<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Are Macs really vulnerable to hackers?</title>
	<atom:link href="http://pcmike.com/uncategorized/are-macs-really-vulnerable-to-hackers/feed/" rel="self" type="application/rss+xml" />
	<link>http://pcmike.com/-2-2-2-2-2/are-macs-really-vulnerable-to-hackers</link>
	<description>The latest in personal technology</description>
	<pubDate>Fri, 29 Aug 2008 01:32:33 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: MAC User</title>
		<link>http://pcmike.com/-2-2-2-2-2/are-macs-really-vulnerable-to-hackers#comment-203</link>
		<dc:creator>MAC User</dc:creator>
		<pubDate>Sun, 28 Aug 2005 18:06:49 +0000</pubDate>
		<guid isPermaLink="false">http://pcmike.com/uncategorized/are-macs-really-vulnerable-to-hackers#comment-203</guid>
		<description>received my first malware on OS 10.4.2 Tiger.  Infected the web browsers.  Anytime I went to google, it took me to another sight.
</description>
		<content:encoded><![CDATA[<p>received my first malware on OS 10.4.2 Tiger.  Infected the web browsers.  Anytime I went to google, it took me to another sight.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mel</title>
		<link>http://pcmike.com/-2-2-2-2-2/are-macs-really-vulnerable-to-hackers#comment-202</link>
		<dc:creator>Mel</dc:creator>
		<pubDate>Thu, 24 Mar 2005 23:27:17 +0000</pubDate>
		<guid isPermaLink="false">http://pcmike.com/uncategorized/are-macs-really-vulnerable-to-hackers#comment-202</guid>
		<description>I have been using Macs since 1985, yes, twenty years. I'll never say that there isn't any malware for Macs, but I have never contracted so much as a Word macro virus on my Macs over the years. Yes, there have been a few; the one that probably spread the most was the Autostart Worm that infected a Mac that had the CD autostart enabled. It even got into a couple of commercial CD releases. But the Mac OS has never been as vulnerable as Windows and it appears that OS X is just as good in that regard. The argument that it doesn't get attacked because of small market share only plays when you talk about commercial malware. Zombie remailers are only good if you have a lot of them, and in relative terms there aren't a lot of Macs, so it's not profitable. However, I'm sure some malware author would love to earn his chops by being the first 1337 h4x0r to write a virulent Mac worm or virus. But it still hasn't happened. I had the same reaction as Mike to Symantec's self-serving press release - they're playing up a small number of isolated incidents to try to make a little more money. Intego tried the same thing last year. I still haven't bought any antivirus software and I don't plan to, especially when I read the complaints attached to every vendor in the field. When I see some real evidence that someone is having success breaking into Macs, I'll look for an open-source solution.</description>
		<content:encoded><![CDATA[<p>I have been using Macs since 1985, yes, twenty years. I&#8217;ll never say that there isn&#8217;t any malware for Macs, but I have never contracted so much as a Word macro virus on my Macs over the years. Yes, there have been a few; the one that probably spread the most was the Autostart Worm that infected a Mac that had the CD autostart enabled. It even got into a couple of commercial CD releases. But the Mac OS has never been as vulnerable as Windows and it appears that OS X is just as good in that regard. The argument that it doesn&#8217;t get attacked because of small market share only plays when you talk about commercial malware. Zombie remailers are only good if you have a lot of them, and in relative terms there aren&#8217;t a lot of Macs, so it&#8217;s not profitable. However, I&#8217;m sure some malware author would love to earn his chops by being the first 1337 h4&#215;0r to write a virulent Mac worm or virus. But it still hasn&#8217;t happened. I had the same reaction as Mike to Symantec&#8217;s self-serving press release - they&#8217;re playing up a small number of isolated incidents to try to make a little more money. Intego tried the same thing last year. I still haven&#8217;t bought any antivirus software and I don&#8217;t plan to, especially when I read the complaints attached to every vendor in the field. When I see some real evidence that someone is having success breaking into Macs, I&#8217;ll look for an open-source solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin Hill</title>
		<link>http://pcmike.com/-2-2-2-2-2/are-macs-really-vulnerable-to-hackers#comment-201</link>
		<dc:creator>Martin Hill</dc:creator>
		<pubDate>Thu, 24 Mar 2005 05:06:45 +0000</pubDate>
		<guid isPermaLink="false">http://pcmike.com/uncategorized/are-macs-really-vulnerable-to-hackers#comment-201</guid>
		<description>I'm afraid Symantec's widely reported marketing material is misleading and self-serving (it would after all be surprising for them not to attempt to encourage the development of new market segments in light of Microsoft's competitive entry into the AV market). 

Let's look at the statistics:

Microsoft Windows:
Viruses and Worms = 70,000+ (symantec.com)
Spyware programs = 78,000 (www.pestpatrol.com)
Burrowers = 40 (www.pestpatrol.com)
80% of PCs infected with spyware (webroot.com)
Last year alone (www.pestpatrol.com):
  500 new Trojans
  500 new keyloggers
  1,287 new adware apps

Mac OS X:
Viruses and Worms = 0
Spyware programs = 0
Adware = 0
Keyloggers = 0
Burrowers = 0
Trojans = 3  
Rootkit = 1

Note that Trojans can't spread by themselves - they are bits of code that pretend to be something innocuous and need to be downloaded and opened by an authorised user.  In the case of the three targeting Mac OS X, two are harmless while the third issues a rm -rf command if run by a user.  

Note also the Rootkit discovered on a couple of OS X machines is a set of scripts that requires root access to be turned on (turned off by default on all Macs). The hacker also needs to know the root password and the malware has no mechanism of spreading and infecting other computers by itself.

Symantec's espousal of the theory of "Security through Obscurity" fails to explain the fact that the number 1 web server, open source Apache with around 69% marketshare has far fewer attacks (including viruses and worms) than Microsoft's IIS which comes in at only 21% marketshare (Netcraft.com). It also does not explain why the many flavours of Linux suffer from so many instances of malware despite having as small a marketshare as OS X. 

37 vulnerabilities (mostly in open source components of Mac OS X) which were promptly patched by Apple does not constitute "increased attacks on OS X" as no attacks using any of these now closed vulnerabilities have been recorded.

John Gruber has a useful article on why Windows suffers so much malware:
&lt;a href="http://daringfireball.net/2004/06/broken_windows" rel="nofollow"&gt;http://daringfireball.net/2004/06/broken_windows&lt;/a&gt;

However, no software can be perfect and it would be foolish to say there won't eventually appear some malware targeting the 10 million+ OS X users out there - however, today is not that day.  Mac OS X has been sitting untouched for 4 years now pretty much without blemish which speaks to a very impressive security story even if/when some effective malware appears. This is the constructive issue everyone should be writing about.

Martin Hill
Information Management Services
Curtin University of Technology
Western Australia</description>
		<content:encoded><![CDATA[<p>I&#8217;m afraid Symantec&#8217;s widely reported marketing material is misleading and self-serving (it would after all be surprising for them not to attempt to encourage the development of new market segments in light of Microsoft&#8217;s competitive entry into the AV market). </p>
<p>Let&#8217;s look at the statistics:</p>
<p>Microsoft Windows:<br />
Viruses and Worms = 70,000+ (symantec.com)<br />
Spyware programs = 78,000 (www.pestpatrol.com)<br />
Burrowers = 40 (www.pestpatrol.com)<br />
80% of PCs infected with spyware (webroot.com)<br />
Last year alone (www.pestpatrol.com):<br />
  500 new Trojans<br />
  500 new keyloggers<br />
  1,287 new adware apps</p>
<p>Mac OS X:<br />
Viruses and Worms = 0<br />
Spyware programs = 0<br />
Adware = 0<br />
Keyloggers = 0<br />
Burrowers = 0<br />
Trojans = 3<br />
Rootkit = 1</p>
<p>Note that Trojans can&#8217;t spread by themselves - they are bits of code that pretend to be something innocuous and need to be downloaded and opened by an authorised user.  In the case of the three targeting Mac OS X, two are harmless while the third issues a rm -rf command if run by a user.  </p>
<p>Note also the Rootkit discovered on a couple of OS X machines is a set of scripts that requires root access to be turned on (turned off by default on all Macs). The hacker also needs to know the root password and the malware has no mechanism of spreading and infecting other computers by itself.</p>
<p>Symantec&#8217;s espousal of the theory of &#8220;Security through Obscurity&#8221; fails to explain the fact that the number 1 web server, open source Apache with around 69% marketshare has far fewer attacks (including viruses and worms) than Microsoft&#8217;s IIS which comes in at only 21% marketshare (Netcraft.com). It also does not explain why the many flavours of Linux suffer from so many instances of malware despite having as small a marketshare as OS X. </p>
<p>37 vulnerabilities (mostly in open source components of Mac OS X) which were promptly patched by Apple does not constitute &#8220;increased attacks on OS X&#8221; as no attacks using any of these now closed vulnerabilities have been recorded.</p>
<p>John Gruber has a useful article on why Windows suffers so much malware:<br />
<a href="http://daringfireball.net/2004/06/broken_windows" rel="nofollow">http://daringfireball.net/2004/06/broken_windows</a></p>
<p>However, no software can be perfect and it would be foolish to say there won&#8217;t eventually appear some malware targeting the 10 million+ OS X users out there - however, today is not that day.  Mac OS X has been sitting untouched for 4 years now pretty much without blemish which speaks to a very impressive security story even if/when some effective malware appears. This is the constructive issue everyone should be writing about.</p>
<p>Martin Hill<br />
Information Management Services<br />
Curtin University of Technology<br />
Western Australia</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charles Gaba</title>
		<link>http://pcmike.com/-2-2-2-2-2/are-macs-really-vulnerable-to-hackers#comment-200</link>
		<dc:creator>Charles Gaba</dc:creator>
		<pubDate>Wed, 23 Mar 2005 18:38:48 +0000</pubDate>
		<guid isPermaLink="false">http://pcmike.com/uncategorized/are-macs-really-vulnerable-to-hackers#comment-200</guid>
		<description>When discussing the security/hacking/virus/malware issue, it's very important to explain to people the difference between a *real-world* problem (virus, spyware, trojans, etc) and a *potential* problem (security hole/vulnerability).

OS X has--at this moment, at least--ZERO of the former.

Of the latter, it's my understanding that all of those 37 supposed issues were quickly &#38; cleanly dealt with, just as pretty much all of Apple's occasional security updates do (unlike Windows updates, which generally take forever to release and often botch things up even worse than before).</description>
		<content:encoded><![CDATA[<p>When discussing the security/hacking/virus/malware issue, it&#8217;s very important to explain to people the difference between a *real-world* problem (virus, spyware, trojans, etc) and a *potential* problem (security hole/vulnerability).</p>
<p>OS X has&#8211;at this moment, at least&#8211;ZERO of the former.</p>
<p>Of the latter, it&#8217;s my understanding that all of those 37 supposed issues were quickly &amp; cleanly dealt with, just as pretty much all of Apple&#8217;s occasional security updates do (unlike Windows updates, which generally take forever to release and often botch things up even worse than before).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Teejay</title>
		<link>http://pcmike.com/-2-2-2-2-2/are-macs-really-vulnerable-to-hackers#comment-199</link>
		<dc:creator>Teejay</dc:creator>
		<pubDate>Wed, 23 Mar 2005 18:14:11 +0000</pubDate>
		<guid isPermaLink="false">http://pcmike.com/uncategorized/are-macs-really-vulnerable-to-hackers#comment-199</guid>
		<description>37? WOW... 

In the Windows world, they'll have that many between now......


...and now :-)</description>
		<content:encoded><![CDATA[<p>37? WOW&#8230; </p>
<p>In the Windows world, they&#8217;ll have that many between now&#8230;&#8230;</p>
<p>&#8230;and now <img src='http://pcmike.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mnystedt</title>
		<link>http://pcmike.com/-2-2-2-2-2/are-macs-really-vulnerable-to-hackers#comment-198</link>
		<dc:creator>mnystedt</dc:creator>
		<pubDate>Wed, 23 Mar 2005 17:31:25 +0000</pubDate>
		<guid isPermaLink="false">http://pcmike.com/uncategorized/are-macs-really-vulnerable-to-hackers#comment-198</guid>
		<description>I remember viruses back in the pre-X days, and there were some nasty ones around, but Disinfectant always took care of them :-)

On OS X I've had no problems with viruses. I ran Norton AV for a bit and it detected one virus once, but it was a PC virus in an email attachment.

It's a matter of time before we'll experience something more substantial on OS X in terms of viruses, worms etc. Sooner or later it'll happen. But in my experience Symantec's current claims are a bit much and not in line with reality.</description>
		<content:encoded><![CDATA[<p>I remember viruses back in the pre-X days, and there were some nasty ones around, but Disinfectant always took care of them <img src='http://pcmike.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /><br />
On OS X I&#8217;ve had no problems with viruses. I ran Norton AV for a bit and it detected one virus once, but it was a PC virus in an email attachment.</p>
<p>It&#8217;s a matter of time before we&#8217;ll experience something more substantial on OS X in terms of viruses, worms etc. Sooner or later it&#8217;ll happen. But in my experience Symantec&#8217;s current claims are a bit much and not in line with reality.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
