3 ms·
This is why I find this policy ironic and silly. MacOS is the largest target of choice for bad actors as late because the ratio of high value/low chance of reje
by leeter 4y ago
This is why I find this policy ironic and silly. MacOS is the largest target of choice for bad actors as late because the ratio of high value/low chance of rejection users have migrated to Mac over the past few years because of the whole "Macs are safer" myth. To the point that an exploit for MacOS goes for a lot more money not because they are all that rare but because the value of the targets is greater.
MacOS CVE details as late: https://www.cvedetails.com/vulnerability-list/vendor_id-49/product_id-156/Apple-Mac-Os-X.html https://www.cvedetails.com/vulnerability-list/vendor_id-49/p...
Windows: https://www.cvedetails.com/vulnerability-list/vendor_id-26/product_id-32238/version_id-677478/Microsoft-Windows-10-21h2.html https://www.cvedetails.com/vulnerability-list/vendor_id-26/p...
Note how the windows ones are more up to date and patched faster? That's because Mac only does major updates on a cycle and doesn't patch out of band ever if they can avoid it. So yeah I think this is all theater and people's own biases being silly. But if it works for them then that's fine.
- ziddoap 4y ago>MacOS is the largest target of choice for bad actors as late I work in cybersec and am in daily contact with a few threat analysts. Not one of them has said this or believes this. Do you have some reputable source that can confirm this, or is this just a feeling you have? >Note how the windows ones are more up to date and patched faster? The presence of, frequency of, and patching of CVEs has very little relation to real-life attack frequency and targets. People are still getting owned by EternalBlue on unpatched machines from 5 years ago, doesn't matter how fast the patch is released if people aren't applying it. >That's because Mac only does major updates on a cycle and doesn't patch out of band ever Same with Windows. Heard of Patch Tuesday? The regular cycle of once per month that Windows does updates? They avoid releasing updates on other days unless it is high severity and there is evidence of active exploitation, and when they do out-of-band security updates it's almost always covered in some media and/or CISA releases because out-of-band updates are noteworthy.