> The fact that OS X has now been targeted speaks to the popularity of Apple’s operating system It's not a security breach it's a problem of rising popularity. That's one way to spin it.
Apple has shut down the first fully-functional Mac OS X ransomware
11–20 of 30 posts
Re: Apple has shut down the first fully-functional Mac OS X ransomware
#12Earlier quoted context omitted.
Do you have a citation for this? The extent of what was illicitly accessed remains unclear. Without knowing how their infrastructure is set up, it's not possible to say that the intrusion was limited to just the web server.
Here's the Reuters article where they state that: http://www.reuters.com/article/apple-ransomware-idINL1N16F17...
[1] https://github.com/jparyani/Transmission/blob/master/AUTHORS
Re: Apple has shut down the first fully-functional Mac OS X ransomware
#13> The fact that OS X has now been targeted speaks to the popularity of Apple’s operating system It's not a security breach it's a problem of rising popularity. That's one way to spin it.
It is a security breach but in the past most malware has been targeting windows because of the larger financial upside due to popularity. As OS X gets more popular expect more attempts like this.
Re: Apple has shut down the first fully-functional Mac OS X ransomware
#14> The fact that OS X has now been targeted speaks to the popularity of Apple’s operating system It's not a security breach it's a problem of rising popularity. That's one way to spin it.
It is a security breach but in the past most malware has been targeting windows because of the larger financial upside due to popularity. As OS X gets more popular expect more attempts like this.
Re: Apple has shut down the first fully-functional Mac OS X ransomware
#15So this confirms that Apple revoking the app-signing certificate that pissed off a bunch of people was related to KeRanger?
Re: Apple has shut down the first fully-functional Mac OS X ransomware
#16Earlier quoted context omitted.
Someone compromised their main web server where the binaries are hosted and put up a malicious binary.
Do you have a citation for this? The extent of what was illicitly accessed remains unclear. Without knowing how their infrastructure is set up, it's not possible to say that the intrusion was limited to just the web server.
Re: Apple has shut down the first fully-functional Mac OS X ransomware
#17"...has shut down the first fully-functional Mac OS X ransomeware" Here I was hoping it was the second malware coded with functional programming. Scheme last time [1]. I was hoping to see some systems Haskell or ATS in there. Oh well. Always another opportunity when it comes to malware. [1] http://philosecurity.org/2009/01/12/interview-with-an-adware...
I...wait, what? Did Windows actually used to be that bad?
Re: Apple has shut down the first fully-functional Mac OS X ransomware
#18"...has shut down the first fully-functional Mac OS X ransomeware" Here I was hoping it was the second malware coded with functional programming. Scheme last time [1]. I was hoping to see some systems Haskell or ATS in there. Oh well. Always another opportunity when it comes to malware. [1] http://philosecurity.org/2009/01/12/interview-with-an-adware...
>Windows has this thing called Create Remote Thread. Basically, the semantics of Create Remote Thread are: You’re a process, I’m a different process. I call you and say “Hey! I have this bit of code. I’d really like it if you’d run this.” You’d say, “Sure,” because you’re a Windows process– you’re all hippie-like and free love. Windows processes, by the way, are insanely promiscuous. So! We would call a bunch of proc…
But you can only inject DLLs (this is how it's called) if your process already has some admin rights and if the other process is not of a higher integrity.
Re: Apple has shut down the first fully-functional Mac OS X ransomware
#19"...has shut down the first fully-functional Mac OS X ransomeware" Here I was hoping it was the second malware coded with functional programming. Scheme last time [1]. I was hoping to see some systems Haskell or ATS in there. Oh well. Always another opportunity when it comes to malware. [1] http://philosecurity.org/2009/01/12/interview-with-an-adware...
>Windows has this thing called Create Remote Thread. Basically, the semantics of Create Remote Thread are: You’re a process, I’m a different process. I call you and say “Hey! I have this bit of code. I’d really like it if you’d run this.” You’d say, “Sure,” because you’re a Windows process– you’re all hippie-like and free love. Windows processes, by the way, are insanely promiscuous. So! We would call a bunch of proc…
Re: Apple has shut down the first fully-functional Mac OS X ransomware
#20So this confirms that Apple revoking the app-signing certificate that pissed off a bunch of people was related to KeRanger?
No. They revoked that single developer's certificate. I think you're referring to an Apple certificate that simply expired and invalidated many App Store signatures.