iMarc | Interactive Media Architects
  • Portfolio
  • Process
  • About
  • Communiqué
  • Contact
  • Support
  • Search

Insecurity

by Robert Mohns - January 2, 2008 / 9:59am View more articles

iMarc is a little unusual in its Mac-PC distribution. More than half of our design team use Windows, while more than half of our developer team use Macs. Overall, we are almost exactly split: eight Windows users, eight Mac users, and Will, who recently went Ubuntu.

Security is of general interest, but in particular, I think the Mac is becoming a more insecure platform ... not so much inherently, but because it's finally becoming interesting to organized internet crime.

BBC News has published an interesting article about the business of "cyber crime" Boom times for hi-tech criminals.

Let's start with a key excerpt from the BBC article:

"2007 was a fairly interesting year," said Joe Telafici, vice president of operations for McAfee's Avert Labs, "cyber crime continued to fuel most of the security attacks we saw."

It was a year, he said, which saw the effective extinction of young hackers who wrote viruses and other malicious programs for fun.

Now, he said, Windows malware was all about money.

Some attacks, such as phishing runs, were clearly about stealing cash from victims either from a credit card or bank account.

But, he said, many others that looked more innocuous were done with money in mind. For instance, he said, trojans placed in banner ads that try to hijack a home PC were all about getting hold of resources that can be rented out for a fee to spammers or other net-based criminals.

"There's a real eco-system built around this," he said.

Paul Henry, vice president of technology evangelism at Secure Computing said the tool of choice for many hi-tech criminals was the botnet - a collection of hijacked home PCs.

Ars Technica has just published a summary of Mac OS X market share, discussing both absolute numbers and trends.

As of November 2007, the Mac had reached 7.3% market share. Remember, we're coming from just 4% two years ago. That's nothing to sneeze at.

Now, let's tie these two articles together and do a little New Year's forecasting: as the Mac market share grows, Macs will begin to become relevant to the botnet market. There are enough out there to be interesting, and the POSIX-compliant BSD (Unix) layer provides some nice tools for crackers once they're in.

In fact, it's already happening. In October, a Mac-specific trojan horse masquerading as a video plug-in for Safari/Firefox was sighted in the wild and took over lots of Macs. Admittedly, we joked about it because it was pretending to give you access to free pornography, and it was pretty primitive in its effects, but as a proof of concept, it does its job nicely. The writing is on the wall.

Of course, marketshare alone isn't everything. Ten years ago, Linux distributions were the target of choice for early botnets. Linux was vastly outnumbered by Windows on the net, but Linux distributions were insecure by default and very easy to exploit. After a few years, all the major distributions got the message and new (and updated) Linux distros were secured by default. It worked -- crackers turned their attention to the next easiest system to exploit, Windows.

Back Oriface had its day, followed by worms such as Code Red and Nimda, which spread themselves with startling effectiveness. (Nimda is said to have become the most widespread worm ever in just 22 minutes.) In January 2007, Storm Worm appeared, and by September, it had created a botnet of ten million Windows PCs. Big business, indeed.

Well, the Mac is next. There are enough Macs on the net to be interesting; they make a nice platform for internet-connected processes and distributed computing; and Apple is slow to respond to security vulnerabilities, making it a ripe target for attacks in the period between discovery and patching.

I am frustrated, at times, by the constant stream of tiny Windows security updates from Microsoft, but the fact is, that stream of rapid patches helps keep modern versions of Windows secure. Apple's approach of occasional monolithic updates is easier for users, but leaves much longer gaps between the discovery of security vulnerabilities and their resolution. To date, Apple has been reasonably responsive in quickly patching actual exploits (which are of far more concern than vulnerabilities, which are usually theoretical), but I fear that Apple's model of slow response and no public acknowledgement of issues while they're working on them is going to leave the Mac platform vulnerable.

We've seen Apple improve its security response times over the past year, but there is still progress to be made. Ultimately, however, responsibility for good security lies in the hands of end users -- you and me. Keep your firewall up; install security updates; don't install software from unknown sources (especially if it promises you free pornography, folks!); don't open email attachments from strangers.

In the Windows world, you can -- contrary to popular belief -- stay virus and worm free without antivirus software (if you start with a clean install of Windows XP Service Pack 2 or later), but it requires diligence and care. I believe that Mac users must adopt a similar mindset. Mac OS 9 was virtually immune to attack because the core OS was so unfriendly to networking, while Mac OS X has been too insignificant to be of interest to professional cyber criminals. This has changed.

Mac OS X is now interesting to organized internet crime. We, as users, must adopt good security practices. Mac OS X provides a fairly secure base, but it's not perfect, and it's up to us to maintain our Macs' integrity.

More Articles Get the RSS Feed Post A Comment

3 Comments

by Elyse Holladay   #
on January 2, 2008 / 4:17pm
Lots of good points in here. As a Mac user who switched from PC 2 years ago and a 4-year tech support consultant, I'm really dreading the day that I have to worry about viruses on my Mac. It really is the responsibility of the end user to maintain their computer's security. The biggest issue I saw at the helpdesk I worked at during college wasn't incredibly fast-spreading viruses or late/bad patching by Microsoft, but just the uneducated user. More often than not, we'd find ourselves explaining to Mechanical Engineering and Computer Science undergraduates that downloading off LimeWire and clicking on links in strange IMs or e-mails saying "hay look naked pixxx" wasn't really the best idea. Kind of amazing. I worked when w32.blaster hit campus; we had to wipe and reimage probably 70% of the machines on campus. Total madness. Hopefully Apple will rise to the challenge of quicker, more accurate updates, and hopefully (I say this with a very enormous grain of salt) computer users will get a little bit smarter. Ha.
by Patrick McPhail   #
on January 3, 2008 / 9:52am
XXX FREE STEVE JOBS INTERVIEWS WOW MUST SEE HAWT
by Jeff Turcotte   #
on January 3, 2008 / 10:01am
I agree that that virus problems come more from uneducated users than they do secure operating systems.

@patrick: That XXX Steve Jobs interview didn't seem to work.

@all: TAKE A SURVEY, WIN A FREE XBOX 360!!

Add A Comment

Accepts and renders HTML. If you include any HTML other than inline elements, you’ll also need to include your own paragraph breaks.

Statements and opinions expressed in this blog and any comments made are the private opinions of the respective poster, and, as such, iMarc LLC is neither responsible nor liable for such content.

iMarc

iMarc is a web development company in Newburyport, MA. This is our blog.
View all blogs or learn more about iMarc.

* Hiring: We’re hiring a Web Designer to design and build web sites and branding collateral.

About the Author

Robert's Head Robert Mohns, Information Architect
Will architect websites for Wii.
More blogs by Robert

Search Our Blog

Recent Communiqués

  • Year in Quotes (volume 2)
  • Gunslinging Rockstar Ninjas
  • Now Hiring: Junior Interactive/Web Designer
  • Photoshop: Create Your Own Glossy Icons
  • They only come out at night
  • Context switches are expensive
  • <i> is not evil.
  • Schooled.
  • Full-screen branding
  • Summer Job, iMarc Style
  • Custom Away Messages are Overrated
  • Random Vent
  • Hiring: Junior Systems Administrator
  • Using A Framework
  • for lack of nail

Popular Communiqués

  • Hiring: Junior Systems Administrator
  • Photoshop: Create Your Own Glossy Icons
  • Now Hiring: Junior Interactive/Web Designer
  • Gunslinging Rockstar Ninjas
  • They only come out at night
  • Summer Job, iMarc Style
  • Random Vent
  • Full-screen branding
  • for lack of nail

Recent Comments

  • Now Hiring: Junior Interactive/Web Designer

    By Dnmhxxsh: this is be cool 8) big tit get fuck >:[

  • Now Hiring: Junior Interactive/Web Designer

    By Zblxsxro: It's serious comforter sets for teenager =-(( preteen boys raped girl %)

  • Now Hiring: Junior Interactive/Web Designer

    By Dejyleps: perfect design thanks old grannie sex tgp =-]]]

  • Year in Quotes (volume 2)

    By Nick: Not inspirational, but how i feel sometimes as "Client Support". "I'm Drowning,…

  • Firefox Html Validator on Ubuntu Gutsy

    By Simeon Anastasov: Forget about my last question - i was too lazy to read through the whole comment chain. Now I got it :)

RSS

RSS Icon Learn about RSS and get the feed for our blog.

About iMarc

  • We build custom web sites
  • In-house strategy, design, programming, hosting
  • In business since 1997
  • We’re located in Newburyport, MA
  • Call us at (978) 462-8848

© 2008 iMarc LLC, Contact Us

Links

  • Home
  • Portfolio
  • Client Support
  • Log In
  • (icon)RSS

Meet the Team

Craig's Head Craig Henry, Creative Director

Designing Media types that exemplify innovation, excitement, and growth to our industry and our clients.

Learn More | Meet the Others