any and all signed software bundles to be installed regardless of where they came from.

Mac App Store can at the very least "prove" that apps are only able to call public APIs, there's a minor but real financial and logistical barrier to entry, and developers and apps can be revoked. All apps must be sandboxed (for better and for worse) and updates must come through a known source.

As for the argument that Apple is doing security by obscurity, I think they've been doing fine. To review the ways I know of to trash a Mac: Drive by web plugin attack, network attack, e-mail attachment attack, tricked into authenticating Installer.app.

I think we can all agree that all major OSes are a lot better about controlling ports open by default nowadays.

Web: Safari is sandboxed. Flash is sandboxed. Extensions are sandboxed and signed. All out of date flash plugins are purged automatically at system boot. Java has basically been disabled across the entire Mac ecosystem. In-line PDFs are handled by the OS.

Disk Mounter refuses to mount known bad .dmgs. Installer.app has a blacklist. Both of these update nightly. System Update will shortly match the default policies and cadence of Windows Update.

PDFs are handled by a sandboxed built-in App, short-circuiting the nightmare that is Adobe Acrobat Reader. There's no AutoRun concept for mounted volumes. ASLR at multiple levels is in use. Signed frameworks are in use. Etc, etc, etc.

I'd argue that a Mac out of the box being used by an novice operator is pretty well protected, with more to come. And these novice operators are the ones who do the most damage to software platforms by blindly installing shit. Apple's straightjacket provides better results for them.

Finally, iOS: the ivory-est of all ivory towers. Name an app that's done real-world damage, because I haven't heard of one.

Re: Apple Quietly Pulls Claims of Virus Immunity

#119

"Let's hope more Apple Mac owners are also learning to take important security steps -- such as installing antivirus protection." This is the worst possible step to take. When I switch someone over to Mac I take the opportunity to recalibrate how they see their computer as secure. I teach them to be more aware of what they are doing and how potential viruses could infect them. I find this is 100x more effective than…

>> When I switch someone over to Mac I take the opportunity

Why only after switching? Is it not simpler to teach them these before switching? Wonder how much effect it will have if they did all those things regarding being careful clicking buttons and protecting personal information without switching.

Re: Apple Quietly Pulls Claims of Virus Immunity

#120
post #98

Earlier quoted context omitted.

> not finally getting around to stop lying about security through obscurity as a positive feature because they're no longer obscure enough. That isn't what happened. It used to be true, now it's not so they changed it. Security through obscurity was a positive feature, there is little denying it. Just because it wasn't going to last doesn't make it positive and just because you think it's not something they should be…

> That isn't what happened. It used to be true Stop drinking the kool aid. It was never true. OS X was exploit central for years. It was only the BSD base that stopped it from being exploitable from the network. All the client side stuff Apple added for years was RCE-you-like. Also a fundamental thing about security is the acceptance that security by obscurity is not a defensive measure. Genuine security doesn't rely…

> Stop drinking the kool aid. It was never true.

It was always true, and it was a tangible benefit. Your arguments rely on it being considered "genuine" security or an effective defensive measure. It's not. That doesn't make it false, or not a benefit to end users.

> and it only became necessary for them to do it when it started to become an issue because people were getting owned.

What were people getting "owned" (ffs, I thought this was HN?) by in Snow Leopard. Care to provide a real world example, because I know you're full of shit. There was no well known dangerous trojan/malware/virus for SL that had any notable number of infections. The anti-malware in SL was a preventative measure.

> Don't even bother comparing it to Microsoft.

Watch me. I don't care about the reasons behind it, the long and short of it is Apple introduced an anti-malware system in OS X before it was a big issue and Microsoft pushed it until 2012, long after they've had countless brutally utilized exploits.

> If MS releases a good enough AV product the AV industry jumps up and down because MS just stole their lunch.

So MS sold out their customers to please their partners? Yeah keep trying to spin that one. And I'M the one drinking the kool-aid.

> Apple is not helping users to have a more secure experience.

Yes they are. FFS, you don't even understand what Gatekeeper is. FYI, it's not just the Mac App Store. Do some research before you continue to run your mouth.

> Do you really think that an App in the Mac App Store has no way of being malicious?

Of course not. Does it have a much, much, much smaller chance? Absolutely. Is it far and away the most effective measure against malware besides not installing anything? Also true.

> Have you not seen what can be done by an app in iOS?

An App Store app? No I haven't, care to demonstrate?

Post reply on HN