7 ms·
Apple has always been exceptional in this regard as well. It usually drives people up a wall when this is pointed out, as the fanboys like to trumpet it a bit t
by RI_Swamp_Yankee 11y ago
Apple has always been exceptional in this regard as well. It usually drives people up a wall when this is pointed out, as the fanboys like to trumpet it a bit too loudly, but it's true. In-the-wild exploits are rare, and the company moves quickly to squash them and to prevent the entire category of exploit from biting them a second time.
- wdmeldon 11y agoI can't help but think this is more a result of low volume and extremely tight control over their ecosystem rather than an intentionally prioritizing on security.
- RI_Swamp_Yankee 11y agoThe MacOS X ecosystem is 25 years old now, counting NextStep, and has an installed base of close to a hundred million systems, most of them unsophisticated personal computer users running a full Unix operating system with internet access. That is a prime target, considering there are malicious exploits that take advantage of Z-series mainframes in recent years. (one of the Pirate Bay founders got popped for looting the mainframe at a tax accounting firm) I think it's more to do with the development culture inside Apple. The features in Swift designed to improve secure coding shows you they're actively thinking about secuirty and how to achieve it, and have been for a while. The only regular security headlines you see about the Mac is in the Pwn2Own contest and their like, where researchers trot out vicious exploits that are then dutifully squashed by Apple in the next update, never to be seen in the wild. (And there's a reason Apple makes it a PITA to install Flash and Java these days, and includes their own very nice .pdf reader.)
- tptacek 11y agoFirst, there is Mac malware. Second, retail-level malware is a numbers game. Malware isn't cross-platform. A malware author chooses their target based on how remunerative the target is. Windows remains more remunerative than OS X. There is no fundamental difference between the security models of modern Windows and OS X that accounts for the disparity in malware infections. (I'm a Mac user, and have been since ~2001.)
- scholia 11y agoThe pwn2own contestants never have any problems pwning Macs, but iOS's security record is hugely impressive.
- deleted 11y ago[deleted]
- tptacek 11y agoThere are a lot of great people at Apple and the security model of iOS is an achievement --- in a lot of practical ways better than that of Android. But I do not know a lot of people who would argue the Apple has a better security program than Google does. Google's team is better funded and better staffed, and has a much broader charter than Apple's.
- blinkingled 11y ago> in a lot of practical ways better than that of Android. Umm no - the update situation is better on iOS but fundamentally iOS has bigger problems - https://twit.tv/shows/security-now/episodes/532?autostart=false https://twit.tv/shows/security-now/episodes/532?autostart=fa... . That problem is unfixable easily due to the way ObjC works. Android gets code access control for free with Java. There have always been Jailbreaks for most iOS versions and it's not like they haven't had other security issues. The ability to fix them quickly is certainly an advantage but there is nothing in iOS that is fundamentally more secure than anything else on the market. Frankly I think Apple's security is a combination of happenstance and restrictive policies - I don't think they care (yet) about the processes, infrastructure and people required to do what Google and Microsoft do. (No offense to the good security people at Apple - this isn't about them, this is about having organization wide security focus like MS needed to turn around Windows.)
- tptacek 11y agoI don't understand what your argument is. Untethered jailbreaks on iOS are worth gigantic amounts of money because they are not easy to come by.
- blinkingled 11y agoBut they have existed for every version of iOS none the less. The relative difficulty may quite well be due to other reasons - closed source, locked down hardware etc. Says nothing about software security.
- 11y ago