On CBS MoneyWatch: 5 Great Jobs for Lousy Times
BNET Business Network:
BNET
TechRepublic
ZDNet

By Fran Foo
Posted on ZDNet News: Sep 29, 2005 12:22:00 PM

Commentary--Security vendor Symantec has once again pointed the knife at Apple Macintosh users.

Symantec's latest Internet Security Threat Report continues to voice concern for the security and stability of the Mac operating system, OS X in particular. The publication covered findings for the first half of 2005.

"An ever-increasing number of users are adopting OS X. Many of these users believe that this operating system and the applications that run on it are immune to traditional security concerns. However, as evidence suggests, increasingly they may be operating under a false sense of security," the report stated. What exactly was the supporting and undisputed evidence? A SecurityFocus page that aggregates 78 entries of OS X flaws starting from version 10 (circa 2001) onwards. Compare this to Windows ... well, where would you start? OK, I hear your ... it's not an apples-to-apples comparison.

SecurityFocus describes itself as a vendor-neutral site that provides objective, timely and comprehensive security information to all members of the security community. Oh, and by the way, SecurityFocus was acquired by Symantec in 2002.

The report briefly touched on a Trojan called OSX/Weapox--its discovery indicates that OS X may no longer be spared from widespread attack. "Though vulnerabilities and malicious code targeting other operating systems continue to outnumber those on OS X, Symantec recommends users continue to apply security patches and educate themselves on OS X security issues," the report stated.

Symantec's stance against OS X users--that this group is delusional--is familiar.

The false-sense-of-security claim was mentioned in a previous report which covered the second half of 2004. Then, Symantec said increased adoption of the Mac mini will escalate malicious activity since it could be purchased by less security-savvy users. These statements were widely covered in the press and opined on by your writer.

The company also claimed OS X's BSD-Unix origins made it susceptible to vulnerabilities.

In the latest report, however, the Mac mini didn't score a mention. This is due to the fact that OS X has increased in popularity on all of Apple's platforms, Symantec security manager Dean Turner said.

"When we referred to the Mac mini we were referring to it as a popular device for OS X (which we continue to talk about). "Cheaper hardware can mean increased adoption ... which has been the case for Apple," Turner said.

Indeed, the mini version is more affordable compared with the sleek iMac; a 1.25GHz 40GB Mac mini costs $429 but throw in a keyboard, mouse and monitor, and the cost is almost comparable to a Dell or any other IBM compatible, while a 1.8GHz, 17 inch iMac starts at $1,299.

Symantec reckons as Mac OS X increases in usage, bad things will happen. Last week was a prime example--Apple released 10 security patches but made no mention to how dangerous the flaws were. As company policy, Apple tends to keep mum in such instances. As clearly stated on its Web site: "For the protection of our customers, Apple does not disclose, discuss, or confirm security issues until a full investigation has occurred and any necessary patches or releases are available". It was Symantec and the French Security Incident Response Team that labeled the flaws "critical".

The media is used to the silent treatment from Apple. When the recent Symantec report was released, I asked Apple to counter the allegations made by the antivirus company.

The response was plain disappointing. "Apple does not comment on another company's claims. We expect users to be vigilant about security and take whatever steps are necessary to secure their operating environment. According to Sophos, the top 10 viruses listed do not impact Mac OS X," Apple Australia spokesperson Debbie Kruger said.

Apple didn't respond when asked if OSX/Weapox was such a menace — as Symantec claimed--to its users.

Of course, there's more to security threats than viruses and worms.

Antivirus firm Sophos believes the malicious software Renepo (alias Opener) is plain nasty. "It turns off system accounting, turns off the OS 10 firewall, turns off auto updates, turns file-sharing on, opens an SSH back door, downloads and installs an open source video conferencing program and opens it in 'do not advise the user mode'," Paul Ducklin, Sophos Asia-Pacific head of technology, told ZDNet Australia in a previous interview. While Macs are safer compared with Windows, Ducklin thinks the existence of Renepo should be a "sanitary reminder" that bad things can happen.

There's not doubt that Mac users believe they operate on a superior platform--when you pay for a BMW, you expect a luxury car, not a scooter--but to allude that OS X customers are living in a world of fantasy is fancy on any vendors' part. If Symantec or anyone else hopes to "educate" Mac users on security, here's a word of advice: don't go it alone; speak to Apple and let the voices at Apple carry the message.

Antivirus makers like Sophos and Symantec have thrived under the auspices of Microsoft--the vulnerability of Windows and related products has helped create and sustain these companies. Isn't it blindingly obvious why Mac users are immune to the "advice" from these players?

biography
Fran Foo is managing editor of ZDNet Australia.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 123 Talkback(s)
The Brewing of Fear Continues
Some businesses need you to be in fear in order to exist, these
includes alarm system installers, insurance and ... the police?

Us veteran Mac users are careful - we do our bit to warn each... (Read the rest)
Posted by: Jeremiah Foo Posted on: 10/03/05 You are currently: a Guest | | Terms of Use
Who's afraid of the Big Bad Wolf?  Laff | 09/29/05
I'm never nervous  Squawkbox | 09/29/05
DENIAL doesn't change REALITY !  realitycheck101 | 09/29/05
Well duhhhh  Squawkbox | 09/29/05
More hot air with NO REAL WORLD EXPLOITS  BitTwiddler | 09/29/05
you must be in denial  csa0307 | 09/29/05
apple releasing updates doesn't make your mac crash etc  hipparchus2000 | 09/29/05
Is that why most hackers use Macs?  nucrash | 09/29/05
Ha! Thats funny!  middle of nowhere | 09/29/05
Because there are major differences  ITGuy04 | 09/29/05
Denial, deflections and double standards.  IT Scion | 09/29/05
Not really  ITGuy04 | 09/29/05
Really?  IT Scion | 09/29/05
Macs scare Symantec  Otto_Delete | 09/29/05
For the record  I'm Ye, the MS SHILL . | 09/29/05
U R Correct  Otto_Delete | 09/29/05
Actually YOU sound a bit scared, now  John Zern | 09/29/05
Nope, not scared a bit  Otto_Delete | 09/29/05
Well if you are not being attackes it's hard to be  Laff | 09/29/05
re: Macs scare Symantec  nightshade0143 | 09/29/05
Huh? Gutted, not on par with? Who has said these  Laff | 09/30/05
I have never had a virus on Mac OS X...  gtdworak | 09/29/05
And your're proof of what Symantec is saying  John Zern | 09/29/05
Consequences  Harry Bardal | 09/29/05
Insight into OS X Code IS freely Available  ChiAny | 09/29/05
Like most of the people here actually LOOKED at the code  John Zern | 09/29/05
Got news for you buddy...  emyulick | 09/29/05
And AutoStart was pre-OSX days...  MacCanuck | 09/29/05
Know more then you think buddy  John Zern | 09/29/05
re: Know more than you think buddy  bgoss@... | 10/01/05
symantec can bite me.  DemonX | 09/29/05
but it wasn't big enough to make the news, and of course, Apple wouldn't te  1macfan | 09/29/05
Same here...  gfeier | 09/29/05
It's sad  IT Scion | 09/29/05
I'm not a Mac user, but if I were  Real World | 09/29/05
MS makes similar remarks  ITGuy04 | 09/29/05
Well ummm they do go public  Squawkbox | 09/29/05
Who said anything about Microsoft? (nt)  Real World | 09/29/05
RE: Who said anything about Microsoft?  Squawkbox | 09/29/05
Roger that, SB  Real World | 09/29/05
So are the two of you going to kiss and make up?  Laff | 09/29/05
Kiss Squawky?  Real World | 09/29/05
No upside down tonguers though. Thanks Jim  Squawkbox | 09/29/05
"Good to see you are OK SB!!!!"  Arm A. Geddon | 09/29/05
Thanks Arm It is good to be back  Squawkbox | 09/29/05
Not really a head in the sand attitude  nucrash | 09/29/05
If you were a Mac user, you would know your post is incorrect  mlindl | 09/30/05
Mac is insekure  b.d.hi | 09/29/05
Show me the REAL WORLD exploits, and then I'll worry...  BitTwiddler | 09/29/05
Make those numbers up, did ye?  John Zern | 09/29/05
We need a Mac version of Mike Cox in here happy  BitTwiddler | 09/29/05
Bwahahahaha Now that WOULD be funny wink  Squawkbox | 09/29/05
Hmm...  Zinoron | 09/29/05
Yes, but how could you be sarcastic  nucrash | 09/29/05
Since...  thetargos | 10/01/05
Sound like they just want to sell more software  DarthRidiculous | 09/29/05
Show me the THREAT  EK. | 09/29/05
This is called pre-emptive preparation  nucrash | 09/29/05
Sorta doubt it  j.m.galvin | 09/29/05
This would be the reason for...  nucrash | 09/29/05
What pre-emptive preparation would you suggest?  tic swayback | 09/29/05
That wasn't meant to be a plug for Symantec  nucrash | 09/29/05
Aren't those things just SOP?  tic swayback | 09/29/05
The last time...  minidriver | 09/29/05
History is repetitive  ibabadur1 | 09/29/05
One problem  bpick_z | 09/29/05
Hmmmm, Symantec....  tic swayback | 09/29/05
re: Hmmmm, Symantec....  nightshade0143 | 09/29/05
How will it help me?  tic swayback | 09/30/05
Symantec is just scared that they live in a glass house  zmud | 09/29/05
Symantec = Nascar restrictor plate  osreinstall | 09/29/05
Auto analogies don't work  Squawkbox | 09/29/05
Hell I can use any analogy known.  osreinstall | 09/29/05
What is really happening...  bpick_z | 09/29/05
You were doing "OK" till  Squawkbox | 09/29/05
Didn't you get the memo?  osreinstall | 09/29/05
AWWWW CRAP  Squawkbox | 09/30/05
MS/Symantec relationship  bpick_z | 09/30/05
They are joined at the hip for a little project back in 1998?  osreinstall | 09/30/05
Look I don't care about any deal(s)  Squawkbox | 09/30/05
Oh yeah and about your proof link  Squawkbox | 09/30/05
What is definitely happening  bpick_z | 09/30/05
Yes bpick  Squawkbox | 10/01/05
Macs are going to get it like every other os  csa0307 | 09/29/05
Riiiiiight....  bpick_z | 09/29/05
you missed the most important part  csa0307 | 09/29/05
Interesting...and could you name these viri?  Laff | 09/29/05
no  csa0307 | 09/29/05
In case you didnt' know...  bpick_z | 09/29/05
Well this issue here is why if you can not name or describe  Laff | 09/29/05
get a clue please  ITGuy04 | 09/29/05
get a clue yourself  csa0307 | 09/29/05
Win $500 for yourself, get the virus software for free...  bpick_z | 09/30/05
magic?  docFUNK | 09/29/05
Simple really, not magic at all  bpick_z | 09/29/05
More like VMWare  Immanuel Tranz-Mischen | 09/29/05
Hey Doc  John Zern | 09/29/05
And if you can't find a logical argument for them...  bpick_z | 09/30/05
Macs are retarded.  A_Pickle | 09/29/05
You would know  bpick_z | 09/29/05
Enough with the iPod battery FUD  bpick_z | 09/29/05
A_Pickled Moron?  Laff | 09/29/05
So are you  ITGuy04 | 09/29/05
Perhaps you should do a little research first.  olePigeon | 09/30/05
R U delusional? Everyone knows Vista is a long delayed OSX Tiger  YuridaMan | 10/03/05
No Viruses for Mac OSX huh??  Ishkaboo | 09/29/05
Lay off the chocolate, Willy  bpick_z | 09/29/05
Oh OK. Well the windows ones  John Zern | 09/29/05
Fine, as long as you follow his rules  tic swayback | 09/29/05
It's and applescript your dumb @#s  TheCrow_z | 09/29/05
I have a Mac OS X virus!  mbrierley | 09/29/05
Just goes to show...  bpick_z | 09/30/05
Worse  mbrierley | 10/01/05
None of those are viruses.  olePigeon | 09/30/05
huh huh?  javinfo@... | 09/30/05
Symantec just wants our money.  Immanuel Tranz-Mischen | 09/29/05
Sanitary?????  NucMed | 09/29/05
hmmmm  mbrierley | 09/29/05
Symantec protecting the gravy train.  Andromedat6 | 09/29/05
Norton sucks  sp29 | 09/30/05
Complacency is deadly  wolf_z | 10/01/05
Where's Kinte? Too busy insulting  mustangj36@... | 10/01/05
The Brewing of Fear Continues  Jeremiah Foo | 10/03/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here