Apple Admits Its Macs Have a Malware Problem
April 12, 2012 12:07 PM
comment(s) - last by
(Source: Mashuga Mom)
Flashback botnet is no fun for the infected
Apple has finally owned up to the fact that many of its users' machines have been
afflicted by crippling malware
. And it promises that it's working on a fix. But experts wonder if the company is simply acting in a reactionary fashion or is ready to finally get serious about protecting its users.
I. Trojans are Increasingly a Problem for Mac Users
In the 1990s, hackers enjoyed a virtual wild west of unpatched exploitable software. But as the new decade rolled around companies like Microsoft Corp. (
) stepped up their security. As a result it's become harder for malware to install on Windows computers without some sort of user action. Hackers have circumvented this by creating programs that trick the user into approving the installation via exploiting trust (hijacked sites, systems) or user ignorance (clicking spam email links). The approach has become tremendously successful and today Trojan-type malware are responsible for a large percentage of the Windows botnets.
Apple, Inc. (
) long avoided such woes, thanks to its small market share and specialized OS code, which precluded stock PC malware from running on a Mac. But the company's base security model is in theory no more secure, and -- perhaps driven by
rising market share
-- of late the company has grappled with
serious trojan issues
Macs are increasingly the target of Trojans. Malware writers love Apple's
sluggish pace of patching. [Image Source: Venitism]
The latest fire facing the Mac community is "Flashback", also knows as "Flashfake". This Trojan has evolved over multiple variants to its current form, which masquerades as an install Java applet on hijacked websites. Customers who approve it unwittingly run a piece of code that exploits a flaw in Oracle Corp.'s (
) Java platform in order to remove OS X's limited anti-malware capabilities and install back-door control programs.
The affected machines are turned into bots, which the attackers can use to spew spam or commit other foul acts. Kaspersky Labs' Igor Soumenkov
in an interview that at its peak, Flashback had infected 600,000 machines, including roughly 300,000 in the U.S. Approximately 98 percent of those machines were Macs.
II. Is Apple to Blame?
Apple has been under heavy fire from the security community. First, it was the company's lackadaisical approach to patching that gave Flashback the opportunity to take hold.
The majority of infections occurred after Oracle had already patched the Java vulnerability. The code would thus have failed under most Windows machines. However, Apple insists on
redistributing all third-party updates
via its own repackaging scheme. And under this system it often delivers updates at a sluggish rate, often months behind their release to the more open, more used Windows platform. As a result it's often
far behind on security patches
of third-party platforms -- something malicious hackers are increasingly realizes means open season on Macs.
Over 600,000 Mac users were infected, thanks to Apple's sluggish patching.
[Image Source: Macenstein]
Apple is quick to respond by
attacking third-party platforms
like Adobe Systems Inc.'s (
) Flash, which it
no longer installs on Macs
, in part for being too "insecure".
At the same time Apple practices a
policy of blatant hostility towards security professionals
who are trying to help it.
But a promising sign is that Apple, after delivering patches to close the Java flaws exploited by Flashback, has released a Knowledge Base post warning users that Macs are indeed afflicted by this piece of malware.
This is one of the first times the company has officially acknowledged malware issues. A
previous Trojan -- MacDefender
--was estimated to have infected as many as one in twenty Macs at its peak. While Apple
quietly battled it
with patches and tools, the company instructed technicians in a leaked memo
to lie to customers
and not inform them of infections.
III. OS X is at a Crossroads in Terms of Security
The new issues put the company's image in an awkward position, given that Apple has long promoted OS X as a platform that is largely
immune to the kinds of malware
that have long afflicted Windows machines. Of course some OS X users are savvy enough to realize the reality -- no platform, certainly no consumer platform, is ever fully secure. However, many less tech-savvy Mac users do truly believe that their machines are immune to malware. The disillusionment when they learn the truth may be a blow to Apple.
The company is preparing a tool that will detect and remove various known variants of Flashback. In the meantime its patching seems to be working -- infections have dropped to 270,000 machines, according to Symantec Corp. (
While it's clear that Flashback will be beaten back by the Cupertino company, the compelling question is whether Apple's unusual public admission to having malware is a prelude to adopting a more proactive approach: patching faster, or possibly even allowing third party patches. For now, customers can only judge the company's security stance by its track record -- a track record that speaks to a generally negligent sluggish pace of prevention interspersed with reactionary spurts of action.
Apple is at a crossroads as to whether to decide to become more responsible about security, or allow its customers to be abused. [Image Source: Letters to Jen]
Today hackers appear to be finding Macs the easiest platform to hack.
Apple computers were hacked the quickest
at recent "hack-to-own" style competitions.
With Microsoft adopting a more proactive approach and with hackers increasingly attracted to Apple's affluent customer base, if Apple sticks to its reactionary approach, customers may soon find their Macs going from being the most secure platform, to being the least secure. OS X is at a critical crossroads -- the next move is Apple's to make.
This article is over a month old, voting and posting comments is disabled
4/13/2012 1:13:14 AM
Friend of mine at work is a total Apple fan. Macs, iPads, and iPhones. He keeps lauding how that nobody writes viruses or malware for Macs and keeps trying to get me to buy one. He says that the price differential between Macs and PCs is because Apple only uses the highest quality hardware in their computers. Even after I price out the components of a Mac and show him I can build the exact same computer sans OS, I come out between 18%-20% less expen$ive. He won't have it. I tell him the Apple logo on the box is the only reason you're overpaying. I told him I'd consider an Apple if I get to choose the components inside the box, in other words if I can build it myself. He just doesn't get it I guess from the bewildered look on his face...
4/14/2012 1:42:46 PM
Keep in mind that
1) Apple doesn't play the low-end, you never see any new Mac laptop under $999 these days.
2) Ignoring the iPhone, it costs you just as much to get the same specs with a non-Apple build. And they end up looking ugly and fat e.g. every Clevo notebook. Or hideously expensive e.g. Sony Vaio Z2.
3) Windows Ultimate is the only Windows consumer/client OS with all features enabled, and it costs as much as a decent desktop GPU card -
when bundled with a PC
. There is only one version of a major Mac OS release. Don't get me started on the Server editions.
Lastly, consumer perception. Why sell something close to what your competition prices their stuff at, when you can simply tack on a few benjamins?
Many people perceive Apple as a purveyor of high quality products,
actual quality notwithstanding
. Consequently Apple can price their stuff higher than normal and people will buy them.
Ever seen Dell do the same? It tried with the Adamo. It flopped big time. Because Dell was never seen as high quality. Big perception difference. One or two products alone catering to the luxury segment does not automatically change how people perceive your products.
And you wonder why businesses keep buying ThinkPads over Acer/ASUS/Toshiba when it's not IBM in the driver's seat anymore.
The closest a non-Apple competitor could get as far as branding goes is Acer's Ferrari edition notebooks. Priced like Apple, all because of the Ferrari logo and branding. Unlike Apple, however, they SUCK.
Good luck trying to convince your work buddy to defect from Apple. You'll keep failing. It's like political change, you can't change their opinions without them going through all the trouble on their own.
Meanwhile, I've already planned my next major computer hardware replacement as a Mac from a PC. At least mine won't have an universally-panned Clevo keyboard and a literal consumer-level UPS battery runtime off the wall.
"Vista runs on Atom ... It's just no one uses it". -- Intel CEO Paul Otellini
Malware Authors Get Boost from Apple's Sluggish Updates, Infect 600K Macs
April 6, 2012, 8:40 AM
Developer Demonstrates Serious Security Breach in iOS, Apple Bans His Account
November 8, 2011, 9:06 AM
"Devil Robber" Trojan Infects Macs, Leeches Their GPUs for Bitcoin Profit
November 1, 2011, 10:59 AM
Analysts: Apple Now Has More Than 10 Percent of the U.S. PC Market
July 14, 2011, 1:52 PM
Apple Tries to Roll Out Trojan Protection, Only to See New Variety Pop Up
June 2, 2011, 9:00 AM
FCC Orders Advertisers to Cut Out That Racket, Turn Down Commercials
August 29, 2014, 12:49 PM
Dropbox Bows to Competitive Pressure, Provides 1TB of Storage for $10/Month
August 27, 2014, 11:17 AM
Amazon Acquires Twitch for $970 Million
August 25, 2014, 4:37 PM
Facebook Adds Satire Tags to Its Auto-Generated "Related News" Posts
August 18, 2014, 10:43 AM
Comcast, TWC Pull Dinner Gift for FCC Commissioner... Sort Of
August 15, 2014, 1:10 PM
Comcast Accused of Wooing FCC Commissioner w/ $110K Dinner
August 13, 2014, 8:20 PM
Most Popular Articles
Numerous Leaks Detail 4.7" iPhone 6 Processor, RAM, Cellular and NFC Capabilities
August 29, 2014, 10:37 PM
Windows 9: "Upgrade Now" Button Coming for Enterprise Updates, ARM Preview in H1 2015
August 26, 2014, 8:00 PM
L.A. Unified School District’s Apple iPad Contract Canceled Following Heavy Criticism
August 26, 2014, 12:37 PM
Apple Builds Not-So-Secret Secret 3-Story Tower for iPhone 6/iWatch Unveil
August 28, 2014, 3:41 PM
Netflix Accuses Comcast of Ripping Off Customers, Files to Block Merger
August 26, 2014, 5:49 PM
Latest Blog Posts
Space Terrorism is a Looming Threat For the United States
Apr 23, 2014, 7:47 PM
Facebook Aims to Provide Internet to "Every Person in the World" with Drones, Satellites
Apr 1, 2014, 10:20 AM
Retail Mobile Sites Experience Outages in Light of Simplexity's Bankruptcy
Mar 14, 2014, 8:48 AM
Tesla vs. BMW: Who Has the Safer EV?
Feb 1, 2014, 2:56 PM
Justice Leaks Details of Next HTC One Two Flagship Phone
Dec 5, 2013, 4:04 PM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information