3 ms·
> An uptick in users installing adware on their computers (yes, you have to manually install it) is a far cry from having a platform blighted by drive-by infect
by Niten 15y ago
> An uptick in users installing adware on their computers (yes, you have to manually install it) is a far cry from having a platform blighted by drive-by infections and autonomously spreading worms as Windows was in years past.
Well yes, but lately how are these drive-by installations happening? Mostly through holes in third-party software. My concern, as a Mac user, is that there's no fundamental reason it should be any harder to attack OS X this way; it's just that up until now Windows has been a vastly more profitable target. And that is changing.
If you're a careful and conscientious user I'd honestly say you're safer on Windows at this point, because Windows is used to being attacked. It's used to defending itself against this kind of threat. You have this ecosystem of powerful antivirus programs like MSE or AntiVir that update themselves constantly, and innumerable other third-party tools such as Secunia PSI as preventative measures, and these just don't really exist on OS X yet. Windows also yet has some exploit mitigation facilities that OS X lacks, such as ASLR and kernel patch protection.
It will be a while before OS X has developed such an ecosystem of its own, and we just have to hope the adjustment period won't be too painful.
- bandushrew 15y ago'but lately how are these drive-by installations happening? Mostly through holes in third-party software' nope. by the user running an installer when requested by a browser ad popup.
- Niten 15y ago> nope. by the user running an installer when requested by a browser ad popup. I agree that this is how most malware happens in general, but I was talking specifically about the subset of malware installations that are drive-by downloads, i.e. which are performed without user interaction: http://en.wikipedia.org/wiki/Drive-by_download http://en.wikipedia.org/wiki/Drive-by_download What I mean to say is that most of those are exploiting third-party software (Java, Adobe Flash and Reader) rather than Microsoft stuff these days.
- Pheter 15y agoThe first point your link makes is that Drive-by downloads includes user intervention: "Downloads which a person authorized but without understanding the consequences".
- danssig 15y ago>and these just don't really exist on OS X yet And hopefully they never will. This is the stupidest possible way of protecting your computer. The proper solution is a more modern security system like SELinux instead of this outdated user/group/others approach.