7 ms·
I would agree. Windows has the largest population of non-computer literate people worldwide so hackers get the bigest bang for their buck and windows gets a bad
by johnl 16y ago
I would agree. Windows has the largest population of
non-computer literate people worldwide so hackers get the bigest bang for their buck and windows gets a bad rap. If everyone jumps to another OS so will the security problems.
- maukdaddy 16y ago?! Are you missing the part where OS X is based on BSD?
- ori_b 16y agoThat's a myth. There are some parts like libc and the command line apps that were ported from BSD, the the kernel is a mach-that-isn't-anymore hybrid oddity, and the user interface is an Apple-only system. So, to a good approximation, you can say that the command line is based on BSD, and the rest came from NeXT and Apple, with a bit of GNU mixed in. The BSD heritage is rather insignificant when it comes to security, since the largest attack surface comes from Apple applications like Safari, or the file manager, or other apps the end user uses directly on a regular basis.
- pavs 16y agoMac OS X Leopard receives UNIX 03 certification: http://arstechnica.com/apple/news/2007/08/mac-os-x-leopard-receives-unix-03-certification.ars http://arstechnica.com/apple/news/2007/08/mac-os-x-leopard-r...
- ori_b 16y agoSure, but that just means it provides the correct library calls, has the right shell utilities, and so on. It says nothing about the pedigree, or the amount of security. It's undoubtedly a good thing, but it's not important in this context.
- pavs 16y agoWhere do you draw the line when a BSD based OS has been customized to the extend that it can't be considered a BSD based OS?
- sp332 16y agoThat only describes the interface, not the implementation. It says (almost) nothing about the kernel, or security.
- pavs 16y agoYou are right. I just double checked my facts and OSX kernel is actually a hybrid kernel and not a direct descendant of BSD flavor (which was my impression). My mistake.
- sp332 16y agoThat's like saying Windows is UNIX-based because it conforms to POSIX.1.
- abrahamsen 16y agoThat would be like calling someone a Ph.D. after completing kindergarten. UNIX 03 certification means MacOS X is a UNIX. It doesn't say anything about its status as a BSD though.
- tptacek 16y agoxnu's BSD code isn't a myth. Have you ever actually read any of it? Which parts? I had to dive into it headfirst for a Black Hat presentation in 2007, in which we loaded probes into a running xnu kernel to detect hypervisors. I was surprised by how easy it was to navigate based on my familiarity with FreeBSD's kernel. Obviously, there's quite a bit of non-BSD code in OS X, but for anyone who has worked with a BSD kernel before, the similarities are impossible to miss. Hell, even if you can't read kernel code, the fact that OS X has sysctl, doesn't have proc, and debugs with ptrace() doesn't tell you anything?
- Legion 16y agoBad logic. Popularity is unrelated to quality of code. While it is true that popularity = bigger target = more incentive to attack the platform's security, it is also often used as an excuse to try to hand-wave away bad, insecure code. Another platform becoming more popular would indeed mean that it would have more people targeting it. But it does not, in any way, mean that the people would have the same level of success exploiting it as they do Windows. We could probably safely expect that the platform would be successfully exploited more than it currently is. And people that think OS X is a security panacea are living in a fantasy world. But the argument that "[i]f everyone jumps to another OS so will the security problems" is a woeful oversimplification, and confuses two separate issues. Also, as a side note, people seriously underestimate the level of incentive that currently exists for targeting non-Windows platforms. It is not the case that the incentive scales proportionally to audience size. Any sufficiently popular platform is a desirable target to attack. It's not like a platform has to have 90% of the market to be worth the effort. The relative ease of attack is a far more important factor than the potential audience size once we're talking millions of users.
- tptacek 16y agoNo. In fact, the incentive for attackers is exactly the inverse of what you claim it is. The author of WinAPI malware can expect multiple tens of conversions for every one obtained by Mac malware. That's because, breathless accounts in the media aside, malware infections don't compete in any practical sense. You would need to deliberately eschew all financial incentives to target OSX. The logic here is exactly the same and exactly as simple as Joel Spolsky's article about investing in OSX dev from 2002. As for the rest of your comment: both Windows and OS X are conventional monolithic operating systems written in C with core facilities designed and built in the '90s. Both are multiuser operating systems repurposed for single-user deployments. Both have strong kernel/userland barriers with well-defined interfaces. In fact, if you've done systems programming on both, they simply aren't all that different, even to a software developer. But: for the past 10 years, Microsoft has been getting hammered by attackers, and has the benefit of a decade-long trial by fire. So when Microsoft randomizes library offsets, they don't (for instance) miss the entire runtime loading subsystem. Also: most of Microsoft's most sensitive application code is written in C for WinAPI on x86, which is one of the best-understood application runtimes in the world. Much of OS X runs on cross-platform Objective C, which has received nowhere nearly as much research. Put simply: nobody knows how to write exploit countermeasures for OS X. I think mostly because nobody cares. (Again: I say this as a Unix dev from '93 at a company standardized on Macs).