The Mac Observer

Skip navigational links

You're viewing an article in TMO's historic archive vault. Here, we've preserved the comments and how the site looked along with the article. Use this link to view the article on our current site:
C|Net: Mac Security Not About the OS Anymore

C|Net: Mac Security Not About the OS Anymore

by , 2:10 PM EDT, April 9th, 2008

Security researchers have never identified any instance in the wild in which a Mac has been exploited from the Internet, according to C|Net on Wednesday. That's despite a recent incident in which a well crafted Website was used to exploit a flaw in Safari. As a result, exploitation techniques have moved from attacking the OS directly to tricking the user.

Tom Krazit, at the RSA conference, took some time to characterize the state of PC security and surmised that it's no longer about which OS is more secure. It's more about economics and social engineering. Because the PC still has vastly dominant market share, the business case for attacking PCs remains favorable.

"Even if Apple moved to 10 percent market share, why spend the time on the 10 percent when you can just nail 90 percent with one bug?" Charlie Miller pointed out.

Mr. Miller took control of a MacBook Air at CanSecWest conference's "Pwn to Own" contest, but it required a specialized exploit that a user would normally never come across. In the earlier part of the contest, the MacBook was immune from attacks restricted to network attacks from the outside.

As a result of this increase OS security by all vendors, thieves are turning to more devious techniques that depend on tricking the uninformed or naive users, especially those who have become accustomed to entering credit card numbers online.

The fastest way to make money in the Internet remains the infamous Nigerian 419 e-mail, Mr. Krazit reported. Given that, it isn't surprising that many PC users thought that the iTunes update in Windows offering them Safari was mandatory.

In the end, the OS battle to see who has the best security pales in comparison to the educational challenge for ordinary computer users who are spending more and more time on the Internet.

Observer Comments

Show: Subjects Only | Full Comments
Close Name:Guest
Subject:

"...exploitation techniques have moved from attacking the OS directly to tricking the user."

This is old hat, but still true. If I remember right, Kevin Mitnick has said this was the primary way he would get access to most of the systems he hacked. He would just use the company's public directory, pick a name from it, call up someone in IT and say he was the person, and tell the IT guy he needed access to some server or something.

This article echos the column posted on Roughly Drafted explaining why the RSA conference is a sham and the exploit of the MBA is a non-issue.

Close Name:Guest
Subject: If ...

Let's see. Mac already has nearly 20% of the home market, but the vast number of exploits are still aimed at Windows flaws. The botnets are where the illegal money is and those thrive on the exploiting Windows - mainly unpatched installs, but still more a Windows problem, than a Mac problem. Yes, the users need educating, but the major fault is still WIndows is swiss cheese.

Comment on this Article


You cannot edit your comments.   You cannot delete your comments.

Comments are currently closed. Please email the author instead.


Recent Headlines - Updated July 6th

Mon, 5:50 PM
News - Counter-Rumor: Nvidia & Apple Doing “Just Fine”
5:28 PM
News - Arlington Police Release Video of Apple Store Shooter
4:40 PM
Deal Brothers - Apple Mac Pro 2.66GHz Intel Xeon Quad Core for $2,274.00 Delivered A/R
4:12 PM
Product News - Babylon Upgrade Adds New Translation Features to Mac Dictionary App
11:17 AM
Ted Landau's User Friendly View - Apple’s LED Cinema Display: A Too Short Story
11:11 AM
Product News - Photo Recovery for Mac Adds Photoshop Support
10:39 AM
Hot Forum Topic - iPhones in Education
8:47 AM
News - Apple Employee Injured in Store Shooting
Fri, 10:29 AM
News - Apple Warns of Learning Interchange Security Breach
7:30 AM
News - Happy Fourth of July!
Thu, 6:07 PM
TMO Scoop - Psystar Moves to Drop Bankruptcy Ahead of Apple Legal Battle
5:37 PM
News - Uncomfirmed Reports Say Apple & Nvidia On The Outs

The Mac Observer Reader Specials

  • __________
  • Buy Stuff, Support TMO!
  • Podcast: Mac Geek Gab
  • Podcast: Apple Weekly Report
  • TMO on Twitter!