C|Net: Mac Security Not About the OS Anymore
C|Net: Mac Security Not About the OS Anymore
by , 2:10 PM EDT, April 9th, 2008
Security researchers have never identified any instance in the wild in which a Mac has been exploited from the Internet, according to C|Net on Wednesday. That's despite a recent incident in which a well crafted Website was used to exploit a flaw in Safari. As a result, exploitation techniques have moved from attacking the OS directly to tricking the user.
Tom Krazit, at the RSA conference, took some time to characterize the state of PC security and surmised that it's no longer about which OS is more secure. It's more about economics and social engineering. Because the PC still has vastly dominant market share, the business case for attacking PCs remains favorable.
"Even if Apple moved to 10 percent market share, why spend the time on the 10 percent when you can just nail 90 percent with one bug?" Charlie Miller pointed out.
Mr. Miller took control of a MacBook Air at CanSecWest conference's "Pwn to Own" contest, but it required a specialized exploit that a user would normally never come across. In the earlier part of the contest, the MacBook was immune from attacks restricted to network attacks from the outside.
As a result of this increase OS security by all vendors, thieves are turning to more devious techniques that depend on tricking the uninformed or naive users, especially those who have become accustomed to entering credit card numbers online.
The fastest way to make money in the Internet remains the infamous Nigerian 419 e-mail, Mr. Krazit reported. Given that, it isn't surprising that many PC users thought that the iTunes update in Windows offering them Safari was mandatory.
In the end, the OS battle to see who has the best security pales in comparison to the educational challenge for ordinary computer users who are spending more and more time on the Internet.
Observer Comments
"...exploitation techniques have moved from attacking the OS directly to tricking the user."
This is old hat, but still true. If I remember right, Kevin Mitnick has said this was the primary way he would get access to most of the systems he hacked. He would just use the company's public directory, pick a name from it, call up someone in IT and say he was the person, and tell the IT guy he needed access to some server or something.
This article echos the column posted on Roughly Drafted explaining why the RSA conference is a sham and the exploit of the MBA is a non-issue.
Let's see. Mac already has nearly 20% of the home market, but the vast number of exploits are still aimed at Windows flaws. The botnets are where the illegal money is and those thrive on the exploiting Windows - mainly unpatched installs, but still more a Windows problem, than a Mac problem. Yes, the users need educating, but the major fault is still WIndows is swiss cheese.
Comments are currently closed. Please email the author instead.
Recent Headlines - Updated November 8th
- Sat, 7:58 PM
- News - Apple TV 3.0.1 Update Fixes Missing Content Bug
- Fri, 7:45 PM
- Rumor - Taiwan Leak Shows Verizon UTMS/CDMA iPhone for Q3 2010
- 6:40 PM
- News - iPhone Moves Into RadioShack
- 6:30 PM
- News - Apple to Open Stunning Paris Apple Store in Le Louvre on Saturday
- 5:43 PM
- Free on iTunes - Dictionary, Dictionary, Dictionary, And More
- 4:09 PM
- John Martellaro's Blog - Particle Debris (week ending 11/6) Failure IS an Option
- 3:32 PM
- Games - The Latest App Store Games: Gravity Sling, RocketBird, Ground Effect, Checkers!
- 2:25 PM
- Games - Star Soccer 2010 for Mac Puts Gamers in Role of Up-and-Coming Player
- 2:15 PM
- How-To - The Mysteries of Rosetta Housekeeping
- 1:33 PM
- News - iPhone Game Developer Sued for Collecting User’s Cell Numbers
- 1:17 PM
- Games - Warhammer Online Expands Trial Play Option
- 11:19 AM
- Rumor - Apple May Be Bringing RFID to the iPhone
The Mac Observer Reader Specials
- TypeStyler For Mac OS X is Now Shipping! Download The Free Fully Functional 60 Day Tryout at www.typestyler.com
RamJet Memory: Mac Pro 8-core 8GB Kit $199.99, 4GB Kits $109.99! Sale on MacBook and MacBook Pro 8GB kits $549.99! New MacBook DDR3 2GB for $49.99. iMac and Mac mini 4GB Kits for $79.99! 1TB SATA Hard Drives for $109.99! Click here
OWC: Get the Right Memory / Ram for your Mac. Top Quality, Competitive Prices, Lifetime Warranty. Expert Support and Video Installation Guidies too! 4.0GB Matched Sets from $87.99, Options up to 32GB. Click here
If you're using a Mac, then you've gotta check out Full Tilt Poker for Mac. This Full Tilt Poker bonus code does the unthinkable, it actually rewards!For the latest Apple products use Ciao, a price comparison website, to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate mobile phones like the Apple iPhone.
Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.

