|
Focus on Apple
Mac Trojan Nov 01 2007 12:26PM David Harley (david a harley gmail com) (1 replies) Re: Mac Trojan Nov 01 2007 06:45PM Dave Schroeder (das doit wisc edu) (2 replies) Re: Mac Trojan Nov 01 2007 08:34PM David Fedoruk (david fedoruk gmail com) (1 replies) RE: Mac Trojan Nov 06 2007 06:41PM Todd Woodward (todd_woodward symantec com) (1 replies) RE: Mac Trojan Nov 06 2007 08:07PM Paul Schmehl (pauls utdallas edu) (1 replies) Re: Mac Trojan Nov 06 2007 09:10PM Philippe Devallois (phdevallois intego com) (3 replies) Mac OS X Security and Common Sense Nov 07 2007 07:03PM Todd Woodward (todd_woodward symantec com) (2 replies) RE: Mac OS X Security and Common Sense Nov 07 2007 07:57PM David Harley (david a harley gmail com) (1 replies) Re: Mac OS X Security and Common Sense Nov 07 2007 08:28PM Radoslav Dejanoviæ (radoslav dejanovic opsus hr) (1 replies) RE: Mac OS X Security and Common Sense Nov 11 2007 04:09PM David Harley (david a harley gmail com) (1 replies) Re: Mac OS X Security and Common Sense Nov 11 2007 05:32PM Radoslav Dejanoviæ (radoslav dejanovic opsus hr) (2 replies) Re: Mac OS X Security and Common Sense Nov 12 2007 04:52PM Paul Schmehl (pauls utdallas edu) (1 replies) RE: Mac OS X Security and Common Sense Nov 13 2007 04:12PM Thor \(Hammer of God\) (thor hammerofgod com) RE: Mac OS X Security and Common Sense Nov 11 2007 07:33PM David Harley (david a harley gmail com) (1 replies) Re: Mac OS X Security and Common Sense Nov 11 2007 09:01PM Radoslav Dejanoviæ (radoslav dejanovic opsus hr) (1 replies) Re: Mac Trojan Nov 07 2007 04:33PM Kevin Long (kevin long verizonbusiness com) (3 replies) Re: Mac Trojan Nov 14 2007 01:32PM Dave Piscitello (dave corecom com) (1 replies) Re: Mac Trojan and Last Security Update Nov 15 2007 03:03PM Philippe Devallois (phdevallois intego com) (1 replies) Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 07:11PM Roland Dobbins (rdobbins cisco com) (6 replies) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 10:33PM Thor \(Hammer of God\) (thor hammerofgod com) (1 replies) Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 08:13PM John Ladwig (John Ladwig csu mnscu edu) Re: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 07:31PM Edward R. Marczak (marczak radiotope com) (1 replies) Re: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 02 2007 01:35AM Roland Dobbins (rdobbins cisco com) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 07:29PM Todd Woodward (todd_woodward symantec com) (1 replies) Re: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 07:45PM Edward R. Marczak (marczak radiotope com) (1 replies) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 08:05PM Todd Woodward (todd_woodward symantec com) (1 replies) Re: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 09:14PM Edward R. Marczak (marczak radiotope com) (1 replies) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 04 2007 09:25PM Thor \(Hammer of God\) (thor hammerofgod com) (3 replies) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 05 2007 03:24PM Paul Schmehl (pauls utdallas edu) (2 replies) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 05 2007 07:26PM Chris Pepper (pepper reppep com) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 05 2007 06:14PM Jeramey Valley (ValleyJR mps k12 mi us) (1 replies) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 05 2007 07:25PM Paul Schmehl (pauls utdallas edu) (1 replies) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 05 2007 11:39PM Thor \(Hammer of God\) (thor hammerofgod com) (1 replies) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 05 2007 08:14PM Jeramey Valley (ValleyJR mps k12 mi us) (1 replies) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 06 2007 01:09AM Thor \(Hammer of God\) (thor hammerofgod com) (2 replies) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 06 2007 05:59PM Paul Schmehl (pauls utdallas edu) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 06 2007 12:13PM Jeramey Valley (ValleyJR mps k12 mi us) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 04 2007 11:25PM Thor \(Hammer of God\) (thor hammerofgod com) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 04 2007 08:29PM Todd Woodward (todd_woodward symantec com) Re: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 07:22PM Dave Schroeder (das doit wisc edu) Re: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 07:16PM Jason Pruim (japruim raoset com) |
|
Privacy Statement |
>> How many Mac users have been faced with a seemingly-random request to
>> grant a non-obvious background app/utility Keychain access, not to
>> mention commonly-used apps asking for it without an easily-discerned
>> reason? And in such situation, what do they typically tend to do
>> (I've my own opinion about this, but clue welcomed).
>
>I've never been presented with anything like that on the Mac. Regarding
>this whole "MAC Trojan" thing, I have to say-- if anyone on the MSFT
>side of things came out and tried to claim "Windows Trojan" on something
>the user had to manually (and purposefully) download, manually execute,
>and then explicitly grant administrative rights to, they'd get
>firehosed.
Um, beg to differ. Much of the Windows malware currently floating around is classed as a Trojan, even though they get referred to as "Worms."
And for those who are poo-pooing a piece of malware that requires user-interaction as part of the setup, I must ask - where do you think bots in those botnets we read about in the press come from?
OSX/RSPlug only varies in the payload from a bot-recruiting trojan. If someone felt it was worth their time, and they had a good "hook" to get conversion (pr0n video codecs are well known to be effective in the Windows space), we could be adding Macs to the worldwise botnets at anytime. And given the amount of "OS-X is secure, and there isn't any malware that affects it" that gets spread around, the average Mac user is simply unprepared to consider "Is it safe to click on this link... download this package... give my administrator password...?"
This is probably as good a time as any to remind people of Dave Goldsmith's Matasano Chargen post "Safety Vs. Security" from last winter:
http://www.matasano.com/log/644/safety-vs-security-2/
I think it's still one of the more thoughtful summaries of the state of OS-X security and the malware ecosystem around OS-X.
-jml
[ reply ]