MacDailyNews - Where Mac news comes first

MacDailyNews Poll

5 Day Most Commented

Opinion Archive

Current Headlines

Latest Joy of Tech

  • Latest Joy of Tech!

MacNN

AppleInsider

Macworld UK

TUAW

MacRumors

Yahoo! Finance AAPL

iTunes Top 10 Albums

Mac OS X Downloads

Mon, Oct 13, 2008 - 03:15 PM EDT  —  AAPL: 106.54 (+9.74, +10.06%)  |  NASDAQ: 1787.34 (+137.83, +8.36%)

The Financial Times tries spreading some Apple Mac security FUD
Thursday, December 06, 2007 - 12:10 PM EDT

"After years of relative safety, the Apple Mac is becoming an increasingly tempting target for malicious computer hackers, according to a new report published this week," Kevin Allison reports for The Financial Times.

MacDailyNews Take: Somehow this is "news" yet again. The same "report" has been published annually for the last half a decade. Yet, somehow, we manage to survive and surf the Web unimpeded on our Macs in the face of all of these "reports."

Allison continues, "Over the past few months, however, the number of malicious programmes has increased, according to a report published this week by F-Secure, an internet security company."

MacDailyNews Take: Oh, F-Secure, again. What do they sell? You'd think the "reporter" would take the source into account and ask, "Do you have anything to gain by ratcheting up fear, uncertainty, and doubt over a weak social engineering trojan and its variants?" But, nooooo! Allison instead reports it as gospel, because he's a hack.

Allison continues, "The rising security threat could present a challenge to Apple, which has long touted the security advantages of its platform over those of Microsoft, whose software is a perennial target for hackers. 'As Apple’s platform becomes more visible, it will increasingly come under the gun,' said Roger Kay, an analyst at Endpoint Technologies."

MacDailyNews Take: That the Mac is secure via obscurity is a myth. Did our intrepid "reporter" Kevin Allision ask why, if obscurity means security, in April was there a virus for iPods running Linux (a few thousand devices total, at most, in all the world), but there are no viruses for the 25 million Mac OS X computers currently online? Nooooo, of course not! He seems to print whatever he's fed without even questioning things that are blatantly illogical, because he's a hack.

"Security via Obscurity" is a defense mechanism for the delusional and a tool for Microsoft apologists and/or those who profit from Windows to keep the sheep in the pen. 25 million Mac OS X installs is not "obscure" at all, but 6+ years of users surfing unimpeded certainly is "secure." The only thing by which Mac users are really affected are large swaths of compromised Windows machines slowing down the 'Net with spam and nefarious botnet traffic targeted at exploiting more insecure Windows boxes. Get a Mac.

The idea that Windows' morass of security woes exists because more people use Windows and that Macs have no security problems because less people use Macs, is simply not true. Mac OS X is not more secure than Windows because less people use OS X, making it less of a target. By design, Mac OS X is simply more secure than Windows. Period. For reference and reasons why Mac OS X is more secure than Windows, read The New York Times' David Pogue's mea culpa on the subject of the "Mac Security Via Obscurity" myth here.

Allison continues, "Mr Runald said the jump in attacks against Apple appeared to be the work of a single gang of professional hackers. The group, known in security circles as the 'Zlob gang,' makes programs that infect PCs by tricking users into thinking they are installing software needed to view copyrighted video files. As with other attacks against Apple, the Zlob gang relies on tricking users to install its malicious software, rather than on exploiting any inherent software vulnerability."

Full article, Think Before You Click™, here.

MacDailyNews Take: Allison actually "reports" something correctly, proving that miracles do happen — even if they are hidden within deeply buried ledes. The entire foundation of Allison's piece is built upon one flimsy Trojan Horse that requires users to be tricked into entering their password to install and run it.

As usual with these increasingly tiresome pieces, there are three factions at work: (1) Anti-this/Anti-that software peddlers, (2) entities looking to stem the tide of Windows to Mac defectors, and (3) the painfully ignorant. Sometimes they originate from separate and distinct camps and other times they occupy two or all three groups at once. As a side effect, we also often get morbidly ignorant morons parroting stupidity, too.

It should go without saying, but we'll say it anyway: If The Financial Times printed articles about every Windows trojan, the world would have run out of trees years ago.

This is not the first Mac trojan, nor will it be the last. As always: Do not enter your Mac OS X admin password to install anything from an unknown and/or untrusted source.

  • Social Web
  • E-mail






Always -- Free ground shipping with orders over $50 at the Apple Store.

Reader Feedback: ( = registered)

Dec 06, 07 - 01:20 pm Comment from: cbs

Only mac users should buy macs. That way we keep our safe little comunity safe. Ha ha ha, or ho ho ho.

Dec 06, 07 - 01:24 pm Comment from: Triumph the Insult Comic Dog

"This is not the first Mac trojan, nor will it be the last. As always: Do not enter your Mac OS X admin password to install anything from an unknown and/or untrusted source."

Yeh-heh-hehesssss . . . more or less de same rules us macho canines use in de real world: Use your "trojans" correctly and don't "enter" anything "untrusted".

It's always worked for me . . . though there was that one time with the neighborhood shitzu . . .

Dec 06, 07 - 01:25 pm Comment from: Tommyr

Got to love the FUD masters! First post?

Dec 06, 07 - 01:36 pm Comment from: The Mac that roared

For me, the word FUD also applies to the people who post FUD. In this case its new definition would be: F*cking Useless Dumbsh*ts!

Dec 06, 07 - 01:39 pm Comment from: Ampar

Apple Mac security FUD = Pulpy tedium, scarface.

Dec 06, 07 - 02:01 pm Comment from: Gandalf

Of course they can't write about Microsoft being hacked because it happens so often that it isn't news. Well maybe in some circles Swiss researchers say they can log keystrokes from Microsoft's wireless keyboards from up to 50 metres away using special radio equipment, and are close to being able to control affected computers remotely.

Dec 06, 07 - 02:02 pm Comment from: Ampar

The last line of the article.
"F-Secure said it had detected 500,000 viruses, trojans and worms in 2007, compared with 250,000 last year."


That's incredibly irresponsible to imply that the Mac is vulnerable to half a million viruses, trojans and worms.

Dec 06, 07 - 02:20 pm Comment from: Wingsy

Same thing was written up at bloggingstocks.com, and I left behind a few paragraphs of my own. Your rebuttal was better tho.

Here the author was Douglas A. McIntyre, an editor at 247wallst.com. Looks like he just copied & pasted.

Dec 06, 07 - 02:21 pm Comment from: synthmeister

Similar dopey article at:

http://www.crn.com/it-channel/204701733?cid=CRNFeed

I could write this stuff in my sleep:

1. Macs and Apple products are more popular now

2. Somebody showed that if downloaded/installed some suspicious software on your Mac, bad things might happen.

3. Ergo sum, Macs might become a huge security risk over the next year if people keep downloading and installing suspicious software.

Just unbelievable. Once you get beyond all the posturing, all they are saying is that the Mac might have a security problem or two in the upcoming year.

Dec 06, 07 - 02:22 pm Comment from: smackman

To get the REAL story on Mac Security you should all go over to
opendoor.com

Alan's Blog is my only source I trust on Mac Security.

Great guy. Used to work for apple many years ago. Trust me. Go there, get eduacated, you'll never regret it.

smile

Dec 06, 07 - 02:34 pm Comment from: Fred Mertz

Wingsy,

Click the "morbidly ignorant morons parroting stupidity" link near the end of MDN's Take and see where it takes you!

Dec 06, 07 - 03:40 pm Comment from: Fed Up

Can anyone recommend a MDN like website that doesn't bombard you will their thoughts? Most of the time I agree with MDN but I still don’t need to hear it…it makes me feel like MDN is telling me what to think. In this article for example, MDN calls the writer a “hack” because he doesn’t question the source or do his own research. Probably true, but MDN…you don’t seem to question anything that is pro-apple do you? Before you point fingers, be sure they can’t be pointed back at you. So, in all seriousness, I must stop going to this site. Please give me a recommendation to a comparable site. I appreciate it.

Dec 06, 07 - 03:43 pm Comment from: almux

Hey, i'm just coming back from a multimedia assembly. Main talks: security and anti-viruses!! Damn! Amongst the 57 present members, we where only 2 to lagh out loud... 2 with Macs vs 55 running windoze... Wouarf!

Dec 06, 07 - 03:56 pm Comment from: HMCIV

F-Secure says something mildly interesting here:
http://www.f-secure.com/2005/2/f-secure_2005_wrapup.zip

I suggest you fast forward the video about 9 minute so you don't have to deal with to much pain and suffering from the accent. wink

However the days of Mac Security are ending. I installed MS Office and now my hard drive is flooded with spreadsheets. I fear there's no saving it.

Dec 06, 07 - 04:01 pm Comment from: Realist

MDN likes to feed stupid quotes back to us, such as the frequently repeated Michael Dell's earlier today.

Better keep an eye on your rear view mirror on this one boys... virus protectors may be FUD today but they are going to be right sooner than later.

Dec 06, 07 - 04:11 pm Comment from: Mr. Peabody

I don't know - Does the FT want RSVPs for those invitations?

Holy cow.

Dec 06, 07 - 04:30 pm Comment from: Ampar

To Fed Up:

Here you go, buddy:
http://thebitchersmoanersandwhinersclub.blogspot.com/

You're welcome.

Dec 06, 07 - 04:31 pm Comment from: Cubert

In my nightly perusings of sketchy porn web sites, I came across (no pun intended) one of these trojans. I clicked on video link and got the "must install missing codec" message, BUT what it tried to install was an executable file. Hah! Windoze suckers! I hit cancel and kept on perusing!

Dec 06, 07 - 04:47 pm Comment from: M

I really don't know for sure how big a factor the Mac's relatively small operating-system market share plays in all this, and neither does MDN. But, whatever, the reason/s for the relative safety of my platform, I'm cool with its being safe.

I also share MDN's suspicion of F-Secure's motives - and, come to that, of some "news" outlets motives. Many of these people depend financially on advertising from the Borg, which makes them quick to run down the Mac for any reason on the flimsiest of evidence. CNet/ZDNet is a case in point.

However, that doesn't mean I'm cool with the Mac sites making over-light of security and encouraging Apple to think it can devote less resources to security than it otherwise might, because it's been encouraged to think that the customers are blase and there's no immediate PR problem.

Apple could probably do a bit more:

http://www.matasano.com/log/981/a-roundup-of-leopard-security-features/

And it seems they still have no "security supremo":

http://erratasec.blogspot.com/2007/11/thing-that-makes-candy-sweet.html

So nuts to F-Secure and the Financial Times. But I sure hope Apple is keeping on top of things and not relying on a low market share.

Dec 06, 07 - 04:58 pm Comment from: RC

It's been over 6 years now, and still no viruses are in the wild for OS X. That pretty much says it all.

Dec 06, 07 - 05:00 pm Comment from: @Ampar

Wow...you're mature. Couldn't just give an honest recommendation. All the better that I don't socialize here. Seriously, I just asked for a good site to read up on apple stuff and you...well you are what you are. Thanks.

Dec 06, 07 - 05:15 pm Comment from: Ampar

To Fed Up:

You're still here? Why?

(Psst. Here's a secret. Don't tell anyone. O.K.? Did you see that freakin' long list of Apple related news and rumor sites on the left column of macdailynews.com? I'll bet they're waiting for you.)

And I've been accused of many, many things. Thankfully, mature is not on the list.

Dec 06, 07 - 05:33 pm Comment from: @Ampar

So what part of personal recommendation don't you get? Like I said before, you are what you are. Nothing more to be said, you're doing it all for me.

Dec 06, 07 - 06:33 pm Comment from: Ampar

To Fed Up:
That WAS my personal recommendation. It was more than generous. Here's a clue. I like this site. I like the MDN Take. You don't like MDN. Many of us do.
"So, in all seriousness, I must stop going to this site."
You lied.
"Nothing more to be said, you're doing it all for me."
Promise?

Dec 06, 07 - 06:54 pm Comment from: @Fed Up

Quite frankly,
Where can you find so much one liner entertainment on a subject we all love?

Quit sitting on tacks and roll with the humor.

When will Apple make a brown keyboard that I can use while reading MDN. I keep spewing my coffee with Ampar, Chrissyone, TowerTone, MDN take,
This is raw poetry man, how could you not love and laugh?

Poetry punctuated with 'think before you click'.. Beautiful ...absolutely beautiful..

Dec 06, 07 - 07:47 pm Comment from: @Fed Up

Don't listen to jack asses like Ampar. He's just upset cause his mom's tits are dry and he's hungry. I like appleinsider.com and thinksecret.com. They may not have as many articles as MDN but you won't have to read around MDN's comments (Listen to me everyone...listen to me!!!!).

Dec 06, 07 - 07:52 pm Comment from: Ampar

"He's just upset cause his mom's tits are dry and he's hungry."

That was funny! Thanks!

xxxooo

Dec 06, 07 - 07:54 pm Comment from: LorD1776

Looks like Ampar got under someone's thin skin.

Dec 06, 07 - 07:59 pm Comment from: Ampar's a baby

@ Ampar

How can you type with MDN's dick in your mouth? I guess you can't form your own decisions. How should I think MDN?? I don't know what to do!!

Dec 06, 07 - 08:03 pm Comment from: Ampar

Braille?

Dec 06, 07 - 08:36 pm Comment from: LorD1776

The brave and bold unregistered.

Dec 07, 07 - 04:08 am Comment from: derekcurrie

How To Utterly Destroy The 'Security By Obscurity' Myth:

Use math.

1) Take the current number of known malware in the wild for Windows. The number is so huge that I never find any sources in agreement. But let's use the very out-of-date, conservative number of 114,000 Apple used in an ad a year ago.

2) Take the number of known malware in the wild for Mac. Just to rub it in I like to inflate this number by including both the number for Mac OS X of 1 (one) and add all the old Mac OS 1 - 9 malware, that being 55. Total = 56 malware for Mac in its entire history.

3) Divide: 114,000 / 56 = 2036.

4) Slowly and kindly explain this to the myth mongers: Using verifiable data there are 2036x more malware for Windows than Mac.

5) Now go in for the kill and calculate the number of malware on a per computer basis for each OS. You can do this using market share percentages. The current agreed percentages are 92% of the US market are Windows boxes and 6% are Macs. (If myth mongers complain that you should use world market numbers, go right ahead. You'll still shock them). Using proportional math:

114,000 is to 56 malware as 92% is to 6% market share times Y, where Y is the difference or disparity factor between the number of malware per computer user for each platform.

Y = (114,000 / 56) / (0.92 / 0.06) = 132

Conclusion: There are 132 times more malware per Windows user than there are per Mac user.

There are theories about why this massive disparity exists. Blame Microsoft incompetence, blame user hatred of the Windows, blame simplicity of hacking Windows. But does 'security of obscurity' of the Mac explain this number? Obviously not.

Then stomp on the grave of this myth:

(A) Take out of the calculations the friendly 55 old non-Mac OS X active malware and point out the figure of 114,000 times more active malware for Windows than Mac. Doing the math, that gives a disparity factor of 7434 times more malware per Windows user than per Mac user. How's that sound?

(B) If there was equality in the security of the Windows platform versus the Mac platform you would at least expect something dramatically closer to a 1:1 ratio of malware per user between the platforms. 132 times more malware per Windows user is utterly insane. What does that make 7434 times more malware?

(C) Considering these figures, why does anyone use Windows? Why are businesses, designed to make money, wasting billions every year on Windows security upkeep and security damage when simply switching to Mac would wipe out nearly all those costs?

Dec 07, 07 - 02:27 pm Comment from: -hh

In addition to all of the other fallacies in this article from Kevin Allison in San Francisco, Kevin Allison ends by saying:

"F-Secure said it had detected 500,000 viruses, trojans and worms in 2007, compared with 250,000 last year."

Gosh! but Kevin Allison in San Francisco utterly neglects to mention that the OS these detections were on was *not* Mac OS X, but was Wonderful Windows.

As such, we can talk about the theory of "Security by Obscurity" until we're blue in the face, but as per F-Prot's numbers, there were a half million ***REAL*** Malware incidents on Windows OS users in the meantime.

Which get ignored as "Acceptable" while Kevin Allison in San Francisco tells us about some theoretical threat that Mac OS X might possibly coming under ... eventually.


Regardless of how or why, the reported half million Malware attack rate on Windows OS users means that Windows users *are* being attacked at a rate that is orders of magnitudes greater than OS X, even after adjusting for market share differences.

If Mr. Kevin Allison in San Francisco is trying to claim that some of this is due to "Security through Obscurity" (STO) which is going to wane, well, where's his data to claim that it exists in the first place?

Unfortunately, neither Kevin Allison in San Francisco, nor F-Prot have apparently even tried to quantify what difference STO may result. For sake of argument, even if STO makes a platform 10x less vulnerable ... the problem that Kevin Allison in San Francisco has is that the Mac OS is still demonstrably more than 10x less vulnerable than Windows OS.


The Pareto Principle says to expend your resources on the 80% that's the problem, which is the opposite of what Kevin Allison in San Francisco is doing.

As such, his advice is analogous to worrying about the possibility of catching a cold while in the middle of a very lethal war zone, complete with bombs, bullets and IEDs.

Thank you very much, Mr. Kevin Allison, for reminding me that wearing mittens is far more important than wearing body armor!



-hh

Dec 08, 07 - 03:46 am Comment from: Redo The Numbers

"Take the number of known malware in the wild for Mac. Just to rub it in I like to inflate this number by including both the number for Mac OS X of 1 (one) "

Get your numbers right, there have been several pieces of malware for Mac OS X found in the wild, and one of those had over a thousand variants (all of which would be counted individually in that Windows number).

So go with say 2,000 pieces of malware for Mac OS X.

Divide: 114,000 / 2000 = 56

Use the real market share number of maximum 3% worldwide (being generous).

Y = (114,000 / 2000) / (0.92 / 0.03) = 1.87

So what you find is Mac OS X, when adjusted on a market share basis is slightly more than half as interesting to virus/malware writers as Windows.

That's probably more like it.



.

Dec 09, 07 - 12:05 am Comment from: macgravy

i want this guys email address

Dec 17, 07 - 02:49 pm Comment from: derekcurrie

'Redo The Numbers' told a whopping H U G E L I E worthy of the most moronic of trolls:

"Get your numbers right, there have been several pieces of malware for Mac OS X found in the wild, and one of those had over a thousand variants (all of which would be counted individually in that Windows number).

So go with say 2,000 pieces of malware for Mac OS X..."

My numbers, those being 55 old Mac OS malware in the wild and 1 Mac OS X malware in the wild, are 100% verifiable. I have ALL the documentation. I can give you the names of all 10 (ten) malware that were ever (E V E R) written for Mac OS X. I can tell you their history and I have the reports from when they were discovered. I can name the one, single Mac OS X malware (the so-called 'Porno Trojan') that currently exists in the wild. I can point you to A N Y of the anti-malware sites and
they will verify
E X A C T L Y
what I have stated.

You, tard, are only here to insight misery. And I know why. You are just another sick sadomasochist living in suffering who insists upon making others suffer as well, no matter what deceit it takes to make it happen.

Sorry, not interested. You've had rings run around you logically, and I still enjoy the reality of my Mac. Now you can feel even more miserable, but of course that was part of your plan as well, wan't it. Congratulations.

Now I'll go off and enjoy my 100% malware free Macintoshes, all four of them. A toast to happy computing for everyone everywhere! :-Derek

Mar 19, 08 - 08:25 am Comment from: Ludor

@ Derek: Don't be hard on the guy, he might have no friends. But I commend your rhetoric math.

Reader feedback page 1 of 1 pages:

Always -- Free ground shipping with orders over $50 at the Apple Store.

Add Your Feedback:

Register or Login

Name:

Email: (optional)

Emoticons | Allowed HTML Tags

Remember my personal information   Notify me of follow-up comments?

Please enter the "MDN Magic Word" you see in the image below: