6 ms·
Apple the new world leader in software insecurity
- NathanKP 16y agoIt is fortunate that Apple still has a small enough market share that they aren't being attacked as vigorously as Windows is. For now I still feel like my Mac is safer from viruses than the average Windows machine, but that security is definitely shaky if Apple gets a larger market share and starts attracting real attention from viruses and hackers.
- b_emery 16y agoI hear this enough to wonder if it's a myth. Mac OS is built on Unix, so how does the total Unix+Linux+Mac market share look? Probably big enough to justify attacking. I suspect but can't prove that Unix is inherently more secure than Windows (or more easily secured). I've actually had a Mac compromised before after being lazy about the password setup. I suspect it difficult for the botnets to get traction, but they're certainly trying.
- Tamerlin 16y agoIt's not actually a myth. There aren't very many UNIX-based operating systems in the hands of the average user, who is the prime target, since the users are the biggest vulnerability in any system. UNIX isn't inherently secure to begin with, in fact initially security for UNIX was an afterthought. It wasn't until it started gaining widespread use that the UNIX developers started taking security seriously. I went through the transition from having encrypted passwords in the /etc/passwords file, which everyone could read (or no one could log in) to /etc/shadow as security started becoming important. That said, there was a virus around 8 years ago that specifically targeted a bunch of NCSA UNIX machines, and they ended up getting caught with their pants down -- there WAS a fix already available that would have blocked the virus, but the NCSA admins hadn't been diligent about installing it.
- wmf 16y agoIt's only fair to count Unix+Linux+Mac as one market if a single exploit could work on all of them, which I doubt.
- g_lined 16y agoI have a tendency to agree with you. For viruses, the numbers don't add up. I couldn't find numbers for how many viruses/worms were written last year. In 2004 there were around 28000 written, so let's assume viruses are on the decline and say 8000 were written last year. With a 5% share, Apple should have anything up to 400 viruses. I am aware of none. I think the reason for this is two fold, firstly, to write a viruses on the Mac, which by their nature need to spread, is harder due to the (*nix) security models used. But also, it seems to me viruses are getting passé and targeted emails with trojans are becoming more popular. Trojans are one thing that Macs have been shown to be susceptible to although often by fooling (social engineering) the person into clicking all the right buttons and typing in their password. I would therefore suggest that any future major problems on OS X will be due to a trojan that gets sent out and manages to auto install through an exploit rather than a virus which does the spreading on its own. The challenge for Apple is being good enough, fast enough to make sure trojan attacks are relegated to social engineering and tainted pirate downloads.
- Herring 16y agoThe Mac share of viruses is zero. If youre right & market share is the only consideration, logically that means nobody should be writing any software (eg games) for Mac either.
- evilduck 16y agoI would agree with this. Windows is a larger market to attack, but if it's lucrative to sell software to a smaller fraction of the market, it's surely lucrative to infect their computers and harvest personal info. The Apple computer marketshare is small worldwide, but inside the US, one of the richer countries in the world, Apple has a much larger representation (+20% of laptop sales, +10% desktops), and almost all >$1000 computer sales. A bank account or credit card harvested from a random Mac is probably worth a whole lot more than a random Windows computer when selecting from a global set of computers. Essentially, wealth among computer users is not evenly distributed worldwide, and Apple products are disproportionately represented in wealthier nations.
- Tamerlin 16y agoAlthough that's true, consider the larger context. One, Apple's market share has only been non-trivial in recent years, meaning since the x86 switch + the iPhone launch. Two, most viruses and hacks use the Trojan Horse method, basically attempting to trick the user into giving you something that they wouldn't normally give you. Three, even though Apple and its cult like to claim that OSX is secure, OSX automatically downloads patches, and Apple releases security patches nearly as frequently as Microsoft (but ironically isn't as diligent about closing security holes as Microsoft). To make these work, the people attempting to harvest data or simply cause harm have to play the odds. So the 100 to 1 ratio between Windows and Mac machines out there has historically been reason enough to ignore the mac as a target for hackers and viruses -- so it's very likely that as Apple's market share grows, and as people start using iPhones and iPads for more and more of their computing tasks, they'll increasingly become targets for hackers also.
- antidaily 16y agoMany of Apple's flaws are not in its operating system, Mac OS X, but rather in software like Safari, QuickTime, and iTunes.
- NathanKP 16y agoHence the title of the article says "software" insecurity. Problems with security of the OS and problems with security of the software running on the OS both have the same end effect: they make the system vulnerable.
- deleted 16y ago[deleted]
- pixelbath 16y ago"...a growing trend in the world of security flaws: the role of third-party software. Many of Apple's flaws are not in its operating system, Mac OS X, but rather in software like Safari, QuickTime, and iTunes." How are any of those third-party? They are all sold by Apple. Just because they also happen to run in Windows doesn't make them third-party.
- evilduck 16y agoNitpicking out of context? Sensationalist headline? I assume you and everyone who voted you up didn't actually read the study. What Secunia did study was described as "In the first part of the report we look at the global picture covering all vulnerabilities in all products, followed by the analysis of vulnerabilities affecting the products and the operating system found on typical end-users PCs." And all their graphs are limited to XP, Vista and 7. So...probably limited to Windows. And they also define 3rd-party software for you as non-Microsoft vendors in the sidebar of page 9. So yeah, everything by Apple is 3rd party software in the context of the study cited.
- chaostheory 16y ago"Though this does not necessarily mean that Apple's software is the most insecure in practice—the report takes no consideration of the severity of the flaws" Then what's the point?
- gizmomagico 16y ago"Eyeballs"?
- KirinDave 16y agoEveryone loves attention.
- kaiuhl 16y agoTheir report only analyzes the criticality of Windows-based exploits, and leaves Oracle and Apple bugs' severity undefined. I can't find anywhere on Secunia's website that they make a big deal out of this though, so I'm going to chock it up to Arstechnica being sensationalist.
- brianpan 16y agoI also noticed Ars becoming much more anti-Apple as well as sensationalist. Articles like Siracusa coverage on the antenna press conference as well as his twitter feed seemed oddly vindictive to me. http://arstechnica.com/staff/fatbits/2010/07/unanswered-questions-unearned-trust.ars http://arstechnica.com/staff/fatbits/2010/07/unanswered-ques... I found it unsettling considering Ars has been a top source of tech news for me in the past that I thought was very even and thorough.
- gbhn 16y agoHave you considered that an even and thorough approach to tech news may go through periods where it levels more criticism than usual at Apple?
- brianpan 16y agoOf course, one great reason to be more critical is if they deserve it. I don't think that it's merited in these cases (original article or my link). I'm trying to figure out if this is a temporary/isolated thing, a systemic change, or a figment of my imagination/biases.
- brianpan 16y agoOk, it's not just my imagination, this is link-bait if I ever saw it: http://arstechnica.com/apple/news/2010/07/international-launch-causes-rehash-of-iphone-4-antenna-issue.ars http://arstechnica.com/apple/news/2010/07/international-laun... Title is: iPhone 4 antenna woes "significantly worse" than competition 1st paragraph explains: one consulting firm says it's worse, another review says it's better. I'm pretty sure I didn't see this type of thing from Ars in the past.
- DuoSRX 16y agoThe actual report (http://secunia.com/gfx/pdf/Secunia_Half_Year_Report_2010.pdf http://secunia.com/gfx/pdf/Secunia_Half_Year_Report_2010.pdf) is only about Windows computers. So it's about iTunes, Safari ... for Windows, not Mac OSX. "In the first part of the report we look at the global picture covering all vulnerabilities in all products, followed by the analysis of vulnerabilities affecting the products and the operating system found on typical end-users PCs."
- Groxx 16y agoIn a similar vein: >Vendors like Adobe (with Flash and Adobe Reader) and Oracle (with Java) are similarly responsible for many of the flaws being reported.
- harshpotatoes 16y agoSo it sounds like the real problem is that we need to create some sort of unified updating system for third party apps, so you don't have to deal with ten different programs complaining they need to be updated. Something so simple, it only needs a single command to run. Like apt-get upgrade. Maybe they should have that for windows/mac.
- progr 16y agoOn Mac every OS-bundled program do update through a central utility found on the Apple dropdown menu. 90% of other programs use the Sparkle framework (~100% if the program is Mac-only) which provide an unobtrusive way of updating.
- SoftwareMaven 16y agoAnd then they could also have a place to make it easy to find applications, too. On top of that, they could expose it through software that (almost) everybody using OS X uses for their other media consumption. They'll call it the "Program Market"