5 ms·
Not as bad as this "Android malware attack spreads via e-mail" http://www.usatoday.com/story/tech/2013/03/28/android-malware-attack-irs-email/2028845/ http://
by sinnerswing 13y ago
Not as bad as this
"Android malware attack spreads via e-mail"
http://www.usatoday.com/story/tech/2013/03/28/android-malware-attack-irs-email/2028845/ http://www.usatoday.com/story/tech/2013/03/28/android-malwar...
http://securitywatch.pcmag.com/mobile-security/311417-windows-malware-techniques-spread-to-android http://securitywatch.pcmag.com/mobile-security/311417-window...
- myko 13y ago1) What does that have to do with this? 2) FTA: >Q: What can or should individuals do? > Stone-Gross: Do not allow installation of applications that are not distributed through the official Google Play marketplace on the device So this malware isn't effective unless the user explicitly makes their device vulnerable, doing something normally only developers or hard core users - people who are likely to spot this attack - would do.
- nicheuser 13y agoPeople were saying for years that the superior UNIX design and the bad Windows code is the reason that Windows had a huge malware problem but Linux and Mac did not.
- pyre 13y agoPeople were mostly talking about drive-by infections and the fact that an unpatched Windows machine idling on the Internet could be infected in an hour or so. There's nothing anyone can do if a user installs software. UNIX design or not, if the user runs a program, it can access everything that the user can. Nothing that this malware did needed special access (e.g. root exploit).
- mikeash 13y agoThat's a highly UNIX-centric attitude. There is no reason in general that an app should be able to access everything the user can access. For example, Mac and iOS apps cannot access the user's contacts without the user's explicit permission, even though the user can access the Contacts app themselves just fine. The idea that all apps run under a single "user" and all share the permissions of that "user" is just how UNIX does it, not how things must work. I don't think we've figured out proper app sandboxing yet (Mac, iOS, and Android all have their problems with it, and differently) but it seems to be the way to go.
- pyre 13y agoThe security is still in the hands of the user. An app can ask for a handful of permissions that the user can just agree to. The user is still compromised, but now you can pin even more blame on the user. That doesn't help any.
- FireBeyond 13y agoAnd for the last several years plus, the very vast majority of Windows malware has been similar in nature. But that's never really stopped the Apple faithful from being in willful denial about the same. - a recent convert to Apple
- pyre 13y agoA good question to ask would be, "How many local privilege escalation bugs have popped up in Windows vs. Linux vs. OSX?"
- claudius 13y agoIf you put in a lot of effort, you could try mounting /home and other user-writeable areas as noexec, use SELinux/AppArmor to do funny things to confine administrator-installed programs etc. etc. However, this will break nearly everything – and I am rather positive that Windows offers similar security measures, if required.
- glhaynes 13y agoThis is basically sandboxing by hand.
- pflats 13y agoIt was. Windows has since improved its security by a large amount. Windows XP and Windows 7 are two completely different beasts, and even XP is far more hardened than it was at release. (I'm not an expert, but I'd point to the ASLR in Vista as the harbinger of improved Windows security.) Now the malware problems on both platforms rarely rely on privilege escalation. They use trojan horses instead, and wait for you to install them.
- korethr 13y agoAll the inherent goodness or badness of the design or implementation of $OS or $APP is ultimately trumped by the user when it comes to security. It is entirely possible to run Windows without any anti-virus/malware protection or firewall, and have the system remain clean for months or years. It is similarly possible to be careless and irresponsible with a Mac or Unix system and have it get compromised in short order. It all depends on the actions of the person running the computer.
- glhaynes 13y agoThat doesn't mean it's equally easy for the user to be careless on all of those systems, and I think that's important.
- makomk 13y agoAt the time when people started saying that, this kind of attack was a lot easier on Windows, because by design installing arbitrary code off the Net was a single click away and the attacker had a huge amount of control over the contents of the request. Since then, Microsoft has improved but Apple has somewhat repeated Microsoft's old mistakes.