South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.
LOL that's not a design fault but a featureOSX is only meant to work on macs.
lol, sure.
Good for you then.
Charlie Miller, the security expert who won both this and last year’s CanSecWest Pwn2Own security contests by exploiting Macs running Safari, repeated in an interview that he’d recommend Macs to typical users as a safer alternative to Windows PCs.
.
Pwn2Own contest winner: Macs are safer than Windows
Following both Pwn2Own contests, numerous sensationalist headlines played up the idea that a Mac had been “cracked in seconds,” conspicuously neglecting to mention what Miller called “the many days doing research and writing the exploit before the day of the competition,” enabling him to discover the bugs and develop a way to successfully exploit them on the first try at the event.
Macs less secure, more safe
In an interview with Tom’s Hardware, Miller stated, “I’d say that Macs are less secure for the reasons we’ve discussed here (lack of anti-exploitation technologies) but are more safe because there simply isn’t much malware out there. For now, I’d still recommend Macs for typical users as the odds of something targeting them are so low that they might go years without seeing any malware, even though if an attacker cared to target them it would be easier for them.”
Miller also offered some suggestions for users. “For all operating systems, make sure you keep your system up to date. That’s the best thing you can do. On a PC, I’d recommend running some AV software to help clean up when things go bad. Otherwise, just be smart, pay attention, and hope for the best. It is possible to really lock down your computer (running noscript for example) and make it safer, but in my opinion it’s not worth the trouble and the loss of functionality you experience.”
Mac security software not recommended
When asked whether having outgoing firewalls, anti-spyware or anti-malware software, or not being logged in as a root user would have done anything to limit the extent of the exploits on the Mac that he demonstrated at the last two security events, Miller said, “None of those protections would have probably worked, or at least there were potential workarounds. The best thing the user could have done is not click on the malicious link. Of course, in some cases such as a man-in-the-middle attack, even this wouldn’t have helped.”
While neither of the exploits gained root access, Miller pointed out that “just [cracking into] running as the user is still very bad. I could have still watched keystrokes as you went to an online bank, read your calendar and address book, sent emails, etc. In real life, one or all of these things would have occurred.”
No market for Mac malware
Repeating comments he made earlier, Miller noted that “Mac bugs aren’t really valuable,” pointing out that while the CanSecWest award of a new Mac notebook and the $5,000 “is a lot of money, it’s really not that much when you consider what a bad guy could make with an exploit for an unknown vulnerability in, say, IE 8 running on Vista.”
In a separate interview, Miller estimated that a researcher with an exploitable Windows vulnerability “could easily get $50,000 for that vulnerability. I’d say $50,000 is a low-end price point.” The huge difference in vulnerability valuations between the Mac and Windows reflect the fact that there is no demand for creating malware on the Mac.
This winter Gregg Keizer wrote about Miller in Computerworld: “Criticizing security software for its cost — both in dollars and in the processor cycles it consumes — Miller admitted that he doesn’t bother running any on his Macs. ‘I don’t think it protects me as well as it says,’ he argued. ‘If I was worried about attacks, I would use it, but I’m not worried.’”
At the time, Miller had taken Apple to task for recommending in a support document that Mac users consider installing antivirus software. Computerworld said Miller “pooh-poohed Apple’s recommendation using the same logic as many longtime [Mac] users,” and quoting Miller as saying, “Windows has 90% of the market, but [attackers] give it 100% of their time.”
You are suggesting that OSX came 3rd out of Vista and Linux based OSes.
Then you conclude, after all logically that's what's implied-- that the reason you think OSX is so hacker-weak is because it is CLOSED SOURCE, yet
as explained by me (and it seems I must use baby words) Windows Vista is the most closed source OS of the 3 - with parts of OSX being OSS too. If your conclusion were to have merit - Vista would blow more than OSX in these hacker comps.
For example, nearly everyone is claiming that:
(Mac)
* Downloading iLife warez that pretend to be stolen software
* from a non-trusted source
* assigning it privileges to install on your system
* and then finding that you have installed a background process that does something ugly, which that you can trivially remove
is the same as:
(Windows PC)
* Trying to use Windows to browse the web and use email
* finding that you’ve been automatically infected with adware and viral malware without knowing it
* then finding that your PC is also self replicating attacks or sending spam on to other systems
* then realizing that Microsoft’s design of the Windows Registry makes it difficult to clean malware out
* then noticing how much of your CPU capacity is being used to protect you from all of these threats via malware and virus scanners
* then finding out how expensive it is to spend hours cleaning up the mess yourself, or alternatively paying some Nerd Patrol $300 to “diagnose” that your PC is hosed.
Pwn2Own contest winner: Macs are safer than Windows
Following both Pwn2Own contests, numerous sensationalist headlines played up the idea that a Mac had been “cracked in seconds,” conspicuously neglecting to mention what Miller called “the many days doing research and writing the exploit before the day of the competition,” enabling him to discover the bugs and develop a way to successfully exploit them on the first try at the event.
That's stating the obvious. Macs don't need all those drivers because it comes fully configured and users are discouraged from changing the innards (mostly).I didnt call it a design fault, I simply stated that Linux has more native driver support in its kernel than any other OS.
FYI.. I installed Ubuntu on a MacBook recently.. I didnt have to install any drivers(This includes Gfx, Wifi, Bluetooth, etc etc).. though I had to fight with the bootloader
Thanks!
Hey guys, there is already a thread about that hacking contest.
Didn't u both argue in that one too?
The geezer at the top of the page likes to troll.
He likes to use that word (just noticed).No. Well I dont recall debating with Peter about this.
Thanks for trolling me.
Man infects 3 000 PCs, charged
2009-08-13 17:02
Adelaide - A 20-year-old Australian man has been charged with infecting more than 3 000 computers around the world with a virus designed to capture banking and credit card data, police said on Thursday.
The man, whose name will not be released until he appears in an Adelaide court on September 4, has been charged with several computer offenses that carry prison terms of up to 10 years, South Australia state police Detective Supt Jim Jeffery said in a statement.
Police also uncovered information that will identify other offenders, Jeffery said.
The man, who lives in the state capital, Adelaide, is also accused of illegally creating a capacity to disable computer systems by bombarding them with unwanted traffic from up to 74 000 computers he controlled around the world.
This type of sabotage is known as a distributed denial of service attack.
Police have not said whether the man allegedly used stolen banking information to commit identity fraud.
The arrest followed a three-month investigation involving state and federal computer crime detectives.
- AP
with infecting more than 3 000 computers
bombarding them with unwanted traffic from up to 74 000 computers he controlled
Nice links PeterCH I laughed so much.. this bit was the funniest.. its like the author has no clue what he is talking about.
Lolz.. yeah cause every hacker instantly comes up to an OS and hacks his way instantly into a system. /end sarcasm.
Its kinda like saying that Thorpe really should not have won those medals because he prepared for it beforehand. hehe.
My conclusion again Peter (I guess I have to clarify it for the sake of another strawman logical fallacy) is that the problem is closed vs opensource. If an exploit is found in Linux.. someone updates the code it, it gets approved by the repositry maintainers and voila.. problem no longer there. From my experience this is normally the next day. Though there are exceptions to this.
Nice links PeterCH I laughed so much.. this bit was the funniest.. its like the author has no clue what he is talking about.
Lolz.. yeah cause every hacker instantly comes up to an OS and hacks his way instantly into a system. /end sarcasm.
Its kinda like saying that Thorpe really should not have won those medals because he prepared for it beforehand. hehe.
They should have a competition to see how long it takes to find and install hardware drivers.
I'm sure Linux will be bulletproof on that one too.
Nice red herring logical fallacy but I`ll bite.
Fact: Linux comes by default with more hardware driver support in its kernel than any other OS.
More than MS and certainly more than OSX.
Personally on all the workstations and servers I have installed in the last two years.. only the Nvidia drivers were needed. Everything just worked for me. Bonus is.. I dont have to use over priced hardware that Apple supplies!
I can confirm this, all of my systems running Ubuntu (currently 6) had all of the drivers installed after a vanilla installation except NVIDIA drivers, which took quite literally two clicks to install.
I can confirm this, all of my systems running Ubuntu (currently 6) had all of the drivers installed after a vanilla installation except NVIDIA drivers, which took quite literally two clicks to install.