The Mac Observer

Skip navigational links

You're viewing an article in TMO's historic archive vault. Here, we've preserved the comments and how the site looked along with the article. Use this link to view the article on our current site:
SANS Institute Sees 'Rapid Growth' in OS X Vulnerabilities

SANS Institute Sees 'Rapid Growth' in OS X Vulnerabilities

by , 4:00 PM EDT, May 1st, 2006

The SANS Institute on Monday updated its Top 20 list of Internet vulnerabilities, noting "rapid growth in critical vulnerabilities in Mac OS X, including a zero-day vulnerability." The security firm acknowledged that the operating system "still remains safer than Windows, but its reputation for offering a bullet-proof alternative is in tatters."

SANS defines a zero-day vulnerability as one that "causes damage to users even before the vendor makes a patch available." In the case of Mac OS X, Safari was susceptible to a flaw that automatically downloaded and executed a malicious file simply by browsing to a specific Web site. Apple fixed it, "but almost immediately had to issue a second patch to stop another attack involving email attachments," according to the SANS report.

SANS noted: "As attackers are increasingly turning their attention to the platform, OS/X vulnerabilities are being discovered at a rapid pace, which could erode this safety in the future."

Apple wasn't alone in getting dinged for critical vulnerabilities, however. SANS also pointed to "continuing discovery of multiple zero-day vulnerabilities in Internet Explorer," as well as "rapid growth in critical Firefox and Mozilla vulnerabilities." File-based attacks, especially those involving media and image files as well as Microsoft Excel documents, continue to surge too.

On the positive side, SANS also saw "substantial decline in the number of critical vulnerabilities in Windows Services," although trend turned into a wash for Microsoft because of the other problems documented by the firm.

Observer Comments

Show: Subjects Only | Full Comments
Close Name:Al Swearengen Posts: 339 Joined: 10 May 2005
Subject: Tatters?

"but its reputation for offering a bullet-proof alternative is in tatters."

That is a bit strong.

Close Name:deasys Posts: 296 Joined: 08 Apr 2003
Subject: The Full Name...

The Institute's full name is actually Sans Indice which is a French phrase meaning "clueless."

I loved this quote: "The security firm acknowledged that the operating system 'still remains safer than Windows, but its reputation for offering a bullet-proof alternative is in tatters.'"

Hmm..."still safer?" At a score of 80,000 to ZERO for Windows vs. Mac OS X, I guess you might say that...

Close Name:Guest
Subject: Need a Truckload of Salt Here

Since SANS makes its money selling training courses in computer security, dontcha think they may feel just a wee bit threatened by a system that doesn't need their services all that much?

I'd take what they say about Mac security with a grain or two of salt.

Close Name:Tiger Posts: 1018 Joined: 17 Jun 2003
Subject: rapid or vapid

This is such a miserable representation of facts (Not by TMO, but SANS). They don't seem to do any critical analysis, just spew out random thoughts and ideas.

Have the attacks on Mac OS increased? Yes. To date, TWO have been accomplished.

Woo hoo.

And every Mac user I know is aware that the system isn't foolproof. We have all had NAV on our systems for years. Because smart people know an ounce of prevention is worth more than a pound of cure!

Close Name:Guest
Subject: Was this file

"automatically" downloaded and executed without the user being notified? Could it happen if the user isn't running as an administrator?

Close Name:Guest
Subject:

Norton Anti virus is more problems than it is helpful.

Close Name:LaurieF -   TMO Forum Mod Posts: 3547 Joined: 15 Jun 2001
Subject:

I just love statistics. "What do these figures mean?" "Well, what do you want them to mean?"

I currently work for Statistics New Zealand, and in the past I've worked for New Zealand Health Information Services, in the breast cancer screening area. One of the things which always got my dander up was journalists who don't realise how much they don't know referring to certain agents doubling or tripling the chance of breast cancer.

On the face of things, that sounds pretty serious. And for the women who get breast cancer, it is serious. But saying 'doubling' or 'tripling' is essentially meaningless when it refers to, for example, five cases per 100,000 turning into ten or fifteen. What is truly important is the absolute number of cases, not the standardised incidence.

The same thing applies to incidents of viruses on OS X. If the number of viral attacks has, say, increased ten-fold in the last year, I don't care. What I care about is the actual number of attacks. It's still low. What I also care about is the propagation of those attacks to other computers: lower still.

Statistics is a black art, which I don't pretend to understand beyond having good instincts. On the other hand, statistical ignorance can be, and is, harmful.



Last edited by LaurieF on Mon May 01, 2006 10:03 pm; edited 1 time in total
Reply | Quote
Close Name:Guest
Subject: Ugly business....

The security analyst market is an ugly business. They market fear.

All that may have changed now is that the security firms have likely decided that either

a) they can generate good business by making Mac users, particularly Mac-based businesses, afraid that there are security concerns that they can help with

or

b) that their current Windows security business is at risk if they don't head off this Mac juggernaut before it gets going (people, particularly businesses, start switching to Macs to avoid the well known security woes of WIndows)

Who needs security consultants if there are no security threats? It's an ugly business.

Close Name:Rainy Day Posts: 607 Joined: 07 Jun 2005
Subject: FUD

Nothing but FUD here. Move on.

Close Name:Guest
Subject: It's the Windows users!

The new vulnerabilities are all of the new Windows users on the Macs!

Close Name:yoyo52 Posts: 1174 Joined: 02 Feb 2002
Subject:

Let's not ignore the fact that these reports--and my local piddly newspaper had a big old page 2 article on the new vulnerability of the Mac--comes out on the day that Apple is releasing new ads touting its relative safety in comparison to Windows computers. What a coincidence

Close Name:gulmatan Posts: 137 Joined: 17 Mar 2005
Subject:

Here's a lnk to another article (sorry if it's a repeat):

http://news.yahoo.com/s/ap/20060430/ap_on_hi_te/apple_security;_ylt=AgHZ1z0WsbvTt_wnBdehOutj24cA;_ylu=X3oDMTA5aHJvMDdwBHNlYwN5bmNhdA--

Close Name:Biff Posts: 1479 Joined: 08 Apr 2004
Subject:

Quote
Guest wrote:
The new vulnerabilities are all of the new Windows users on the Macs!
Ok that was just stupid.

Close Name:Guest
Subject: Yup

Quote
Guest wrote:
"Was this file automatically" downloaded and executed without the user being notified? Could it happen if the user isn't running as an administrator?


A. Yes, it was, but it had to open Terminal to do it's work, which should have been a pretty huge clue that it wasn't actually a screenshot of Leapord. And it happened in February and was widely reported then, but most people won't realise it's the same story again.

(Governments do the same by announcing the same 'extra cash for schools and hospitals' over and over. People think it's new cash when it's the same 'extra cash' as before).

The main thing to consider is that no Mac AV program has yet been proven to work, but at least one has introduced 2 different security problems of it's own, as well as stability problems. Until proven otherwise, running Software Update on it's normal schedule is the best known measure.

Security firms do a useful job, but unfortunately have got into the habit of calling everything 'critical' rather than reserving critical for what they now call 'zero-day'.

A problem on Windows is not critical if I need to surf to a specially crafted website. A problem on Apache is not critical on a Mac or Linux box unless it's being used as a web server. Most networking problems aren't a problem unless the hacker is on your local network.

Close Name:Guest
Subject:

Hahahah.

Hey, is this the same SANS Institute that's predicted OS X would soon be rendered a smoldering crater by malware, every few months since OS X's very inception?

It IS!

What a surprise.

What morons.

The "zero-day vulnerability" they're talking about has long since been patched by Apple. The "rapid growth in critical vulnerabilities in Mac OS X" has yielded no results whatsoever, as there is still no functional malware for OS X. What's that mean, kids? It means the "critical vulnerabilities in Mac OS X" are actually the furthest things from BEING critical you can imagine.

But what do you expect from a security firm that warns you about the CLEAR AND PRESENT DANGER posed by a security hole that has, infact, already been fixed?

That's some good work, SANS Institute.

Comment on this Article


You cannot edit your comments.   You cannot delete your comments.

Comments are currently closed. Please email the author instead.


Recent Headlines - Updated November 9th

Mon, 7:20 PM
Rumor - Apple May Update iPod touch in December
6:45 PM
Product News - MacUpdate Desktop Updated to 5.0.1 with New Features, Bug Fixes
5:16 PM
Apple Releases Mac OS X 10.6.2 - Guest Account Bug Fixed, Much More
4:12 PM
Games - New For iPhone: Star Rangers, Air Force Supremacy, Blood Beach, More
2:51 PM
Apple Stock Watch - Radio Shack Jumps 14% on iPhone Deal, Apple Up 3%
2:25 PM
Games - EA Scoops Up Social Games Publisher Playfish
1:51 PM
Deal Brothers - Western Digital 1TB SATA Intellipower Hard Drive:  $84.99
10:58 AM
News - StarHub Signs Singapore iPhone Deal
10:36 AM
Hot Forum Topic - Reader Speculation: What’s in Apple’s Tablet?
10:08 AM
News - Apple Kicks Off New Credit Program
9:26 AM
News - Apple Launches Reserve and Pick Up Program
8:49 AM
News - ikee Worm Rickrolls Jailbroken iPhones

The Mac Observer Reader Specials

  • TypeStyler For Mac OS X is Now Shipping! Download The Free Fully Functional 60 Day Tryout at www.typestyler.com
  • RamJet Memory: Mac Pro 8-core 8GB Kit $199.99, 4GB Kits $109.99! Sale on MacBook and MacBook Pro 8GB kits $549.99! New MacBook DDR3 2GB for $49.99. iMac and Mac mini 4GB Kits for $79.99! 1TB SATA Hard Drives for $109.99! Click here
  • OWC: Get the Right Memory for Your Mac Top Quality, Competitive Price, Lifetime Backed Free Expert Support + Installation Videos too! MacBook & mini 8GB, iMac 16GB, Mac Pro up to 32GB. Click here
  • Poker Mac If you're using a Mac, then you've gotta check out Full Tilt Poker for Mac. This Full Tilt Poker bonus code does the unthinkable, it actually rewards!
  • For the latest Apple products use Ciao, a price comparison website, to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate mobile phones like the Apple iPhone.

  • Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.
  • __________
  • Buy Stuff, Support TMO!
  • Podcast: Mac Geek Gab
  • Podcast: Apple Weekly Report
  • TMO on Twitter!