9 ms·
OS X – Safe, yet horribly insecure
- yalogin 15y agoThe whole article seems overly emotional and not objective at all. The only thing I agree with are that ASLR and DEP are not implemented as well as they could ( though I have not looked at it myself).
- zdw 15y agoThey often share vulnerabilities with core libraries in other UNIX like systems with samba and java being two examples. Good thing that Lion jettisons both (Samba for going GPLv3, and Java is non-core download) The firewall functionality in OS X is impressive, but hardly utilized. The underlying technology is ipfw Also changed in Lion, which now uses OpenBSD's pf. Apple doesn't make much more use of it though. It has been a shame to see the sandboxing functionality introduced in Leopard not being utilized to anywhere near its full capacity. That's changed as well in Lion, as any Mac App Store developer can tell you.
- vogonj 15y agoThe point he was trying to get across is that Apple shares attack surface with other Unix operating system vendors, which -- given his assessment of them as derelict in resolving vulnerabilities -- increases the harm their users are exposed to while Apple is sitting on fixes that other vendors have already written and deployed. No piece of software is synonymous with insecurity -- except, perhaps, Sendmail. ;)
- gonzo 15y agoOpenBSD's pf? I highly doubt that Jordan Hubbard took the OpenBSD tree's variant. More likely it came directly from FreeBSD. (Yes, I know that 'pf' started on OpenBSD.)
- hackermom 15y agoYour parentheses seem to imply that the OpenBSD team only started PF, and then let go of development, which isn't the case at all. The OpenBSD team is still the lead developer of PF, and FreeBSD sources changes from "The Source". To the best of my knowledge, there are no notable PF forks around from which the OpenBSD team can, or ever have sourced changes from, but I'd be happy to learn otherwise if you have any accounts to share.
- gonzo 15y agothere is no "lead developer". Shall we discuss why pfSense is based on FreeBSD, not OpenBSD?
- hackermom 15y agoBecause the developers of pfSense are FreeBSD users? I fail to see your point with that. And I beg to differ regarding the "no lead developer". Indulge yourself by looking at the OpenBSD changelog from release to release, year by year, and notice how every single change, minor and major, stems from there, and radiates out to, f.e., the PF port in FreeBSD.
- zdw 15y agoAh, so they get a version that is several years out of date, and uses a slightly different syntax... great.
- there 15y agowhat have freebsd contributed to pf?
- gonzo 15y agodon't get me stared on the lamefest that is OpenBSD
- fourspace 15y ago11px font with 19px line height? Uf, not for my tired eyes. Fixed with this CSS snippet: p { font: 16px "Lucida Sans Unicode", "Trebuchet MS", Verdana, monospace; }
- beaumartinez 15y agoMy go-to bookmarklet for poor article design: Readable (not Readability). Someone posted it as a Show HN a few months ago and I haven't looked back since―it's incredibly fast and very customisable. http://readable.tastefulwords.com/ http://readable.tastefulwords.com/
- ralfd 15y agoOr the "Reader" functionality in Safari or just enlarge the Text with ⌘+ which every Browser can.
- yuvadam 15y agoWouldn't a simple ⌘+ be easier?
- comex 15y agoAlthough it's not officially documented, Snow Leopard's sandbox is already quite capable and easier to use than the norm; it's nonsensical to list "sandboxing" and "mandatory access controls" as wins for other operating systems. Lion will make it mandatory for all App Store apps and add features like a secure open dialog (where the OS handles the open dialog and gives the app access to only user-selected files) and an easy-to-use privilege separation API (to make it easier to take advantage of the sandbox); the result is much more advanced than anything mainstream in Windows or Linux. Lion will also get rid of previous limitations on DEP and ASLR; in particular, it randomizes dyld. The article also seriously underestimates the benefit of the centralized App Store model (which has an equivalent in Linux, but not Windows); despite all the horrible rejections and review issues, if it becomes the usual way to obtain Mac applications, it will greatly reduce the chance that users will come into contact with malware.
- ralfd 15y agoI want an optional feature which only allows the OS to execute MacAppStore programs. This would be "grandparent proof" and would prevent trivial kinds of social engineering used by MacDefender (which targeted clueless users).
- meemo 15y agoIf they did this (even as just an option), then there'd be an uproar about how they're incrementally making os x a completely closed system (a walled garden).
- X-Istence 15y ago> The Unix Design is significantly less granular than that of Windows, not even having a basic ACL. The UNIX design came from a time when security was less of an issue and not taken as seriously as it did, and so does the job adequately. Windows NT (and later OSes) were actually designed with security in mind and this shows. This comparison doesn't even make sense, comparing a decades old UNIX design to a comparatively newly designed OS (Windows NT). POSIX permissions have stood the test of time for a long time and by far were much better than what was available in Windows for the longest time. Off course Windows NT has improved on what was available at the time. That being said, Mac OS X since 10.4 has had ACL, so that argument goes right out of the window. ACL's are enabled by default and they function as designed. touch testing chmod 700 chmod +a "otheruser allow delete" su - otheruser ls -lahe testing rm testing > They often share vulnerabilities with core libraries in other UNIX like systems with samba and java being two examples. That is because they use that exact open source software. This is a simple no shit sherlock kind of deal. Luckily those are going away and won't be in Lion. Java will be an extra download, like Adobe Flash and Samba won't be included by default because of the GPLv3. Apple's policy regarding third-party software vulnerabilities could definitely be improved, and they already have, but it could still be better. Ultimately many of the third party tools they ship are never used by consumers and even though they may be exploitable they aren't accessible to an attacker (looking at you PHP ...) > They are extremely difficult to deal with when trying to report a vulnerability, seemingly not having qualified people to accept such reports. Even if they do manage to accept a report and acknowledge the importance of an issue they can take anywhere from months to a year to actually fix it properly. This has been fixed recently, they have a new head of security [1] and have increasingly shown that they are getting faster at closing bugs and bringing out updates to fix issues. Look at the Pwn2Own contest iPhone bug, Apple was notified and an update was made available that fixed only that one flaw. Do I think they are doing the best of job? No, MSFT has them beat by a mile with their security response team (really impressive), however the above sentence makes it sound like this is still the case which is no longer true. -- It is a pretty good article in that it shows that there are certain issues that Apple could definitely improve upon, but completely ignoring any development to OS X for the past couple of years doesn't look good at all especially when the flaws you are attempting to point out have already been fixed. [1] http://threatpost.com/en_us/blogs/apple-hires-new-security-chief-012411 http://threatpost.com/en_us/blogs/apple-hires-new-security-c...
- epistasis 15y ago>Personally for me, malware is a minor threat with the impact being negligible as long as you follow basic security practices and can recognize when something looks out of place. Likewise, with proper security knowledge, the holes that Apple leaves unpatched for months are "minor threats." For example, disabling Java in the web browser when there's a known vulnerability. It's an inconvenience, but so is having to always be on the watchout for things that are out of place. Apple is not fantastic on security, but they are good enough for the current threat level, as long as you take basic security precautions.
- vogonj 15y agowith apologies to ESR: "with sharp enough eyes, all bugs are visible." "the impact [is] negligible as long as you follow basic security practices and can recognize when something looks out of place" is a worthless statement, because the majority of users have repeatedly proven to be unable to do that (hence MacDefender, hence the largest families of malware on Windows being fake AV.) it also makes it too easy to hand-wave away security threats. you got a trojan on your MacBook? you obviously weren't following basic security practices.
- quinndupont 15y agoSo, let's review the actual exploits listed here (since, the author says, it isn't just FUD): ASLR & MacDefender... Hmm... hardly a damning criticism.
- mcritz 15y agoI was thinking the same thing. A subheading in the article is “Malware for OS X Increasing.” He does a poor job substantiating that claim, IMHO. I don't want to point fingers at Chicken Little, because I agree with the thesis; Apple needs to be more serious about OS X security.
- ralfd 15y agoWell in the years prior there were zero and now there is one. This is an increase of infinity percentage! Okay, beside the snark it is true, Apple should maintain security bugs better and "File Quarantine" looks to me rather rudimentary: http://support.apple.com/kb/HT3662 http://support.apple.com/kb/HT3662 But as long as the "Trojan Botnets" he mentions are simple PHP scripts which are distributed years ago by pirating Photoshop and are simply killed by deleting the file and a reboot I personally stay feeling pretty secure. http://blog.notahat.com/posts/28 http://blog.notahat.com/posts/28
- scottw 15y agoAgreed; follow the link the author offers near the top of the article to Secunia. Of a few common OSes I looked at (Red Hat Enterprise 5, Windows XP Pro, Windows 7, OS X), OS X had the fewest advisories for 2009, 2010, and 2011; most vulnerabilities seemed to be of a more benign nature than other OSes. Perfect? Probably not, but it's still the OS I'm going to recommend to my mom.
- vogonj 15y agoApple has fewer advisories because it's their standard operating procedure to sit on security bugs for several months and then patch them all at once, even if their contemporaries are patching them as they appear. If you look at the numbers for OS X as opposed to Windows XP, OS X has 1,544 vulnerabilities in 153 advisories (~10.1 vulns/advisory) and Windows has 472 vulnerabilities in 358 advisories (~1.31 vulns/advisory). Unless you have a good reason to believe that bugs in Windows are nearly eight times "more unique" than bugs in OS X, please don't compare advisories.
- crag 15y agoFirst, the author is right. Except his article is a boring read; repeating himself over and over and over and over again. Yeah, I get that OSX is not secure. Now move on and tell me why. In short, I wish the author would not write like a lawyer (unless of course he IS a lawyer).
- 5teev 15y ago> A lot of OS X users seem to have this idea that Apple hired only the best of the best when it came to programmers while Microsoft hired the cheapest and barely adequately skilled... Is this really a commonly held belief? I've never encountered anyone expressing this opinion.
- olliesaunders 15y agoIt’s possible some people might believe that, perhaps not HN readers But the quality of the management plays a very important role in the quality of the end result: Apples has Jobs and Microsoft has Ballmer. So Microsoft is at a disadvantage human-resource-wise.
- vogonj 15y agoAs an engineer (though admittedly one at Microsoft), Steve Jobs seems like he'd be a /horrible/ boss. All appearances suggest that he doesn't care about good engineering, but rather that he cares about good user experience, damn the torpedoes.
- tres 15y agoThis statement reveals so much about what's wrong with Microsoft... Good engineering is good user experience.
- shadowfox 15y agoI wouldn't disagree that good engineering includes good user experience. But I would have thought that good engineering would include a bit more than that.
- seanp2k 15y agoGood UX engineering is good UX engineering. Software engineering / architecture / development in general is not necessarily the same. An app can be beautifully engineered by have an awful UX. The inverse is less likely to be true (because bugs and obvious flaws like long delays and unresponsive UIs can quickly degrade UX), but still possible.
- fedorabbit 15y agoI wouldn't go so far say Mac is more secure than Linux, both are Unix-based. As for my user experience, Mac OS X is by far the best.
- skybrian 15y agoThe author may have some good points, but this essay is so poorly organized that it's hard to tell what they are or put them into proper perspective. It's mostly a good argument for teaching essay-writing in school.
- skybrian 15y agoThe author may have some good points, but this essay is so poorly organized that it's hard to tell what they are or put them into proper perspective. It's mostly a good argument for teaching essay-writing in school.
- deleted 15y ago[deleted]
- hollerith 15y agoThe presence of "tl;dr" at the start of parent might give the reader the idea that parent is a summary of the OP, which it definitely is not.
- ralfd 15y agoIt is also bad practice to not read the submission and instead just jump into comments. (I admit I'm sometimes guilty by it myself.)
- deleted 15y ago[deleted]
- molecularbutter 15y agoDoes anyone have a version of this article with an even smaller font size? Maybe something that requires a microscope to read? Size 8 font isn't blinding enough.
- api 15y ago"The Unix Design is significantly less granular than Windows..." That's why it's more secure. Complexity means you don't know what's going on. Complexity means you will forget something. Complexity means there's more likely to be a way to squeeze through, more likely to be a bug, more likely to be a little thing that is forgotten. This is also a problem with complex cryptographic APIs, overly complicated things like PKCS11 and X.509, etc. It's curious that security-related systems are among the most complex, since complexity is inherently bad for security. I call it a lack of "situational awareness."
- nwmcsween 15y agoUnix by far is not secure. Access control via unix permissions is a mess, this is why we have selinux, apparmor, smack... The whole 'complexity' argument is moot todays unix with selinux, chrooting, jails, apparmor is much more complex than say a capability based security.
- X-Istence 15y agoACL's are not even close to what selinux, apparmor, and smack are trying to accomplish.
- nwmcsween 15y agoI never said anything about access control lists
- Hawramani 15y agoCan you mention specific issues with Unix permission management that Windows solves?
- Goladus 15y agoOne example: given a file, you can create several different access levels. One group can be read-only, one group can have read and write but NOT delete, one group might only be able to modify permissions, and one group might have full access to the file, while "EVERYONE" has no access at all. Administrators, incidentally, need not have access beyond "take ownership" which is an obvious and easily-audited action. These are all standard features in most ACL-based multi-user environments. Unix file permissions don't use ACLs, so off the top of my head I'm not sure how you would set this up on Unix. For one thing, I am pretty sure w implies delete permissions. So that group can't even exist, and if it could, there's no easy way to have that group be different from the read-only group, and still have a no-access-at-all group. I suspect most complicated requirements can be resolved with some combination of sudo and traditional permissions but it's not always straightforward and probably won't be exactly equivalent to the way you would do it in Windows.
- andos 15y agoJust as a curiosity: yesterday I watched a talk by Thomas Ptacek at some indie Mac dev conference where he showed, en passant, how some kludges used by Apple produced vulnerabilities in Mac OS X. It’s old, fixed stuff by now, but I was like “WTF?” all the same. Because it’s very stupid stuff from Apple. Here’s the talk, slides (check slide 11), and related blog post: http://www.viddler.com/explore/rentzsch/videos/31/ http://www.viddler.com/explore/rentzsch/videos/31/ http://www.slideshare.net/tqbf/c42-software-security-presentation http://www.slideshare.net/tqbf/c42-software-security-present... http://chargen.matasano.com/chargen/2009/9/24/indie-software-security-a-12-step-program.html http://chargen.matasano.com/chargen/2009/9/24/indie-software...
- mahrain 15y agoI don't see why this is discussed so much, afaik this article just says "Windows is more secure than OSX", mentions Mac Defender and goes on OSX about market share... The same story Mac users have heard for the last 10 years. Nothing new here, moving on, and remembering the days of Melissa, Kournikova, Sober, MyDoom etc...
- 16s 15y agoOne point I would add is that by default, Macs have Perl, Python and Ruby (I think). So it's easy to script malware or write portable tools. I'm not suggesting that these languages are insecure or should not be installed, only that a malware designer can pretty much count on having them available to use. This may make Mac/Linux cross-platform malware easier as well.
- X-Istence 15y agoThose applications aren't launched or available from the outside. If the user runs/double clicks on something it is already game over. Social engineering attacks are never going away so long as humans are humans and want to see Anna Kournikova naked.
- rryan 15y agoI was struck by the part about the OSX ASLR implementation. I can't believe they only randomize library loads :-/.
- getsat 15y agoIt is weird, but ASLR and DEP are regularly bypassed, anyways.
- davidu 15y agoThis is actually just the tip of the iceberg for OS X vulnerabilities. On the enterprise side, it's much much worse. AFP is heinous. Their kerberos implementations are painful. They actually have checkboxes in OS X server config screens that say: "Prevent man in the middle attacks? Yes or No?"
- X-Istence 15y agoI don't know any enterprise installations of Mac OS X Server that use AFP. As for kerberos, that is painful on any platform. At the moment at work I am trying to figure out why Mac OS X takes 10 minutes to connect to a Windows Server 2003 based file share, all I see with Wireshark is a bunch of Kerberos stuff being thrown around, whereas Windows clients connect without issues, but without ever attempting to use Kerberos.
- vogonj 15y agoyour Windows clients are probably using NTLM (or NTLMv2), Microsoft's old, terrible auth protocol that the Windows team eventually abandoned for Kerberos. there are policy settings you can change to force Kerberos; I'd suggest Googling to see if you can find them, and see if it breaks your Windows clients as bad as your OS X clients seem to be.
- X-Istence 15y agoI had not thought about that, would OS X fall back to using that in case Kerberos doesn't function? Thanks for the suggestion!
- lulz1234 15y agopersonal opinion about security is all well and good but they wont make you any more or less secure either for what its worth osx really provides nothing impressive on the security front
- lulz1234 15y agopersonal opinion about security is all well and good but they wont make you any more or less secure either for what its worth osx really provides nothing impressive on the security front but apple seems is however trying to catch up with everyone else it seems so that's good... quicktime, itunes their pdf rendering system, how their updates are handled and now they respond to and treat security researchers .. I mean just look at the permissions on the binaries in your applications directory or plugins in ~/Library seriously?
- berkes 15y agoIt is a pity the author does not include at least one Linux distro. Especially for the mentioned "targeted attacks", servers are the most likely targets. And in the servermarket, OSx is hardly around, and is the share of various Linux servers growing larger then Windows, even.
- bborud 15y agoI read until the author expressed a preference for granular ACLs rather than a less complex security model. Security starts with an aversion towards complexity. No point in reading the rest of the article.
- speleding 15y agoApple did one thing very well: they ask for a password when doing something potentially harmful, but made sure that the password popup is rare enough that you won't be trained to blindly fill it in. That one thing has more security value than any of the advanced security techniques listed in the article like "stack canaries" and "fine grained ACL". It's too bad there are so many security consultants that focus on the technology instead of user behaviour. If they would just look at the statistics they'd see that >90% of security issues are not technology issues, they are behavioural issues. Sure, it would be nice to have a few of those advanced security techniques in OS X if they don't cause too much usability or performance issues, but it will have very little effect on security as a whole.
- comex 15y agoHowever, you only need the password if you want to be root, and most of the stuff malware wants to do (including keylogging, which the article mentions; requiring root to intercept keyboards is only moderately useful if the regular user can gdb -p whatever app has the password field) does not require being root.
- X-Istence 15y agoIf you want to attach a debugger to a program in OS X you are required to be in a developer group, and it will ask you for a password. See: http://i.imgur.com/l6Ntz.png http://i.imgur.com/l6Ntz.png
- adsr 15y agoIs it only me who find it funny that the name is allthatiswrong given how many factual errors there are in there. :) Can't quite make up mind if the author is trolling or if he have just failed to read up on the topic he tries to school us in.
- ricardobeat 15y agoThe blog post wont open on an iPad...
- getsat 15y agoYou need cookies enabled to get past their interstitial ad.
- gnubardt 15y agofound this to be salient, there's a lot of malice to be done in plain sight of an ignorant user: Root access is only needed if you want to modify the system in some way so as to avoid detection. Doing so is by no means necessary however, and a lot of malware is more than happy to operate as a standard user, never once raising an elevation prompt and silently infection or copying files or sending out data or doing processing, or whatever malicious thing it may do.
- ravivyas 15y agoAll things said and done , one of the biggest flaws will be both Unix and Max giving a user the sense that both are secure and nothing can go wrong. That is the same reason Mac Defender worked.