|
Focus on Apple
Mac Trojan Nov 01 2007 12:26PM David Harley (david a harley gmail com) (1 replies) Re: Mac Trojan Nov 01 2007 06:45PM Dave Schroeder (das doit wisc edu) (2 replies) Re: Mac Trojan Nov 01 2007 08:34PM David Fedoruk (david fedoruk gmail com) (1 replies) RE: Mac Trojan Nov 06 2007 06:41PM Todd Woodward (todd_woodward symantec com) (1 replies) RE: Mac Trojan Nov 06 2007 08:07PM Paul Schmehl (pauls utdallas edu) (1 replies) Re: Mac Trojan Nov 06 2007 09:10PM Philippe Devallois (phdevallois intego com) (3 replies) Mac OS X Security and Common Sense Nov 07 2007 07:03PM Todd Woodward (todd_woodward symantec com) (2 replies) RE: Mac OS X Security and Common Sense Nov 07 2007 07:57PM David Harley (david a harley gmail com) (1 replies) Re: Mac OS X Security and Common Sense Nov 07 2007 08:28PM Radoslav Dejanoviæ (radoslav dejanovic opsus hr) (1 replies) RE: Mac OS X Security and Common Sense Nov 11 2007 04:09PM David Harley (david a harley gmail com) (1 replies) Re: Mac OS X Security and Common Sense Nov 11 2007 05:32PM Radoslav Dejanoviæ (radoslav dejanovic opsus hr) (2 replies) Re: Mac OS X Security and Common Sense Nov 12 2007 04:52PM Paul Schmehl (pauls utdallas edu) (1 replies) RE: Mac OS X Security and Common Sense Nov 13 2007 04:12PM Thor \(Hammer of God\) (thor hammerofgod com) RE: Mac OS X Security and Common Sense Nov 11 2007 07:33PM David Harley (david a harley gmail com) (1 replies) Re: Mac OS X Security and Common Sense Nov 11 2007 09:01PM Radoslav Dejanoviæ (radoslav dejanovic opsus hr) (1 replies) Re: Mac Trojan Nov 07 2007 04:33PM Kevin Long (kevin long verizonbusiness com) (3 replies) Re: Mac Trojan Nov 14 2007 01:32PM Dave Piscitello (dave corecom com) (1 replies) Re: Mac Trojan and Last Security Update Nov 15 2007 03:03PM Philippe Devallois (phdevallois intego com) (1 replies) Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 07:11PM Roland Dobbins (rdobbins cisco com) (6 replies) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 10:33PM Thor \(Hammer of God\) (thor hammerofgod com) (1 replies) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 09:08PM John Ladwig (John Ladwig csu mnscu edu) Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 08:13PM John Ladwig (John Ladwig csu mnscu edu) Re: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 07:31PM Edward R. Marczak (marczak radiotope com) (1 replies) Re: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 02 2007 01:35AM Roland Dobbins (rdobbins cisco com) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 07:29PM Todd Woodward (todd_woodward symantec com) (1 replies) Re: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 07:45PM Edward R. Marczak (marczak radiotope com) (1 replies) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 08:05PM Todd Woodward (todd_woodward symantec com) (1 replies) Re: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 09:14PM Edward R. Marczak (marczak radiotope com) (1 replies) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 04 2007 09:25PM Thor \(Hammer of God\) (thor hammerofgod com) (3 replies) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 04 2007 11:25PM Thor \(Hammer of God\) (thor hammerofgod com) RE: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 04 2007 08:29PM Todd Woodward (todd_woodward symantec com) Re: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 07:22PM Dave Schroeder (das doit wisc edu) Re: Privileged vs. non-privileged? (was Re: Mac Trojan) Nov 01 2007 07:16PM Jason Pruim (japruim raoset com) |
|
Privacy Statement |
<thor (at) hammerofgod (dot) com [email concealed]> wrote:
>
> In that regard, I'm of the opinion that our OS's are and can be properly
> configured with a little bit of education as they now stand. If this
> MAC trojan is successful, it's our fault as admins and users, not
> Apple's fault at this point.
I disagree. Here's why. When you try to install a program on OS X, you
are prompted for *your* password. Nowhere does it warn you that this is an
administrator level access. I think that's a mistake on Apple's part (and
many other OSes as well) in that the average joe user won't understand the
implications of typing in *his* password.
Now, if Joe is especially sharp, he might question *why* he has to type in
his password again when he's already logged in, but, unless he's been
learning the OS, he's not going to make the connection that he's about to
authorize privileged access to the file system.
Unix, IMNSHO, handles this the right way. You try to run something that
requires root access, it refuses to run it *and* tells you that you need to
be root to do it. Unfortunately, some of the GUIs are now obscuring this
knowledge by simply prompting for the password, but at least they tell you
it's the *root* password and not yours.
I totally agree with you that we need to educate users, but OS designers
shouldn't be making it harder by blurring the lines between user and admin.
Good security doesn't make it harder to do things, but it *does* make it
obvious when something you're about to do has implications well beyond your
normal access.
--
Paul Schmehl (pauls (at) utdallas (dot) edu [email concealed])
Senior Information Security Analyst
The University of Texas at Dallas
http://www.utdallas.edu/ir/security/
[ reply ]