• #507
    Refresh Thread
    By: freakynipples69 x Show Full Post
    Reply
    http://www.engadget.com/2010/03/19/charlie-miller-to-reveal-20-zero-day-security-holes-in-mac-os-x/

    I like his analogy.

    "Mac OS X is like living in a farmhouse in the country with no locks, and Windows is living in a house with bars on the windows in the bad part of town." In other words, Apple users are "safer" (due to the lack of work that goes into hacking them), "but less secure."
    Mar 19, 2010 6:54am PDT
    toggle
    http://www.engadget.com/2010/03/19/charlie-miller-to-reveal-20-zero-day-security-holes-in-mac-os-x/ I ... : freakynipples69

    Thread Truncated. Click to see all 56 replies.

    • toggle
      Not quite the best analogy. It's more like a farmhouse with a gate (you need a password to install anythi... : ryuusekiThis person is cool!
      • Assuming that they're going for root. Lots of malware nowadays doesn't even bother going for root, with ... : umcpwintermute
      • You realize analogies aren't used as 1:1 comparisons of a system right? : pyrosThis person is cool!
    • toggle
      As somebody who mostly uses Macs these days I'm rather afraid that they are some kind of monoculture that... : tcsThis person is cool!
      • toggle
        There really isn't much you can do on a Mac - security market hasn't expanded to the point where there ar... : umcpwintermute
        • toggle
          IIRC Apple rolled out a mini anti-virus a little while ago through software updates that was for a specif... : ryuusekiThis person is cool!
          • There are some rootkits in heavy use for cracked servers, but a lot of the Linux/BSD malware is aimed at ... : umcpwintermute
          • I heard that too, that there was some minimal AV-type thing in Snow Leopard. I think it would be a very s... : tcsThis person is cool!
      • toggle
        there needs to be spyware first before you can have a spyware remover : electrolyThis person is cool!
        • bingo : two50six
        • toggle
          Well, once that happens I'll be back here all like MAC MENZ HELP ME I DONT KNOW HOW TO REMOVE SPYWAREZ FR... : tcsThis person is cool!
          • toggle
            the worst that would happen is you'd have to nuke your user account and create a new one. the rigorous s... : electrolyThis person is cool!
            • toggle
              So malware can only spy out & destroy all my data, but the OS is safe! Thank god! Wheew, what a relief! ;... : tcsThis person is cool!
              • toggle
                if they can overwrite your OS, they can overwrite your Time Machine backups :) unless you unplug that ha... : electrolyThis person is cool!
                • toggle
                  Yes, I'd agree that most risk is to stuff like banking information and installing spam mass mailers and a... : tcsThis person is cool!
                  • toggle
                    OSX has a Unix-like user system. There isn't really any concept of an "admin" user; there's only limited... : electrolyThis person is cool!
                    • toggle
                      UAC isn't an artificial barrier, it's very much like sudo. It's that by turning off UAC, you essential s... : umcpwintermute
                      • UAC isn't a security barrier in default mode, you can easily side-step it : jcupittThis person is cool!
                    • toggle
                      Ok, thanks! I'm quite familiar with Linux/UNIX, just wasn't sure if OS X was doing anything different her... : tcsThis person is cool!
                      • Having an "Administrator" account means that you're allowed to do administrator things with prompting, no... : umcpwintermute
                      • toggle
                        note that "sudo su" does work, if you find yourself needing to do a lot of admin tasks at one time : electrolyThis person is cool!
                        • or "sudo -s" :) : jcupittThis person is cool!
                  • Yea, an account compromise on one account won't spread to the others (assuming FileVault or non-world-wri... : umcpwintermute
      • toggle
        there are anti-virus and anti-malware apps for Mac out there, yet, I've been running my Mac for about 3 y... : g0nkThis person is cool!
        • toggle
          Yea, but those aren't the "real" malware things you need to watch out for. The real ones are malicious F... : umcpwintermute
          • toggle
            There are a handful of exploits of OS X out there: http://www.metasploit.com/modules/exploit/osx/ : umcpwintermute
            • toggle
              Newest one is 2007 looks like. : ryuusekiThis person is cool!
              • Yea, Metasploit is kind of slacking in putting out exploits and shellcode for OS X. Plus I'm sure the go... : umcpwintermute
      • toggle
        it's not that bad. OS X is half BSD+GNU, there are tons of non-Apple people that work on their software : ]pm[chemThis person is cool!
        • Sure, I'm a software developer and enjoy both BSD and the GNU tools daily on my system ;-) With monocultu... : tcsThis person is cool!
      • http://security.comcast.net/ gives free norton Is for Mac to it's customers hey, free norton 360 to wi... : sludge vohaulThis person is cool!
    • It's also living in a farmhouse in the country because the town you live in only has like 30 people. : JohnnyRey
    • toggle
      So Mac OSX is basically going to be that figure in the news story where they start out the piece by sayin... : SchnappleThis person is cool!
      • toggle
        Pretty much. As Macs pick up market share (and I'm a Mac user at home myself), I certainly expect them t... : umcpwintermute
        • that's fortunate because now I can resume those activities without risking the censure of my peers : boring gegtik
    • toggle
      same argument / viewpoint for the past 10 years, I don't see OSX suddenly becoming more popular so I don'... : fatmanThis person is cool!
      • toggle
        You don't see OSX suddenly becoming more popular? : boring gegtik
        • toggle
          I don't. Not percentage-wise anyway. Sure there may be more users than there were a year ago, but I'd s... : SgtPepper78
          • toggle
            Doesn't look very accurate in comparison to this: http://www.w3schools.com/browsers/browsers_os.asp : ryuusekiThis person is cool!
            • But I posted my graph from some random proprietary source first so mine's right! : SgtPepper78
            • that's just percentages of people who visit a single particular site. A site whose visitors aren't repre... : MamiyaOtaru
          • so 5.15% in 2010, 3.5% in 2007, according to that site (pulldown top left to change the date) : jcupittThis person is cool!
        • For developers, yes. The app store alone forces many wanna get rich developers to purchase at least a Ma... : freakynipples69
        • OS X is too close to sounding like Malcolm X. It's an OS for black people. Also, Apples are red and tha... : TwiLyghtThis person is cool!
    • I don't use OS X because its perceived as more safe, and security never really bothered me while I grew u... : not work safeThis person is cool!
    • toggle
      Analogies should be banned on the internet. : walker270This person is cool!
      • toggle
        The internet should be banned in analogies. : SgtPepper78
        • toggle
          One could say the internet is an analogy. : Godhatesfatpeople
          • The analogy is the internet. : freakynipples69
      • I know, it's like, there's these tubes and someone is trying to fuck them with their genitalia. : scottythejock
      • Saying that is like me trying to be funny. Futile. : KleboldThis person is cool!
    • I'm not sure why this is news to anyone. Apple patches security holes in free updates just like microsof... : SqueegyTBS
    • toggle
      Whilst on the subject, i lol'd today when a mate told me he had to "book an appointment" at the mac store... : KleboldThis person is cool!
      • toggle
        if its broken and he wants a free one, then it is like any other cell phone store in existence and you ne... : papaskotThis person is cool!
        • Because you need an appointment to get a fucking cable? The kind of crap you are pulling i find equally a... : KleboldThis person is cool!