8 ms·
Mac OS X Isn’t Safe Anymore: The Crapware / Malware Epidemic Has Begun
- stephenr 12y agoBreaking news: Free download sites like Download.com are shit. More at 11.
- jkot 12y agoOSX will become walled garden just as IOS. I am personally happy for that, many developers will return to Linux.
- karlshea 12y agoIsn't that kind of cynical? If Linux on the desktop was compelling, they wouldn't have left in the first place.
- bluthru 12y agoApple knows that their computers are a favorite amongst developers. No way would they do that. Apple already made their move and it was a nice compromise called Gatekeeper.
- trebor 12y agoAs a Mac user who migrated from Windows, I had no doubt that it was only a matter of time before Macs became more lucrative targets. Anyone who thinks that their OS of choice is unassailable is fooling themselves.
- protomyth 12y ago"Examining further comes up with something curious… the person who wrote this malware wanted to give special thanks to his mom." That's the old default Credits.rtf.
- JamesBaxter 12y ago"We’d love to see Apple fix some of the App Store issues and make everybody use it." I agree with the first part of this but not the second.
- abrowne 12y agoI've seen a lot of Mac users with adware in the last few months. I've found Adware Medic[1] to remove nearly all of it pretty easily. [1]:http://www.adwaremedic.com/ http://www.adwaremedic.com/
- corv 12y agoSeconded, AdwareMedic is quick and painless. Power users might also appreciate Little Snitch[1] to see what their Mac is connecting to. [1]: http://www.obdev.at/products/littlesnitch/index.html http://www.obdev.at/products/littlesnitch/index.html
- abrowne 12y agoI forgot to mention, after running AdwareMedic, make sure to check browsers' search engine and homepage settings.
- tedunangst 12y ago> It wasn’t that long ago that you could install almost anything for OS X from almost any website, and you didn’t really have to worry about what you clicked on. Full stop. That's a ridiculous statement to make. Are we really pining for a return to such an oblivious mentality? Good riddance.
- smackfu 12y agoIt's a true statement though. OS X users avoided malware by there not being malware, not by being smarter or being protected.
- tedunangst 12y agoIt's along the lines of "Not long ago I could back out of my driveway without even looking, but now my new neighbor's kids play in the street." I will stipulate it's a true statement. Still foolish.
- swang 12y agoUhm, Apple had an entire campaign about it. "No worries about viruses and other things affecting PCs!"
- wvenable 12y agoBut it was true; many years ago it was prevailing wisdom that Mac's were just virus and spyware free. I'd like to think most technical people realized that Mac was simply not popular enough to be targeted. But most users were simply under the impression their choice of OS was magically protected. From article: "Since it is actually Unix under the hood, OS X has some native protection against the worst types of viruses." Hey look, it's got Unix, I'm totally safe.
- smackfu 12y agoPart of the problem is that a lot of legitimate freeware / open source software is not signed. I assume because people don't want to pay the $100 a year just to support OS X. So people get used to installing unsigned software, and then end up installing malware.
- 3JPLW 12y agoCNet's downloader app looks like it's signed. It warns that it was downloaded from a website (which it was), but you don't have to do the right-click-open song and dance.
- comex 12y agoI'd love to see Apple take a stand and revoke their certificate. Usually I strongly support developer freedom / openness, but these apps are straight-up malware. Having a decline option somewhere doesn't matter if essentially all users who accept do so unintentionally.
- shalmanese 12y agoThe official Silverlight installer from Microsoft wasn't signed, leading me to a half hour search to make sure my browser wasn't hijacked before reluctantly installing it. Kind of defeats the point of signing when it's that untrustworthy.
- JohnTHaller 12y agoNow that Mac OS X has hit about 7% of internet users, it's profitable enough for adware/malware folks to target. Most of the infections on Windows aren't due to some huge security issue on Windows that Macs are magically immune to. They are due to the users themselves installing adware or malware-infected software from sites online. Now that there are more Macs out there, the reward is greater. So, there is more revenue to be made form adware-laden software and a better return for the time investment/risk of creating malware for Macs (to send out spam, be used in DDoS attacks, sniff for and steal financial info and passwords, etc).
- nkozyra 12y agoThis is a common (and tired) response but it's really not entirely true - Windows does in fact have a lot of potentially catastrophic holes that are innately tied to higher privileges for users. Most of what Windows has implemented since 7 with UAC, MSSE and now integrated with Defender is a layer on top that introduces some failsafes. I won't argue that it's been a massive and much-needed improvement to Windows, but Java and Flash still provide viable vectors to bypass it and infect a Windows machine. Designing actual viruses - stuff that has the ability to read and modify the filesystem - is still harder to pull off undetected on OSX. This article intimates as much. Most of what's included here is either bundled applications you don't want - but you still have to actively find and then agree to - or browser modifications. Neither of those is within 500 sqmi of, say, CryptoLocker.
- JohnTHaller 12y agoI never claimed that Windows or Mac OS X are more or less secure than the other. I very specifically said the following: "Most of the infections on Windows aren't due to some huge security issue on Windows that Macs are magically immune to. They are due to the users themselves installing adware or malware-infected software from sites online." This is 100% accurate and what most home users have to deal with in terms of issues on Windows. The vast majority of Windows issues that end users experience and get frustrated over have nothing to do with Java or Flash flaws or needing to compromise a system. The users themselves give the apps permission to install and do their thing. It's also worth noting that Java and Flash don't provide much of an attack vector for the majority of Windows users you and I know anymore either. Firefox won't permit outdated versions of the Java or Flash plugins with security issues to run and will direct you to update. Chrome has its own version of Flash built in and automatically updated with the browser and disables Java by default. Even Internet Explorer blocks outdated ActiveX plugins like old and insecure versions of Flash and Java these days.
- joncameron 12y agoHow about a non-Apple App Store: something like homebrew with a friendly GUI that's easy to navigate? I started using Homebrew Cask recently, and it seems like a perfect workflow for the average user who just wants to download VLC or whatever. I'm imagining Grandma pulling up the "Application Warehouse", let's say, and clicking a download button under a VLC icon. It gets downloaded from a trusted source over HTTPS, gets checked against a hash, symlinked and Gran's ready to go, all without the hassle of shady installers from the search engine shitpile.
- ShinyCyril 12y agoBrew integration would be nice. There used to be a couple of non-Apple app stores, but most of them were killed off when the actual App Store came along. MacUpdate is still running one though: http://www.macupdate.com/desktop/ http://www.macupdate.com/desktop/
- astrodust 12y agoMicrosoft really should consider making something like Ninite (https://ninite.com https://ninite.com) a native component of Windows 10. It skips all the garbage and installs the application.
- beamatronic 12y agoThis would require Microsoft to take a stand on behalf of the consumer
- Someone1234 12y agoThey are/have. In Windows 10 it is called "OneGet." It is a Linux-like package manager to complement their Windows Store (app store) which isn't going away.
- gress 12y agoHow is this better than the Apple App Store? As soon as you have multiple ones, nobody knows which one to trust.
- amalag 12y agoI cleaned some crapware off an acquintances computer. She is around 70 and didn't know why the computer was not behaving correctly. It was really easy compared to windows crapware. When my dad's Windows computer had malware I had to reformat . But with OSX I deleted a plist or two and it was done.
- mrks_ 12y agoI have to disagree with this. At my current job I deal with a lot of Mac malware/adware, and fully removing it is complicated process. After clearing the applications folder and removing browser extensions, you have to check a lot of folders, and you kind of have to know what you're looking for. In /Library/ for example, you have to check Application Support, Extensions, Frameworks, LaunchAgents, LaunchDaemons, PreferencePanes, and StartupItems. I like OSX, but it definitely needs a MalwareBytes equivalent.
- coldtea 12y ago>Mac OS X Isn’t Safe Anymore: The Crapware / Malware Epidemic Has Begun Yeah, not really. Like it hadn't began all the other times in those last 14 years that such articles appeared. I've used Windows for decades (still do ocassionally), and had lost count of malware, adware and viruses I had to battle. So, don't tell me about "malware epidemic" on OS X with a straight face...
- dublinben 12y ago>adware and viruses I had to battle This is largely a user problem now. I haven't caught a single problematic download on my Windows 7 box.
- josephlord 12y agoSee recent Lenovo issue. It isn't a user problem but an ecosystem problem starting with the OEMs and the general discovery and distribution of software.
- snowwrestler 12y agoIt's also a user problem on Macs--and really, it always had been. I use and like Macs but they've never been invulnerable.
- goalieca 12y agoI wouldn't be so confident. Most viruses now are pretty stable and silent. They don't crash your system and they don't eat up all your bandwidth. They'll get you when you log in to your banking website or they'll use you as part of an attack on someone else.
- RexRollman 12y agoI've noticed that people are quite liberal with the use of the word "epidemic".
- WorldWideWayne 12y agoI've been using Windows for over 20 years and I've had very few (exactly 2) personal battles with malware and those were on Windows 95 and 98. Why don't you try looking things up and scanning them before installing? Whatever you're doing doesn't seem to be working. EDIT: A commenter below reminded me of another rule that I follow when I get a new machine: Always do a clean install with my own copy of Windows (usually from MSDN or an upgrade offer).
- raverbashing 12y agoI click on all MacKeeper ads I see, repeatedly Let the fuckers pay for that
- spacehome 12y agoYou see ads?
- raverbashing 12y agoSometimes when I run without Ad blockers...
- MBlume 12y agoThat's a really damning Yahoo screenshot and it matches my experience pretty well. Yahoo is not an acceptable search platform and I'm really confused about why Mozilla thinks otherwise.
- pix64 12y agoMoney
- Someone1234 12y agoAs an aside: Everyone who read this article, please keep in mind that the process injection model used by these pieces of adware is exactly what your typical "keylogger" uses also. No malware literally logs keys typed anymore. I cannot stress that point enough. Instead they log form submissions (e.g. POST requests) which give the malware author much more useful information they can data mine in an automated way (e.g. URL, named parameters, etc). This works even on a "secure" page (e.g. HTTPS with extended certificate). I'm super tired of supposed power users or "geeks" telling others to copy/paste in their username/passwords to improve security. That's not how this works, it isn't how any of this works. Nobody reads raw key-streams, they're completely useless because they fail to contain CONTEXT (i.e. where you typed what). Sorry, just a pet peeve of mine. The term "keylogger" is largely a misnomer. A more accurate name would be "credential hijacking" or "form submission theft." A lot of malware actually use standard injected JavaScript to add event hooks to a page, to fire the data back to a evil browser extensions.
- bhayden 12y agoDon't a lot of login forms hash passwords with JS before sending it over the internet? Wouldn't it then be useless to anyone listening?
- Someone1234 12y agoI cannot think of a popular site which does this. If that provides security really depends on what the "bad guys" are hooking. If they're placing event triggers straight onto text box/button/form elements themselves (either through JavaScript or grabbing something akin to Win32 messages) then that wouldn't do anything at all. Even if they did grab the raw POST request (which is somewhat common) a hash would only provide security if it was merged with an anti-forgery token sent from the server, otherwise the "bad guy" could just re-post the exact same hash and login anyway. I think it really boils down to how popular your site is. If for example Facebook did that, because it is popular enough with the "bad guys" they're going to spend the time circumventing any JavaScript-based security you could implement.
- 12y ago
- geoelectric 12y ago"If you do stick to the App Store, you have nothing to worry about. We’d love to see Apple fix some of the App Store issues and make everybody use it." Yeah, that'd be just awesome.
- Someone1234 12y agoDevil's advocate here: That could just be the default, and the user could disable it. On Windows 8/8.1 the default is for the "SmartScreen Filter" to block "unrecognised" applications from being run or installed. See their FAQ [0]. It can be disabled however. If someone is smart enough to be installing applications from third party sources themselves, then they're smart enough to flip a switch in a Preferences panel to enable it. However this does protect the lowest common denominator who these malware are actually targeting (i.e. computer illiterate individuals who will click ads in search results). [0] http://windows.microsoft.com/en-us/windows7/smartscreen-filter-frequently-asked-questions-ie9 http://windows.microsoft.com/en-us/windows7/smartscreen-filt...
- geoelectric 12y agoIf it can be disabled, I'm less bugged by it. It's still a lot of friction for the acceptance of open source apps and other "not really appstore-compatible" projects, though.
- ocdtrekkie 12y agoApple was never good at security, they just weren't a big target. Now they're both bad at security AND a big target.
- coldcode 12y agoI've been a Mac developer since 1984 and the last time I ever saw a virus was 1988 I think. It's not impossible to get irritation-ware if you download random crap from these download sites but genuine malware is extremely difficult to produce. Saying "Mac OS X Isn’t Safe Anymore: The Crapware / Malware Epidemic Has Begun" is beyond stupid.
- lawnchair_larry 12y agoBy "difficult to produce", do you mean difficult to find? If you mean difficult to develop, it's actually very straight forward, and no different from Windows.
- goblin89 12y agoRecently was surprised to discover that the official uTorrent distribution, downloaded straight from utorrent.com, has some Spigot stuff in it. Was I tricked somehow or pre-hijacked already into downloading a non-authentic installer, or do they make money that way now—not yet completely sure.
- stcredzero 12y agoThis is a big problem. Are there browser extensions that can block crapware?
- cmurf 12y agoPretty sure the "Allow apps downloaded from:" has been set to "Mac App Store and identified developers" since 10.8? Maybe 10.7?