Live data from Hacker News

Flashback trojan reportedly controls half a million Macs and counting

arstechnica.com

91–100 of 125 posts

Re: Flashback trojan reportedly controls half a million Macs and counting

#91

Earlier quoted context omitted.

Whoa, no kidding. The majority of people are not going to stop on those two letters and consciously differentiate "virus" from "PC virus."

"A Mac isn’t susceptible to the thousands of viruses plaguing Windows-based computers." Pretty clear.

There are two possible ways to interpret this:

1. "A Mac is susceptible to viruses. But it is not susceptible to viruses plaguing Windows-based computers."

2. "A Mac isn’t susceptible to viruses, whereas a Windows-based computer is susceptible to thousands of viruses."

The fact that you still get viruses, but they just don't happen to be the same viruses, isn't worth stating. So as a customer, it is very unlikely that I would infer the former (Meaning 1) from the statement. Yet it is what is meant.

I would personally call this misleading (and dangerously close to lying).

Re: Flashback trojan reportedly controls half a million Macs and counting

#92
post #6

This both saddens and delights me, as it proves that Macs are now at a large enough market share that malware writers are willing to target that platform ...

Did not pre X versions of Mac OS have more viruses in the wild with much smaller market share?

Well, I saw this movie called "The Net" and there was a virus on a Mac.

Then again, that's hollywood.

Re: Flashback trojan reportedly controls half a million Macs and counting

#93
post #78

What annoys me is that I just found Java to be enabled in Firefox again, when I was pretty sure that I had disabled it before. I suspect that yesterdays update reinstalled it into Firefox. (I could be wrong, though - but I definitely remember starting Safari just for the sake of trying Minecraft, because it was the only one of my Browsers with Java enabled).

IIRC Mozilla are going to blacklist out-of-date Java versions in FF.

Re: Flashback trojan reportedly controls half a million Macs and counting

#94
post #65
post #59

Earlier quoted context omitted.

> Such vulnerabilities are incredibly rare in Mac OS X since unlike Windows, kernel space is isolated from users. That's just flat wrong and hasn't been true for an OS Microsoft has supported for mainstream use since 2003 [1]. Windows XP and all current Windows releases are based on the protected NT kernel which debuted in 1993 (with Windows NT 3.1). In fact, Microsoft and Apple stopped shipping OSes with unprotected…

That can't be true. If NT-based versions of Windows implemented a system call mechanism that protected the kernel from users, XP wouldn't have been ridden with viruses, and there would have been no purpose in giving Vista and 7 the access control mechanism to warn users of potentially harmful system calls. By the way, Cheatah just refers to the original Mac OS X. Your phrasing "stopped shipping OSes with unprotected…

First, Cheetah wasn't the first Mac OS X. There was Mac OS X Server 1.0 in 1999 (see: Wikipedia). Cheetah was the first desktop-oriented version of Mac OS X.

Second, I didn't imply that prior versions Mac OS X didn't have kernel protection, I implied that prior versions of Mac OS didn't have kernel protection. This is indisputably true (see: Mac OS 9). Personally, I find Windows / Mac OS parallel surprisingly close here: Windows ME is to Windows XP as Mac OS 9 is to Mac OS X Cheetah.

Third, UAC (User Account Control), the access control introduced with Windows Vista, is almost entirely unrelated to kernel protection (except that UAC would probably be pointless without it). The problem UAC tries to solve is "users running as an administrator too often", not "the kernel isn't protected from user programs". In other words, it is Windows' answer to sudo, not a fundamental change to the Windows kernel.

Re: Flashback trojan reportedly controls half a million Macs and counting

#95

Earlier quoted context omitted.

Whoa, no kidding. The majority of people are not going to stop on those two letters and consciously differentiate "virus" from "PC virus."

"A Mac isn’t susceptible to the thousands of viruses plaguing Windows-based computers." Pretty clear.

[deleted]

Re: Flashback trojan reportedly controls half a million Macs and counting

#96
post #87

Earlier quoted context omitted.

That's a good observation. Avoiding GPL3 software, like newer versions of bash and gcc, might have the unintended consequence of putting their users at risk.

I highly highly doubt we'll see a day when there are significant exploits for Joe Soap Mac User from a bug in bash or gcc. Those are not software that Joe Soap is likely to have install (e.g. gcc), or will be hard for a website to run.

I think they install bash by default, not sure if they use gcc's libstdc++.

Re: Flashback trojan reportedly controls half a million Macs and counting

#97
post #44

Earlier quoted context omitted.

Yes, it is correct that Macs can get viruses. Where people get upset is when you generalize this to say that because >1 virus exists, OSX presents no significant advantage over Windows. Viruses are not a fact of life for Mac users. Talk to anyone who uses or services Macs; you'll be hard-pressed to find anyone who's even seen an OSX virus. Whereas for Windows power-users, cleaning viruses for friends/parents is pract…

OSX is still dramatically safer in terms of your actual risk of a random remote attack. It certainly was in the WinXP years due to a far superior security model, but I'm curious if this is still the case with modern windows.

The developer mindset on Windows is still stuck in the 90s, and most of the exploits are due to the laggards who've never taken the user experience for updating very seriously (Adobe, Sun/Oracle, various streaming video players, etc.) or treating security as an optional feature and installing with insecure defaults (see previous list).

Mac culture has been less user-hostile for a long time so Mac apps usually have e.g. automatic updaters (and rarely the crazy login-to-vendor-website-to-download insanity) and lack installers, making it less common to require authentication or slop things around the entire filesystem. This is not perfect but it avoids some of the pathologies which Microsoft (and Chrome) are slowly dragging the Windows community out of.

Re: Flashback trojan reportedly controls half a million Macs and counting

#98

As someone who used to sell Mac computers, I used to get asked the question "Is it true macs never get viruses?", to which I replied "No that's not true." (It was just an apple reseller store afterall so I was never compelled to bend the facts.) I'd try to explain the caveats a bit: a smaller market share and the unix based operating system requiring more permissions, yada yada, being "prohibitive" to an attack but s…

Yes, it is correct that Macs can get viruses. Where people get upset is when you generalize this to say that because >1 virus exists, OSX presents no significant advantage over Windows. Viruses are not a fact of life for Mac users. Talk to anyone who uses or services Macs; you'll be hard-pressed to find anyone who's even seen an OSX virus. Whereas for Windows power-users, cleaning viruses for friends/parents is pract…

Malware creators are going to get more creative and more dangerous now that Windows is better and Macs are more popular. Technical countermeasures can only do so much against a determined mind with a strong incentive.

Re: Flashback trojan reportedly controls half a million Macs and counting

#99

Earlier quoted context omitted.

You are constraining your discussing to Windows 7. I am not. XP may have disappeared from the life of a non-corporate programmer Well what version of OSX are you using to make your comparison? SP3 to 10.8? Either way, there isn't some nebulous security gap between OSX and Windows, vulnerabilities exist in all systems and a responsible vendor patches them when they're discovered. Please show me how to remotely comprom…

|vulnerabilities exist in all systems Couldn't disagree with you more.

[deleted]

Re: Flashback trojan reportedly controls half a million Macs and counting

#100

Earlier quoted context omitted.

No. If they didn't qualify it with "PC" it would have that implication. By qualifying it, they make it unambiguous.

They're implying that only PCs have viruses.

No, they are stating that Macs are not susceptible to PC viruses, which is true.

They are implying that viruses are a severe problem on PCs that Mac users do not face. This was undoubtedly true when they were running those adverts.

Post reply on HN