Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Large Prize Offered For Writing Mac Virus

Posted by Zonk on Sat Mar 26, 2005 01:36 PM
from the come-get-some dept.
Mordant writes "Some experienced Mac developers are offering a $25K prize to the first person to successfully infect two 'naked' Internet-connected Macs running stock Apple software. The best part is that if any Symantec employee succeeds in infecting the Macs, the prize goes up to $50K (Symantec has been fanning the flames of totally bogus "Macs aren't more secure, it's just that Windows is a bigger target" technical-equivalence propaganda)!" Update: 03/26 20:24 GMT by Z : Well, that was quick. Jack Campbell has cancelled the contest, after he "...was contacted by a large number of Mac users, and Mac software professionals who shared their thinking with me about the contest."
This discussion has been archived. No new comments can be posted.
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1) | 2
  • Stupid (Score:5, Interesting)

    This has got to be one of the stupidest contests of this type I've heard about.

    1) If a virus has spread over every Mac on the Internet, then it's harmful.

    2) Many people would say that ANY virus is harmful, just by virtue of it being a virus (spreading, infecting.)

    3) I'm so sure it's worth $50,000 for Symantec to finally put that "Antivirus companies don't write viruses" myth to bed.

    4) We're going to use antivirus software to determine if we've been infected... which will only catch previously known viruses.

    5) Hey you guy that wrote the virus that spread to every Mac on the Internet: just identify yourself afterwards, and we'll pay you.
    • Re:Stupid by dnoyeb (Score:2) Saturday March 26 2005, @01:41PM
      • Re:Stupid by ryanr (Score:3) Saturday March 26 2005, @01:44PM
        • Re:Stupid (Score:5, Informative)

          by interiot (50685) on Saturday March 26 2005, @02:25PM (#12055268)
          (http://paperlined.org/)
          It's a quote from Full Metal Jacket [imdb.com] directed by Stanley Kubrick:

          Hartman: Private Joker, do you believe in the Virgin Mary?

          Joker: Sir, no sir!

          Hartman: Well Private Joker! I don't believe I heard you correctly.

          Joker: Sir, the private said "No sir!", sir!

          Hartman: Well, you little maggot, you make me want to vomit!

          ...

          Hartman: Are you trying to OFFEND me?

          Joker: Sir, negative sir! Sir, the private believes that any answer he gives will be wrong, and the senior drill instructor will beat him harder if he reverses himself, sir!

          Hartman: Who's your squad leader, scumbag?

          Joker: Sir, the private's leader is Private Snowball, sir.

          Hartman: Private Snowball!

          Snowball: Sir! Private Snowball reporting as ordered, sir!

          Hartman: Private Snowball, you're fired! Private Joker is promoted to squad leader.

          Snowball: Sir, aye aye sir!

          Hartman: Disapear scumbag!

          Snowball: Sir, aye aye sir!

          Hartman: Private Pyle!

          Pyle: Sir, Private Pyle reporting as ordered, sir!

          Hartman: Private Pyle, from now on, Private Joker is your new squad leader, and you WILL bunk with him. He'll teach you everything, he'll teach you how to pee!

          Pyle: Sir, yes sir!

          Hartman: Private Joker is silly and he's he ignorant, but he's got guts, and guts is enough.

          [ Parent ]
          • Re:Stupid by ryanr (Score:2) Saturday March 26 2005, @02:41PM
            • Re:Stupid by Freexe (Score:1) Saturday March 26 2005, @07:41PM
            • 1 reply beneath your current threshold.
          • Re:Stupid by interiot (Score:1) Monday March 28 2005, @02:18AM
            • Re:Stupid by interiot (Score:1) Monday March 28 2005, @04:32AM
              • Re:Stupid by DA_MAN_DA_MYTH (Score:2) Monday March 28 2005, @06:14PM
              • 1 reply beneath your current threshold.
            • 1 reply beneath your current threshold.
          • 3 replies beneath your current threshold.
        • Re:Stupid by TFGeditor (Score:3) Saturday March 26 2005, @03:11PM
          • Re:Stupid (Score:4, Informative)

            No the article doesn't say that explicitly, you'd have to understand how viruses spread, and make a logical connection to get there.

            Let me help you out.

            Here's my paraphrasing of the individual claims, from memory. I'd quote better, but oh look, they've cancelled already.

            -We have two Macs on different Internet connections. We won't tell you the IPs.
            -We're going to check for the next couple of months and see if they are infected, just by being on the Internet.
            -(Vague statements about being successful enough in the wild)

            Leaving alone the email vector, which I've agreed elsewhere is(was) viable, how do the viruses get onto their two Macs? Has to be both, mind you.
            [ Parent ]
            • Re:Stupid by TFGeditor (Score:2) Saturday March 26 2005, @03:48PM
          • 1 reply beneath your current threshold.
      • Re:Stupid by Spectra72 (Score:2) Saturday March 26 2005, @01:57PM
      • Re:Stupid (Score:5, Interesting)

        by Ohreally_factor (593551) on Saturday March 26 2005, @02:03PM (#12055125)
        (Last Journal: Sunday November 27 2005, @02:29PM)
        DVforge is owned by one Jack Cambell [jackwhispers.com], a known con artist and admirer of publicity stunts. This is exactly that and nothing more: a publicity stunt.d I'd be very surprised if 1) either of the two computers actually exist, 2) the prize money exists, 3) if the computers exist and the prize money exists, then Jack will ever pay up if someone wins.
        [ Parent ]
        • Re:Stupid by ryanr (Score:2) Saturday March 26 2005, @02:37PM
          • Re:Stupid by Ohreally_factor (Score:2) Saturday March 26 2005, @03:50PM
            • Re:Stupid by sumdumass (Score:2) Monday March 28 2005, @05:35AM
              • Re:Stupid by sumdumass (Score:2) Monday March 28 2005, @11:20AM
              • 1 reply beneath your current threshold.
        • Re:Stupid Publicity Stunt (Score:5, Informative)

          by quarkscat (697644) on Saturday March 26 2005, @03:18PM (#12055669)
          A quick visit to the website reveals that their
          "Mac Virus Contest" is a totally bogus bit of
          showmanship. ( From the: "Even bad publicity
          is still publicity" Department ):

          DVForge Virus Prize 2005
          The Contest That, Sadly, WIll Never Be

          Contest goal: To lay to rest, once and
          for all, the myths surrounding the lack
          of spreading computer virii on the
          Macintosh OS X operating system, by
          sponsoring a contest that challenges
          virus writers to actually prove that
          they can introduce a harmless virus
          into two modern OS X Macs.

          That was the goal of a contest
          announced recently by DVForge, but,
          due to a variety of influencing factors
          was cancelled shortly after having been
          announced.

          A Statement About The Contest Cancellation
          "In response to the statements put forth
          this past week by Symantec Corporation
          suggesting that Mac users are at
          substantial risk to infections from viruses,
          our company crafted and announced a contest
          that would have paid a $25,000 prize for
          the successful creation of such a virus,"
          said Jack Campbell, DVForge, Inc. CEO,
          "During the first several hours after making
          the public announcement, I was contacted by
          a large number of Mac users, and Mac software
          professionals who shared their thinking with
          me about the contest. A few of these people
          are extremely well-regarded experts in the
          field of Mac OS X security. So, I have taken
          their advice very seriously, and have made
          the difficult decision to cancel our contest.

          I have been convinced that the risk of a virus
          on the OS X platform is not zero, although it
          is remarkably close to zero. More importantly,
          I have been convinced that there may be legality
          issues stemming from such a contest, beyond
          those terminated by our own legal counsel,
          prior to announcing the contest. So, despite
          my personal distaste for what some companies
          have done to take advantage of virus fears
          among the Mac community, and my own inclination
          to make a bold statement in response to those
          fears, I have responsible choice but to retract
          the contest, effective immediately."

          DVForge, Inc. supports honesty and integrity by
          manufacturers in all public communication. And,
          we strongly discourage the use of exaggeration,
          innuendo, or loosely stated claims in an effort
          to increase sales of a company's products. We
          believe in accurate, fair marketing statements,
          and in allowing an accurately informed public to
          then make its own decisions about purchasing,
          or not purchasing, a company's products or
          services. We implore all Mac industry businesses
          to support these same values.

          We do not endorse the creation or distribution
          of computer viruses. U.S. and international law,
          as well as simple good judgment forbid the
          transmission of computer viruses.
          [ Parent ]
          • Re:Stupid Publicity Stunt by Ohreally_factor (Score:3) Saturday March 26 2005, @03:55PM
          • Re:Plurals by azav (Score:2) Saturday March 26 2005, @08:07PM
            • Re:Plurals by all your mwbassguy a (Score:2) Saturday March 26 2005, @11:14PM
            • Re:Plurals by Ohreally_factor (Score:2) Sunday March 27 2005, @04:31AM
            • Re:Plurals by lafuerzasindical (Score:1) Sunday March 27 2005, @11:49AM
            • Re:Plurals by theTerribleRobbo (Score:1) Sunday March 27 2005, @03:48AM
            • Re:Plurals by Anonymous Coward (Score:1) Sunday March 27 2005, @08:04AM
              • Re:Plurals by Golias (Score:2) Monday March 28 2005, @02:52AM
            • 1 reply beneath your current threshold.
          • 1 reply beneath your current threshold.
        • Re:Stupid by Zeinfeld (Score:3) Saturday March 26 2005, @04:12PM
          • Re:Stupid (Score:4, Insightful)

            Oh you say, no fair pointing at third party software bugs, they don't count. Well sure they do

            It is not correct, however, to blame Apple for the bugs in Apache. When people rant about bugs in IE, they blame Microsoft and the IE developers. When people rant about bugs in firefox, they don't complain to Torvalds, do they?
            This competition was about the bugs on Macs, and the accusations that Macs are as vulnerable as Windows PCs. Third party software is not "Macs." The competition compares OS X and Windows, not OS X with [product] and Windows with [product.] However, it would be valid to blame vulnerable first-party software - such as Finder, or IE.

            [ Parent ]
            • 1 reply beneath your current threshold.
          • Re:Stupid by arminw (Score:2) Saturday March 26 2005, @07:32PM
        • 1 reply beneath your current threshold.
      • Re:Stupid by Ohreally_factor (Score:2) Saturday March 26 2005, @02:05PM
        • 1 reply beneath your current threshold.
      • Re:Stupid (Score:4, Funny)

        by iCEBaLM (34905) <icebalm@NOSpaM.icebalm.com> on Saturday March 26 2005, @02:09PM (#12055163)
        s/their/they're/
        s/theve/they've/

        Remember kids, if you can replace your their or there with "they are" and have it make sense, it's really "they're". If you can replace your "theve" (?) with "they have" and have it make sense, it's really "they've". Contractions!

        [ Parent ]
        • 1 reply beneath your current threshold.
      • Re:Stupid by znu (Score:2) Saturday March 26 2005, @03:06PM
        • Re:Stupid by Ohreally_factor (Score:2) Sunday March 27 2005, @04:36AM
        • 1 reply beneath your current threshold.
      • 3 replies beneath your current threshold.
    • Re:Stupid (Score:5, Insightful)

      by gl4ss (559668) on Saturday March 26 2005, @01:42PM (#12054953)
      (http://--/ | Last Journal: Monday December 09 2002, @05:12PM)
      well. the contest is REALLY about finding a remote exploit hole in a mac.

      because that's what it burns down to, making it self replicating wouldn't be much of an addition.

      but why bother.. just send a chain letter with an executable for mac.. that amounts to what is some of windows viruses nowadays anyways(and that's what all symbian viruses are and they're getting awful lot of attention - they're just self replicating 'mailers' that the user needs to install themselfs).. and points out that a system that has no holes doesn't really protect you from everything(it doesn't protect the user if the user WANTS to install the software, which many do).

      [ Parent ]
      • Re:Stupid by ryanr (Score:3) Saturday March 26 2005, @01:49PM
      • Not as easy as you think (Score:5, Insightful)

        by mamladm (867366) on Saturday March 26 2005, @02:59PM (#12055545)
        (http://www.astmasters.net/maml.html)
        Sending an executable as a mail attachment is easy, but fooling a user into launching is is much harder on the Mac than it is on Windows.

        Unlike Windows, the MacOS uses filesystem embedded filetype and resource fork information to determine what kind of file a file is. You can't just change the filename into photo.jpg or letter.doc to make the attachment look like a photo or a word document. If it is an executable, the Mac will show it as such.

        This means you will have to convince the user that the ececutable in question comes from a trusted source and that it is safe to launch. Even then, MacOS X will open a dialog that explains to the user that this is the first time this application is about to be launched, that it might be dangerous and then ask if the user wants to proceed. At that point most Mac users will cancel if they are not sure what this application is and where it came from.

        But even if they proceed to launch the application, then the application still won't be able to install anything on the user's machine. If it tries to do that, the user will again be notified that some software is about to be installed and that an administrator password is required to do so.

        Somebody would have to be incredibly naive to ignore all the warnings and still proceed.

        This type of attack is rather unlikely to be successful in causing a spreading of the trojan. The propagation mechanism is far too weak. The news about such an attack will be all over the net before the trojan had a chance to propagate.

        If anybody is to succeed with an attack against the Mac, it would have to be an exploit of some security flaw in the OS or in a privileged application.
        [ Parent ]
        • Re:Not as easy as you think by gl4ss (Score:2) Saturday March 26 2005, @03:37PM
          • Re:Not as easy as you think (Score:4, Insightful)

            by mamladm (867366) on Saturday March 26 2005, @04:05PM (#12055977)
            (http://www.astmasters.net/maml.html)
            The warning that an executable is being launched for the first time is standard on MacOS X for _any_ executable. The warning is initiated by the OS, not the executable itself. It thus applies to _every_ program indeed.

            If you haven't seen this, then you either haven't launched any new applications since this feature was introduced, or you are running an older version of OSX. I can't tell you exactly when this was introduced, but it has been around for a while now - my best guess would be sometime between 10.3.3 and 10.3.7.

            As far as your assertion of "stupid users" who will click on anything and proceed regardless of how many warnings they are being given, is concerned I tend to think that it is not the "stupidity" of users but the presentation of alerts by the OS which makes a big difference.

            Remember that there have been attempts of trojans for OSX not so long ago and they didn't cause a major impact. I seem to remember that only one person reported to have launched a hostile script and getting hit as a result.

            In my opinion the way the alerts are being presented makes a big difference. I believe that Microsoft could improve the security of Windows users significantly if only they worked out how to properly alert people, how to design alerts in such a way that even lazy folks who always click through will have to stop and think before they click.
            [ Parent ]
            • Re:Not as easy as you think by gl4ss (Score:2) Saturday March 26 2005, @05:26PM
            • Re:Not as easy as you think by jawtheshark (Score:1) Saturday March 26 2005, @05:26PM
            • Re:Not as easy as you think (Score:4, Informative)

              by Have Blue (616) on Sunday March 27 2005, @01:45PM (#12060852)
              (http://www.seizurerobots.com/)
              The warning that an executable is being launched for the first time is standard on MacOS X for _any_ executable. The warning is initiated by the OS, not the executable itself. It thus applies to _every_ program indeed.

              This thread has the wrong idea about how this feature works. The dialog does not appear the first time any app is launched. It only appears if you try to open a document or URL that results in the Finder having to launch an app that you have never launched before. There are very few legitimate situations where you would have to do this, so it's quite likely that some users have never seen the message before.

              This dialog is meant to deter the following exploit:
              1. User clicks malicious link.
              2. Page uses scripting to automatically downloads a disk image.
              3. If the user has "open safe files" enabled in Safari, the disk image will be automatically mounted in the Finder. This makes the Finder scan the disk image for applications and add them to the Launch Services database, which is how it knows that application X opens file type Y- and that application A is a helper app for URL scheme B.
              4. The disk image contains an application whose metadata indicate it can handle URLs of type malware://. The Finder sees this and registers it.
              5. The malicious web pages waits a few moments so the previous few steps can complete, then attempts to redirect to malware://blah.
              6. The Finder helpfully launches the application on the disk image to handle the URL. Owned.
              [ Parent ]
              • 1 reply beneath your current threshold.
        • Re:Not as easy as you think by TrancePhreak (Score:2) Saturday March 26 2005, @05:04PM
        • Not as hard as you think (Score:5, Insightful)

          by DragonHawk (21256) on Saturday March 26 2005, @05:24PM (#12056421)
          (http://slashdot.org/ | Last Journal: Saturday November 18 2006, @08:52AM)
          "Somebody would have to be incredibly naive to ignore all the warnings and still proceed."

          Yes, and if ignorance really was bliss, the world would be one hell of a lot happier then it actually is.

          I'm an IT consultant.

          I've watched countless users sit there and click though endless dialogs warning them about how they're about to unleash bubonic plague upon the world or whatever. These people regard warnings as a hassle, something to be dismissed as quickly as possible. They do not regard them as an actual warning. Warnings are something that apply to other people.

          If you change the default button to be the "safe" option, they click-and-close, try again and click-and-close, try again and click the other button and continue. They don't do this by reading the dialogs, they do this because if it didn't work the first two times they tried the first button, then it must be the other one.

          If you require users to enter in "please destroy all my data" on the keyboard before running something, they will happily do that, to. While asking me why it asks them that.

          If you require them to type a password, they'll type that in upon request, too. Look at how successful phishing scams are.

          If all this fails to get some badware on the computer, users will seek out things like "Hotbar", "Gator", "Comet Cursor", "Bonzai Buddy", and so on, and try to install them.

          People just don't want to have to think. That's the ultimate problem.

          There's no doubt that the average MS-Windows system, as deployed, is hideously insecure. However, experience has shown me that even if you lock the system down well, users will still try and destroy it.

          I've found the only way to keep users from compromising the security of their system is to remove their ability to do so. Then they just complain to me constantly that they cannot install all their badware. But then I can just tell them "Tough!".
          [ Parent ]
        • Easier than you think by Magic5Ball (Score:2) Saturday March 26 2005, @05:31PM
          • Re:Easier than you think (Score:5, Insightful)

            Nice theory, but here's a few more points for you:

            1. Finder doesn't display previews of Postscript files.
            2. Finder doesn't display previews of EPS files, either. (It might if they have attached bitmap previews, but I'm not sure.)
            3. Finder does display PDFs natively (and Quartz uses very PDF-like display lists natively), but PDF is not Turing-complete.
            4. It doesn't matter if the language is Turing-complete if it executes in a contained environment. Malicious code can only harm what it has access to, by definition.

            Postscript has been around two decades now, and AFAIK the only "virus" ever reported written it couldn't do anything but reset your Apple Laserwriter password. If you think you can write a Postscript program which reformats my hard drive, talks to my mail client, or even just brings up a dialogue box on my screen that says "Hi, I'm PostScript!", you're welcome to start hackin' now.

            [ Parent ]
          • Re:Easier than you think by FrangoAssado (Score:1) Sunday March 27 2005, @02:37AM
          • Re:Easier than you think by macmurph (Score:2) Sunday March 27 2005, @04:55PM
          • 2 replies beneath your current threshold.
        • Re:Not as easy as you think by DenDave (Score:2) Saturday March 26 2005, @06:00PM
        • Re:Not as easy as you think by Skuld-Chan (Score:2) Saturday March 26 2005, @07:12PM
        • Re:Not as easy as you think by Tim C (Score:2) Saturday March 26 2005, @07:55PM
        • Re:Not as easy as you think by Psychic Burrito (Score:2) Saturday March 26 2005, @08:41PM
        • Re:Not as easy as you think by drsmithy (Score:2) Sunday March 27 2005, @10:58PM
        • This is both wrong and misinformed. by Paradox (Score:2) Monday March 28 2005, @08:57PM
        • 2 replies beneath your current threshold.
      • Re:Stupid by un1xl0ser (Score:2) Saturday March 26 2005, @03:25PM
        • Re:Stupid by It'sYerMam (Score:2) Saturday March 26 2005, @05:25PM
        • Re:Stupid by drsmithy (Score:2) Sunday March 27 2005, @11:15PM
      • Re:Stupid by myov (Score:2) Saturday March 26 2005, @08:48PM
    • Re:Stupid by R.Mo_Robert (Score:1) Saturday March 26 2005, @01:47PM
      • Re:Stupid by ryanr (Score:2) Saturday March 26 2005, @01:52PM
        • 1 reply beneath your current threshold.
    • Re:Stupid by aftk2 (Score:2) Saturday March 26 2005, @01:47PM
    • Re:Stupid by lphuberdeau (Score:3) Saturday March 26 2005, @01:48PM
    • They should be the experts. (Score:4, Interesting)

      by khasim (1285) <brandioch.conner@gmail.com> on Saturday March 26 2005, @01:52PM (#12055037)
      3) I'm so sure it's worth $50,000 for Symantec to finally put that "Antivirus companies don't write viruses" myth to bed.
      Their people should be among the best qualified to show how easy it is to infect a Mac.

      Would you accept the word of a locksmith telling you that your current locks aren't sufficient and that you should give him lots more money to put new locks on your house if he cannot SHOW you how easy it is for him to pick your current locks?

      It's time for Symantec to put up or shut up. Either Macs do need their software AND they can prove it or they're just pushing their software with lies.
      1) If a virus has spread over every Mac on the Internet, then it's harmful.
      That's an awful big "if".
      4) We're going to use antivirus software to determine if we've been infected... which will only catch previously known viruses.
      That's a real problem. Either the virus writer has to modify an existing virus so that its signature is picked up, or send the virus software companies a copy of his virus so they can update their signature files.
      5) Hey you guy that wrote the virus that spread to every Mac on the Internet: just identify yourself afterwards, and we'll pay you.
      That's about how it will go.

      Either someone has to show how it can be done, or Symantec needs to shutup about how vulnerable Macs are.

      Personally, I don't see much of a problem there.

      Worms attack through ports.

      Viruses load themselves into memory and infect other files.

      Trojans only run when you launch them.

      From the article, it looks as if they're hunting for worms or exploitable holes in apps. But the most common Windows-side issues now are trojans emailing themselves to everyone.
      [ Parent ]
    • Re:Stupid by 88NoSoup4U88 (Score:2) Saturday March 26 2005, @03:14PM
    • Baleeted! by ryanr (Score:2) Saturday March 26 2005, @03:42PM
    • Stupid as his Soup site by Killer Instinct (Score:1) Saturday March 26 2005, @08:52PM
    • Re:Stupid by praetis (Score:1) Saturday March 26 2005, @10:51PM
    • Re:Stupid by tonywong (Score:2) Sunday March 27 2005, @01:40AM
    • Re:Stupid by ivano (Score:1) Saturday March 26 2005, @02:08PM
      • Re:Stupid by ivano (Score:1) Sunday March 27 2005, @11:07AM
      • 1 reply beneath your current threshold.
    • Re:Stupid by ryanr (Score:2) Sunday March 27 2005, @01:56AM
    • 5 replies beneath your current threshold.
  • Seems dangerous by presidentbeef (Score:1) Saturday March 26 2005, @01:38PM
  • and.. by Turn-X Alphonse (Score:2) Saturday March 26 2005, @01:39PM
  • I am going to laugh... (Score:4, Insightful)

    by bob670 (645306) on Saturday March 26 2005, @01:41PM (#12054941)
    for days when someone suceeds at this. Never dare someone to do stuff like this, it is just too tempting of a target.
    • Re:I am going to laugh... by Anonymous Luddite (Score:2) Saturday March 26 2005, @01:54PM
    • Apple will be suing .... by alexandreracine (Score:1) Saturday March 26 2005, @01:59PM
    • It would only make OSX more secure by mamladm (Score:2) Saturday March 26 2005, @03:36PM
      • by theCoder (23772) on Saturday March 26 2005, @05:41PM (#12056490)
        (http://slashdot.org/ | Last Journal: Saturday April 01 2006, @07:15PM)
        I hate to break it to you, but there's very little that Apple (or Mircosoft, or Linux, etc) can do to prevent many types of viruses, since they are installed by the user themselves. Think about a traditional virus that infects a binary and is run when the program is run. Or a trojan program that does bad things to your system. Good file permissions can prevent the spread of such viruses and limit their damage, but they aren't that hard to write. I've even seen prototypes for a shell script virus (in an educational setting, and non-destructive except for polluting your shell scripts). There's very little technically that anyone can do to prevent a shell script virus, at least not without making the system difficult to use (or radically redesigning the system, which will probably have other drawbacks).

        Now, if you're talking about worms, yes most spread through security holes in the system, and those can be fixed. But there are many classes of malware where the security "hole" is the human doing work. And those are very hard, if not impossible to prevent.

        [ Parent ]
    • 2 replies beneath your current threshold.
  • Balance (Score:3, Interesting)

    by fish34 (636162) on Saturday March 26 2005, @01:41PM (#12054944)
    Nice balanced submission you got there. As far as I'm aware there is no conclusive evidence that shows Macs are inherently more secure and would not suffer the virus problem that Windows does if it had Windows' market share. Note that a lot of the virus problem comes from users showing bad practice (clicking 'Yes' to install things they really shouldn't, opening attachments they really shouldn't). I wouldn't be suprised if Mac users were on average more savy, and this could contribute.
    • Re:Balance by knitterb (Score:1) Saturday March 26 2005, @01:45PM
      • Re:Balance by bwintx (Score:2) Saturday March 26 2005, @03:19PM
      • 1 reply beneath your current threshold.
    • Re:Balance by Anonymous Coward (Score:3) Saturday March 26 2005, @01:48PM
      • Re:Balance by jawtheshark (Score:1) Saturday March 26 2005, @05:37PM
    • Re:Balance (Score:5, Informative)

      by Snocone (158524) on Saturday March 26 2005, @01:55PM (#12055067)
      (http://www.alexcurylo.com/)
      As far as I'm aware there is no conclusive evidence that shows Macs are inherently more secure and would not suffer the virus problem that Windows does if it had Windows' market share.

      The conclusive evidence is that OS X is a flavour of *BSD.

      If that doesn't strike you as conclusive, then feel free to explain how it is that Apache running on *BSD has such a better security record than IIS running on Windows, despite the fact that the Apache setup has, always has had, and most likely always will have too, a market share far greater than that of IIS.

      That certainly strikes *me* as being a pretty compelling counterargument to the greater market share theory of hacker victimization, anyway...
      [ Parent ]
      • Re:Balance (Score:4, Insightful)

        by IamTheRealMike (537420) on Saturday March 26 2005, @02:09PM (#12055161)
        (http://plan99.net/~mike/)
        Being based on BSD has nothing to do with anything, the userland/desktop space is where most exploits have been in recent years and the Aqua shell is no more free from exploits than Explorer is.

        In particular, appfolders have had some pretty nasty broken-by-design security exploits like the URL handler variants where an internet enabled DMG would self-mount itself into the filing system and automatically reconfigure URL schemes in Safari, all without the user doing anything other than visiting a web page. I think (hope) they fixed that but it was still several months until all the holes and variants of this technique were "fixed" (really just hacked around). The help system exploits Apple suffered were similar in nature.

        Essentially, Apple haven't proven themselves any more skilled at designing secure desktops than Microsoft have. That said, this sort of competition is fairly pointless: being able to "infect" a machine with no action taken by the user boils down to finding buffer/heap overflows and the like in running software. Many viruses propogate with a bit of help from the user, even if all that involves is surfing the web.

        [ Parent ]
        • Re:Balance by 51mon (Score:1) Saturday March 26 2005, @02:58PM
        • Re:Balance by NFNNMIDATA (Score:1) Saturday March 26 2005, @03:47PM
          • Re:Balance by IamTheRealMike (Score:2) Saturday March 26 2005, @04:05PM
            • 1 reply beneath your current threshold.
          • Re:Balance by Dylan Zimmerman (Score:2) Sunday March 27 2005, @01:42AM
        • Meaning of "proved" by MisterSquid (Score:2) Saturday March 26 2005, @04:15PM
        • Re:Balance (Score:5, Interesting)

          by node 3 (115640) on Saturday March 26 2005, @04:59PM (#12056292)
          Being based on BSD has nothing to do with anything,

          Are you serious? It's a significant swath of the OS that you don't have to worry about!

          the userland/desktop space is where most exploits have been in recent years

          Wrong. Most 'theoretical' exploits have been in the BSD/OSS side of OS X. Absolutely none of those 'theoretical' exploits have been known to have been actually 'exploited' (all you've had was a 'click this to test' proof-of-concept).

          the Aqua shell is no more free from exploits than Explorer is.

          That's absurd. Aqua isn't what you use every day to visit untrusted sites with, while Explorer is. That makes it harder to exploit, which makes it inherently more secure.

          I think (hope) they fixed that but it was still several months until all the holes and variants of this technique were "fixed" (really just hacked around).

          The 'hack' fixes came out the same day, Apple's fix was about two weeks later, primarily because it wasn't a 'patch', it was a change in the policy for running apps from Safari.

          Essentially, Apple haven't proven themselves any more skilled at designing secure desktops than Microsoft have.

          Except for the fact that there have been *zero* malicious exploits for OS X.

          Zero, none, el zip-o, a big goose egg (like the one on your face).
          [ Parent ]
          • Re:Balance by lixlpixel (Score:1) Sunday March 27 2005, @03:07PM
        • Re:Balance by Anonymous Coward (Score:1) Saturday March 26 2005, @05:42PM
        • Re:Balance by grunherz (Score:1) Tuesday March 29 2005, @01:07PM
        • 1 reply beneath your current threshold.
      • Because Normal Users don't run Apache! by Anonymous Coward (Score:1) Saturday March 26 2005, @02:29PM
      • Re:Balance (Score:5, Insightful)

        by groomed (202061) on Saturday March 26 2005, @03:40PM (#12055841)
        The conclusive evidence is that OS X is a flavour of *BSD.

        This is a meaningless statement. It is unclear what bearing the BSD heritage has on the ability of OS X to thwart the kind of trojan/malware attacks that Windows users are subjected to.

        If that doesn't strike you as conclusive, then feel free to explain how it is that Apache running on *BSD has such a better security record than IIS running on Windows

        Without knowing which versions of Apache, BSD, IIS and Windows you are referring to, it is impossible to establish whether your assertion that the Apache/BSD combo is more secure than the IIS/Windows combo is actually true.

        And even if it were universally true, it is unclear what bearing any purported security benefit of Apache/BSD over IIS/Windows has on the ability of OS X to thwart the mostly email-propagated attacks that Windows users are subjected to.

        That certainly strikes *me* as being a pretty compelling counterargument to the greater market share theory of hacker victimization, anyway...

        If you think a non-sequitur based on unsubstantiated premises qualifies as a "compelling counterargument" of any sort, I suppose.
        [ Parent ]
        • Re:Balance by node 3 (Score:2) Saturday March 26 2005, @05:16PM
          • Re:Balance by groomed (Score:2) Saturday March 26 2005, @06:17PM
            • Re:Balance by node 3 (Score:2) Saturday March 26 2005, @10:40PM
              • Re:Balance by groomed (Score:2) Saturday March 26 2005, @10:56PM
              • Re:Balance by node 3 (Score:2) Sunday March 27 2005, @12:55AM
              • Re:Balance by groomed (Score:2) Sunday March 27 2005, @07:50AM
              • Re:Balance by node 3 (Score:3) Sunday March 27 2005, @04:33PM
              • Re:Balance by groomed (Score:2) Monday March 28 2005, @03:08AM
              • Re:Balance by node 3 (Score:2) Monday March 28 2005, @04:18AM
              • Re:Balance by groomed (Score:2) Monday March 28 2005, @04:34AM
              • Re:Balance by node 3 (Score:2) Tuesday March 29 2005, @01:38AM
              • Re:Balance by groomed (Score:2) Tuesday March 29 2005, @06:14PM
              • Re:Balance by AndyCadley (Score:1) Thursday March 31 2005, @02:57PM
              • 2 replies beneath your current threshold.
      • Re:Balance by m3talsling3r (Score:1) Saturday March 26 2005, @03:54PM
      • The OTHER factors missed... by AKosygin (Score:1) Saturday March 26 2005, @04:36PM
      • Re:Balance by geekee (Score:2) Saturday March 26 2005, @04:37PM
      • What about Windows NT? by ImaLamer (Score:2) Saturday March 26 2005, @05:11PM
      • Re:Balance by Anonymous Coward (Score:3) Saturday March 26 2005, @02:51PM
      • 3 replies beneath your current threshold.
    • Re:Balance by willCode4Beer.com (Score:3) Saturday March 26 2005, @01:56PM
      • Re:Balance by Lars T. (Score:2) Saturday March 26 2005, @02:28PM
      • Re:Balance by kevcol (Score:3) Saturday March 26 2005, @03:29PM
        • Re:Balance by kevcol (Score:3) Saturday March 26 2005, @03:53PM
          • Re:Balance by MSTCrow5429 (Score:2) Saturday March 26 2005, @07:00PM
            • Re:Balance by kevcol (Score:2) Saturday March 26 2005, @07:10PM
      • Re:Balance by gnasher719 (Score:1) Saturday March 26 2005, @07:12PM
        • Re:Balance by anthony_dipierro (Score:1) Saturday March 26 2005, @07:29PM
      • 2 replies beneath your current threshold.
    • Re:Balance (Score:5, Informative)

      by tehshen (794722) <tehshen@gmail.com> on Saturday March 26 2005, @01:56PM (#12055075)
      clicking 'Yes' to install things they really shouldn't

      Macs use verbs in dialog boxes, instead of 'Yes', 'No' and 'Cancel'. The button to install software on a Mac would be 'Install Software', not 'Yes', so clueless users have a better sense of what they are doing.

      Discussed better here [xvsxp.com]
      [ Parent ]
      • Re:Balance by RzUpAnmsCwrds (Score:2) Sunday March 27 2005, @02:18AM
      • Re:Balance by Lars T. (Score:2) Saturday March 26 2005, @04:49PM
        • 1 reply beneath your current threshold.
      • Re:Balance by lcracker (Score:2) Saturday March 26 2005, @05:05PM
        • Re:Balance by ratsnapple tea (Score:1) Saturday March 26 2005, @11:47PM
        • 1 reply beneath your current threshold.
      • 1 reply beneath your current threshold.
    • No conclusive evidence by xeno-cat (Score:3) Saturday March 26 2005, @01:57PM
      • Re:No conclusive evidence by erick99 (Score:1) Saturday March 26 2005, @02:11PM
      • Re:No conclusive evidence by 51mon (Score:1) Saturday March 26 2005, @02:44PM
      • Re:No conclusive evidence by ryanr (Score:2) Saturday March 26 2005, @03:09PM
      • Re:No conclusive evidence by groomed (Score:2) Saturday March 26 2005, @03:49PM
        • Re:No conclusive evidence (Score:4, Insightful)

          by xeno-cat (147219) on Saturday March 26 2005, @04:37PM (#12056150)
          (http://www.deximer.com/)
          "Only if you choose to ignore the preponderance of evidence in the form of viruses targetting Windows."

          Which may or may not be do to Windows market share. It may also not have to do with any one factor. The problem I see is when Windows zealots use the market share argument exlusively to defend Windows.

          I'm really trying to extract your point from your post and not having much success.

          How is Classic MacOS and DOS less secure? DOS had zero internet connectivity out of the box. Even if you added a TCP/IP stack there were no services you were going to run on DOS. If you ran Windows 3.1 or something you could run Netscape I think. But then, here we are with Windows (actually, DOS) again with about the same market share as Windows has today and no rampent network exploit problem. So again, I'm not sure what your getting at.

          The fact that Windows is exploted is proof that it is insecure. That is my point. Speculating that Linux or Mac would be just as insecure if they had the same market share is just speculation. It also ignores the possiblity that a system that was easier, or even as easy, to exploit as Windows but had a smaller market share might also be exploited. So the fact that Linux and Mac exploits are not a pandemic does not mean that they are just as insecure as Windows. It's not "fact-free hystrionics", it's just observation and logic.

          Now if you think Linux is insecure because Windows is exploited maybe you can elaborate on why that is so I can better understand what your getting at. If on the other hand your arguing something else, please don't confuse it with my argument because you make me feel like you are'nt really paying attention to what I am saying.

          Kind Regards

          [ Parent ]
        • Re:No conclusive evidence by foszae (Score:1) Saturday March 26 2005, @04:59PM
    • Re:Balance by Planesdragon (Score:3) Saturday March 26 2005, @02:01PM
      • Re:Balance by ryanr (Score:2) Saturday March 26 2005, @04:02PM
      • Re:Balance by squiggleslash (Score:2) Saturday March 26 2005, @06:07PM
      • Re:Balance by squiggleslash (Score:1) Saturday March 26 2005, @02:46PM
        • Re:Balance by arminw (Score:2) Saturday March 26 2005, @09:18PM
      • 1 reply beneath your current threshold.
    • Re:Balance by Anonymous Coward (Score:1) Saturday March 26 2005, @02:03PM
    • Re:Balance by Homology (Score:2) Saturday March 26 2005, @02:03PM
      • Re:Balance by groomed (Score:2) Saturday March 26 2005, @03:27PM
        • Re:Balance by Homology (Score:2) Saturday March 26 2005, @04:00PM
          • Re:Balance by groomed (Score:2) Saturday March 26 2005, @04:33PM
            • Re:Balance by Homology (Score:2) Sunday March 27 2005, @03:13AM
          • Re:Balance by geekee (Score:2) Saturday March 26 2005, @04:48PM
            • Re:Balance by Homology (Score:2) Sunday March 27 2005, @02:48AM
    • Re:Balance by TCQuad (Score:1) Saturday March 26 2005, @02:22PM
      • Re:Balance by Lars T. (Score:2) Saturday March 26 2005, @02:31PM
        • Re:Balance by TCQuad (Score:1) Saturday March 26 2005, @02:35PM
    • Mac is *nix by WindBourne (Score:2) Saturday March 26 2005, @02:49PM
    • Back in the Day by Greyfox (Score:2) Saturday March 26 2005, @02:49PM
    • Re:Balance by ScrewMaster (Score:2) Saturday March 26 2005, @02:58PM
    • On this subject, I recently answered a query raised during a Chronicle of Higher Education colloquy. I believe it touches on the major issues here.

      Question from Lisa L. Spangenberg, UCLA:
      Given that there are no viruses or Trojan horses for the current Macintosh system, OS X 10.3, and given that it is essentially UNIX, and given that the most common applications (Microsoft Office Suite, Adobe applications) work very well on OS X, why don't more institutions adopt Macs and encourage faculty to use them?

      Gregory A. Jackson:
      Well, first of all, there are viruses and Trojans that afflict MacOS, witness Apple's periodic release of security fixes to counteract them.


      First, that isn't true, regarding viruses. To date, there are no known viruses that specifically target Mac OS X. Last week's "trojan" was nothing more than an application with a different icon and misleading name that displayed a dialog box (which was an example posted to a USENET Mac programming group to illustrate this fact that has been known and possible on Mac OS for over twenty years; an antivirus vendor apparently thought this an appropriate time to dress it up, incorrectly, as some new, terrible exploit easily adapted for malicious means, when in reality it's nothing more than an application).

      If you're referring more broadly to security issues in general, almost all of the security and security-related updates for Mac OS X to date have been updates for primarily server-type services that ship with the OS, all of which are disabled by default, and the lion's share of which are never even enabled, much less touched, on the vast majority of systems. I'm not saying that they should be ignored, but Apple's comprehensive and swift response to the most minor security issues does not rise to the level of the staggeringly numerous, sometimes completely automated, remote exploits, worms, and so on for Windows. It is no longer possible to even get through a full installation Windows XP on a machine connected to a public network without it being exploited before you even have a chance to patch it.

      It's definitely possible for Mac OS X to have viruses, worms, trojans, and other malware - Mac OS X is not invulnerable, and no sensible person would claim it to be. But the underlying philosophical design principles are fundamentally more secure than Windows, period. Since the major ingredient for the success of a worm or virus is some ability to spread, witness the fact that there is no way with anything built into Mac OS X to perform automated propagation of a virus, and no current known ways to exploit a machine remotely, not to mention that potentially exploitable network services are disabled to begin with anyway (and remain that way unless explicitly enabled), a stark contrast to Windows. Any hope for automatic propagation would require a comparatively high level of sophistication, and perhaps even its own mail server - not to mention some intrinsic vulnerability to exploit. On the other hand, there are still, to this moment, unfixed vulnerabilities in certain versions of Outlook that will spread certain virus variants simply by previewing a message, and nothing more. There is simply no equivalent to this on any other platform. Microsoft's track record and attitude on security (though admittedly much improved) versus other vendors speaks volumes on this topic.

      It takes work and thought to do security, and do it right. Ease of use and security aren't mutually exclusive. The key is to make security easy to use, and Apple has so far been on the right road with Mac OS X.


      But the small installed base of Macs makes them an unexciting, low-visibility target for the bad guys, and so the weaknesses don't get exploited much.

      The marketshare argument only goes so far. This seems to be a version of the "Macs have no software" argument. It is indeed true that they are targeted less for this reason. But the argument that it's straight cause-and-effect is disingenuous
      [ Parent ]
    • Re:Balance by shaitand (Score:2) Saturday March 26 2005, @03:41PM
    • Re:Balance by Lars T. (Score:2) Saturday March 26 2005, @04:19PM
    • Re:Balance by arminw (Score:2) Saturday March 26 2005, @08:18PM
      • Re:Balance by AndyCadley (Score:1) Thursday March 31 2005, @03:28PM
        • Re:Balance by arminw (Score:2) Thursday March 31 2005, @11:32PM
    • Re:Balance by 1u3hr (Score:2) Sunday March 27 2005, @03:29AM
    • Re:Balance by darkgreen (Score:1) Saturday March 26 2005, @03:15PM
    • 6 replies beneath your current threshold.
  • To the winner: by Anonymous Coward (Score:1) Saturday March 26 2005, @01:42PM
    • 1 reply beneath your current threshold.
  • "Harmless and Benign" by Winckle (Score:2) Saturday March 26 2005, @01:42PM
  • "Experienced Mac developers" my ass. (Score:5, Interesting)

    by qengho (54305) on Saturday March 26 2005, @01:42PM (#12054952)
    This is the notorious Jack Campbell [macintouch.com], one of the shadiest characters around. It's undoubtedly a publicity stunt for his business. What a jerk.
  • And we've got a winner! (Score:5, Funny)

    by Flounder (42112) * on Saturday March 26 2005, @01:42PM (#12054954)
    Microsoft Word 6.0 for Mac

    Even a virus would be more useful.

  • here's how it goes by hyperstation (Score:2) Saturday March 26 2005, @01:43PM
  • This strikes me as irresponsible. (Score:4, Interesting)

    by MillionthMonkey (240664) on Saturday March 26 2005, @01:43PM (#12054961)
    (Last Journal: Wednesday January 31 2007, @02:25AM)
    They aren't asking for source code to the virus, or the virus to be sent to them (and only to them) in a polite form, they're leaving two Macs exposed to the net and expecting to pick a winner by what their virus scanning software finds. You claim the money by sending them a 32 character string that appears in the virus.

    If you got a virus to them this way, I think the $25k would only begin to cover your legal bills.
    • Re:This strikes me as irresponsible. by crimoid (Score:2) Saturday March 26 2005, @01:51PM
    • Re:This strikes me as irresponsible. by anagama (Score:2) Saturday March 26 2005, @01:57PM
      • Re:This strikes me as irresponsible. (Score:4, Informative)

        by John Newman (444192) on Saturday March 26 2005, @02:11PM (#12055173)
        If you have permission to run a virus on their computers, and lets assume that their two computers are walled off from the rest of the world so the infection strays no further, why would you have legal bills?
        If you RTFA, it says that the two computer are at separate locations, linked only via the internet-at-large. No IP's are given. The expectation is that the only way to win the prize is to release a virus that is sufficiently virulent to infect virtually every non-firewalled Mac on the internet, so that it eventually gets to both of these random, anonymous Macs. They request "benign" viruses only, but at that level of virulence there's probably no such thing (even if it doesn't harm the computers themselves, it'll hammer a network). I wouldn't be at all surprised if the FBI subponeaed the contact info of the "winner".
        [ Parent ]
      • Re:This strikes me as irresponsible. by MillionthMonkey (Score:2) Saturday March 26 2005, @02:18PM
      • 1 reply beneath your current threshold.
    • Re:This strikes me as irresponsible. by Cougem (Score:1) Saturday March 26 2005, @02:14PM
    • What I'd wonder (Score:5, Interesting)

      by mcc (14761) <amcclure@purdue.edu> on Saturday March 26 2005, @03:26PM (#12055728)
      (http://allstarpowerup.com/)
      If you contract and pay someone to kill someone else, you are held liable in their murder. I'd assume if you contract and pay someone to write a virus, you're liable for whatever computer crimes are broken as well.

      If you offer a $25,000 prize to someone who writes a virus, you are contracting someone to write a virus, and I would very much expect you are liable to be charged with computer crimes even if the person who writes the virus is never caught.

      If you look at the link, these people have cancelled their contest. But the offer was still made. I am not sure canceling the contest is enough to get them out of legal liability of having offered cash to break the law. If someone attempts a mac virus in the next month, or some other timeframe that would make it likely to be a response to this "contest", I wonder what will happen to them.
      [ Parent ]
  • Bah (Score:5, Insightful)

    by Dachannien (617929) on Saturday March 26 2005, @01:44PM (#12054970)
    (http://www.unity08.com/)
    A computer is only as secure as its user. Are they going to man these two naked Macs with total noobs, to make it a fair contest?
    • Re:Bah by v1 (Score:2) Saturday March 26 2005, @02:01PM
      • Re:Bah by Anonymous Coward (Score:1) Saturday March 26 2005, @02:32PM
    • Re:Bah by Anonymous Coward (Score:1) Saturday March 26 2005, @02:16PM
      • Re:Bah by Lars T. (Score:2) Saturday March 26 2005, @04:26PM
    • Re:Bah by Lars T. (Score:2) Saturday March 26 2005, @02:42PM
    • U got it backwards by WindBourne (Score:3) Saturday March 26 2005, @03:02PM
    • your attitude is why Microsoft is in business by Scudsucker (Score:1) Sunday March 27 2005, @12:59PM
  • In other news, Microsoft... by bird603568 (Score:1) Saturday March 26 2005, @01:44PM
  • Check out the Sponsor ... (Score:5, Interesting)

    by Socket Scientist (777417) on Saturday March 26 2005, @01:44PM (#12054974)
    ... before wasting your time.

    Something tells me it's unlikely you'd ever see the cash, even if you were to succeed.

    Google for Jack Campbell and MacTable for more info on this guy's shady past.

  • What about the user? (Score:3, Interesting)

    by PxM (855264) on Saturday March 26 2005, @01:44PM (#12054976)
    Since the majority of viruses, spyware, and other crap are due to user inaction, this isn't really a fair metric about the overall security. However, it is good to compare against the Windows survival time which is measured in minutes [sans.org]. This does show that Apple has its default security setup as "paranoid with multiple tin foil hats) compared to Windows XP's default setup. A more interesting test would compare how hard it is to get spyware onto a user's computer via the default webbrowser since that seems to be the primary vector these days. However, this is problematic since it's heavily dependent on user stupidity.

    --
    Want a free iPod? [freeipods.com]
    Or try a free Nintendo DS, GC, PS2, Xbox. [freegamingsystems.com] (you only need 4 referrals)
    Wired article as proof [wired.com]
  • C'mon... (Score:3, Informative)

    by _PimpDaddy7_ (415866) on Saturday March 26 2005, @01:45PM (#12054981)
    "Macs aren't more secure, it's just that Windows is a bigger target"

    While this statement may SOUND true, it's a fact, MAC OS X was built with more security in mind than Windows. Security was built into the OS from the ground up. That can't be said of Windows.

    While making a statement such as "Macs can't have a virus" is false, I would say it would be more difficult to make one, than creating one for a Windows box, which seems like an Joe Shmoe can do.
    • Re:C'mon... by failure-man (Score:1) Saturday March 26 2005, @02:13PM
    • Re:C'mon... by mt v2.7 (Score:1) Saturday March 26 2005, @02:51PM
    • Re:C'mon... by TheRaven64 (Score:2) Saturday March 26 2005, @03:42PM
    • 1 reply beneath your current threshold.
  • Sound more like a test of Email client then the OS by ID000001 (Score:1) Saturday March 26 2005, @01:45PM
  • How come? by John Seminal (Score:2) Saturday March 26 2005, @01:45PM
    • Re:How come? by eluusive (Score:1) Saturday March 26 2005, @02:00PM
  • Interesting strategy by ATomkins (Score:1) Saturday March 26 2005, @01:46PM
  • Totally Bogus? by LordPhantom (Score:1) Saturday March 26 2005, @01:46PM
    • Re:Totally Bogus? by rokzy (Score:2) Saturday March 26 2005, @02:14PM
      • Re:Totally Bogus? (Score:5, Insightful)

        by SJS (1851) on Saturday March 26 2005, @03:15PM (#12055651)
        (http://www-rohan.sdsu.edu/~stremler | Last Journal: Wednesday September 26, @10:29PM)
        2. they require entering the admin password for significant changes whereas XP is happy for you to run as admin 24/7 without further confirmation of any actions.
        Any application can pop a dialog asking for the admin password, and more programs all the time are doing so.

        Tried to install any applications lately (like, say, OpenOffice)? The installer demands administrator access, and will REFUSE to continue unless it gets it. Even if you're only going to install it into /tmp or $HOME to check it out.

        Try to compile F95 in GCC? You might be instructed to download a DMG of "up to date" cctools. But when you mount the drive, you get an installer, and this installer also demands administrator access, presumably so it can stomp on the tools already installed. And it's non-obvious where you go to get the source that will compile on the Mac so you can install it in a place of your own choosing.

        Mac users are slowing being trained to be as dumb as MSWindows users. When the pretty little dialog asks for the administrator password, just provide it, otherwise you won't be able to play, and the maintainers of that package will mock you. Caution? What's that? Prudence? Soooo old-school. Paranoia? Get a life!

        There's not much difference between being trained to grant a program administrative status every time it asks for it and running as the administrator all the time. It just adds a ten-second delay before your machine is compromised, and people can point at you and wonder aloud why you didn't _know_ what the program was going to do before it did it.

        I'm not giving up my Mac in favor of anything out of Redmond. I just want a stick I can beat developers with when they write installers that demand administrative access and refuse to go further until they get it. If the user declines to give the administrative password, then let them choose where to install your software, and give them a README on what they can do "by hand" to integrate your software. IF they so choose.

        [ Parent ]
        • Re:Totally Bogus? by LordPhantom (Score:1) Saturday March 26 2005, @05:09PM
        • Re:Totally Bogus? by hedora (Score:2) Sunday March 27 2005, @02:13AM
          • Re:Totally Bogus? (Score:4, Informative)

            by SJS (1851) on Sunday March 27 2005, @03:08AM (#12058991)
            (http://www-rohan.sdsu.edu/~stremler | Last Journal: Wednesday September 26, @10:29PM)
            Sure, most users will blindly type in a password if a software installer asks them to, but what about an e-mail attachment or random internet site?
            True, but if they run an email attachment, the obvious (to me, at least) thing to do would be to drop a program in a dot-file, and then modify the user's .tcshrc/.bashrc so that some later login, it pops the dialog, after prompting with an error message appearing to be from the system.

            "A critical security update is needed for your $RANDOM_APP. The update has been downloaded. Installing update..."

            [Password Dialog Here]

            Or somesuch.

            It would be better if the OS provided customizable permissions (grant networking access seperately from hard drive access, for example), but I've yet to see a good security setting setup or user interface to allow that sort of thing...
            I think that's the sort of thing a security-minded expert would prefer, and the average user would be overwhelmed by.
            It would also be nice if you could 'spoof' root access to trick software into thinking it has full access to your system.
            Yes, it would. I believe that Debian kinda-sorta does this with "fakeroot". I'd like an actual sandbox...
            For instance, the OS could intercept all calls to update files outside of a folder called "buggy-app" on the desktop, and use an overlay file system and copy-on-write to store the changes in a special directory.
            Yup! I've been pondering the need for this sort of thing for awhile. If it's clean enough, and robust enough, you can run _all_ of your applications in their own sandboxes. I think that this approach is simple enough to work for both the average home user and powerful enough to make a security guru happy.
            Only the spoofed program would use the files that it created and modified, and the changes it performed could be reversed by deleting the stuff the OS put in /tmp...
            Exactly. And if you want to keep the changes, you can put it in $HOME/.sandboxes/appname, or, since we're on the Mac, perhaps $HOME/Sandboxes/Appname/...

            I like the way you're thinking.

            [ Parent ]
          • Re:Totally Bogus? by AndyCadley (Score:1) Thursday March 31 2005, @03:47PM
    • Re:Totally Bogus? by rpozz (Score:2) Saturday March 26 2005, @02:12PM
    • 1 reply beneath your current threshold.
  • Obligatory by Schrockwell (Score:1) Saturday March 26 2005, @01:46PM
  • They want a worm not a virus by Anonymous Coward (Score:1) Saturday March 26 2005, @01:47PM
  • What's the point by evulgenius (Score:1) Saturday March 26 2005, @01:48PM
  • Fast forwarding a couple months... by origamy (Score:1) Saturday March 26 2005, @01:49PM
  • Some odd caveats by jfengel (Score:2) Saturday March 26 2005, @01:50PM
  • smell like the LinuxPPC challenge by for_usenet (Score:2) Saturday March 26 2005, @01:51PM
  • Not a very smart move by pg110404 (Score:1) Saturday March 26 2005, @01:51PM
  • benign power by thundercatslair (Score:1) Saturday March 26 2005, @01:52PM
  • This is not as bad as it sounds... by Upaut (Score:1) Saturday March 26 2005, @01:52PM
  • Marketing scam? by bird603568 (Score:1) Saturday March 26 2005, @01:53PM
  • Microsoft should... by scotty777 (Score:1) Saturday March 26 2005, @01:53PM
  • I win. by sakusha (Score:2) Saturday March 26 2005, @01:54PM
    • Re:I win. by sakusha (Score:2) Saturday March 26 2005, @01:57PM
      • Re:I win. by k8to (Score:1) Saturday March 26 2005, @04:40PM
        • Re:I win. by sakusha (Score:2) Saturday March 26 2005, @04:48PM
          • Re:I win. by k8to (Score:1) Wednesday March 30 2005, @11:15AM
    • Re:I win. by Net_Wakker (Score:1) Saturday March 26 2005, @02:09PM
      • Re:I win. by sakusha (Score:2) Saturday March 26 2005, @02:13PM
  • Brilliant Marketing Regardless of the Outcome by BlueDjinn (Score:1) Saturday March 26 2005, @01:54PM
  • wait you have to go read the fine print by foszae (Score:1) Saturday March 26 2005, @01:54PM
  • DVForge / MacMice? Great... (Score:4, Interesting)

    by nuxx (10153) on Saturday March 26 2005, @01:55PM (#12055060)
    (http://nuxx.net/)
    Too bad this is being sponsored by a manufacturer of rather poor-quality products. For example, they make a product called the SightFlex [dvforge.com] which appears to be the ideal iSight [apple.com] stand. So, I bought one... The camera caused all sorts of problems on the FireWire bus, so I contacted Jack at MacMice. The long thread of emails ended in my not receiving a response to a request for a working product, although Jack did suggest opening up the SightFlex and wrapping aluminum foil around the wires in the base.

    So, I opened it up and here's what I found: http://www.nuxx.net/gallery/sightflex_troubleshoot ing [nuxx.net]

    Great, huh? Nicely random scattered, poorly soldered wires in the base, not all twisted up like they are supposed to be in a FireWire cable.

    I would have pursued the issue further, but the cheap plastic base of the device ended up breaking when I was moving it around one day. It seems that the flexible metal of the neck is just threaded into some fairly thin plastic in the base (again, see pictures [nuxx.net]) and the rather brittle plastic just up and broke one day.

    Great idea, piss poor execution.

    And, it is exactly becuase of this sort of product why I will never trust DVForge / MacMice again, no matter how noble the cause may be.

    After my experience, I'd think that they are offering $25,000 in monopoly money. Note that they never say US Dollars, so you can't fault them if they pay up in fake bills. ;)
  • Is this another... by SWTP_OS9 (Score:2) Saturday March 26 2005, @01:55PM
  • by alchemist68 (550641) on Saturday March 26 2005, @01:56PM (#12055070)
    AppleScript is a pretty powerful language. Someone might go about creating a MacOSX virus by writing it in AppleScript and disguising it as another program. For instance, the html-formatted email received in Mail would have the look and feel of Apple eNews and information letters with an attached Applescript. The AppleScript when activated pops up a window requesting the administrator password to do some check on the operating system, or to activate a security feature not turned on by default. The AppleScript then gathers all email addresses from Mail and AddressBook and sends itself to everyone in the databases, then the program does "rm -rf /*" as its final trick.

    While this is not a virus in the traditional sense, it could work in theory with some unsuspecting Mac users out there, like grandma or aunt Mae. And we all know that this couldn't happen to Slashdotters, not ever!
  • Stability by Deanasc (Score:2) Saturday March 26 2005, @01:56PM
  • +1$ Symbolic... by mirko (Score:1) Saturday March 26 2005, @01:57PM
  • Do they know the difference between virus and worm by micron (Score:1) Saturday March 26 2005, @01:57PM
  • Releasing self-replicating code on net is ILLEGAL by skeptictank (Score:1) Saturday March 26 2005, @01:58PM
  • by w3woody (44457) on Saturday March 26 2005, @01:58PM (#12055093)
    (http://www.alumni.caltech.edu/~woody)
    It had better be more than $50K for a Symantec Employee: according to my employment contract, writing a virus will result in my immediate termination. Such termination also means that I forfit all my stock options, worth far more than $50K at this point. And not to mention a great paying job with annual bonuses worth about half the original award.

    So from an economic standpoint I'd be seriously in the hole, trading in options and bonuses worth a hell of a lot more than the amount being offered from a rather shady source.

    No way!
  • I have one by Jozer99 (Score:2) Saturday March 26 2005, @02:01PM
  • Can anyone say class action? by PrvtBurrito (Score:2) Saturday March 26 2005, @02:01PM
    • 1 reply beneath your current threshold.
  • Root exploit _still_ not fixed (Score:4, Interesting)

    by McDutchie (151611) on Saturday March 26 2005, @02:02PM (#12055123)
    (http://www.interlingua.com/)

    So the summary claims that Mac OS X is technically more secure than Windows. Then why has this well-known root exploit in iSync [linuxsecurity.com] not been fixed even after several security updates and one system update, and despite that Apple has apparently been notified?

    That worries me -- this bug is trivial to exploit from any user account (just compile and run). It smells like Microsoft-esque security practices.

    FWIW, my temporary fix was to revoke the vulnerable file's setuid and execute permissions:

    $ chmod 644 /System/Library/SyncServices/SymbianConduit.bundle /Contents/Resources/
    mRouter

    (Note: omit any spurious spaces and linebreaks Slashdots inserts here.)

  • Creating a Market by Inst1gator (Score:1) Saturday March 26 2005, @02:03PM
  • by sgb235 (686043) on Saturday March 26 2005, @02:04PM (#12055133)
    Jack Campbell, who is behind this, has been behind a number of rather dubious projects. There's a page about him at Macintouch http://www.macintouch.com/mactable.html [macintouch.com].
  • Similar Challenge in 1997 by BinBoy (Score:2) Saturday March 26 2005, @02:04PM
  • Symantec and Macs by Anonymous Coward (Score:1) Saturday March 26 2005, @02:05PM
  • Fat Tony's Virus Protection Service by mshaslam (Score:2) Saturday March 26 2005, @02:05PM
  • Publicity stunt, folks, nothing to see here, by melted (Score:2) Saturday March 26 2005, @02:06PM
    • Illegal? by don.g (Score:2) Saturday March 26 2005, @03:41PM
  • Prediction by Frankie70 (Score:1) Saturday March 26 2005, @02:06PM
  • Why this contest means something by SuperKendall (Score:2) Saturday March 26 2005, @02:07PM
  • Biological Equivalent? by joe_janitor (Score:1) Saturday March 26 2005, @02:11PM
  • Wow, this is a real-world contest! by WarPresident (Score:2) Saturday March 26 2005, @02:12PM
  • Why don't Microsoft do this? (Score:3, Funny)

    by Xerp (768138) on Saturday March 26 2005, @02:19PM (#12055213)
    (Last Journal: Monday January 03 2005, @08:29PM)
    I mean, they are big on security, right? Perhaps they could offer $50k to someone who can write a virus that infects Microsoft Windows?
  • Criminal? by Cheirdal (Score:1) Saturday March 26 2005, @02:21PM
  • AV stuff is garbage now anyway... by alkaloids (Score:2) Saturday March 26 2005, @02:21PM
  • cancelled by rlds (Score:1) Saturday March 26 2005, @02:27PM
  • Cancelled (Score:3, Informative)

    by kryogen1x (838672) on Saturday March 26 2005, @02:27PM (#12055279)
    RTFA. It's cancelled.
  • 2 interesting themes here. by Fox_1 (Score:2) Saturday March 26 2005, @02:29PM
  • The challenge is to infect a naked machine. by irieken (Score:1) Saturday March 26 2005, @02:29PM
  • Contest Cancelled by FreemanPatrickHenry (Score:2) Saturday March 26 2005, @02:33PM
  • legal? by CatGrep (Score:2) Saturday March 26 2005, @02:33PM
  • Cancelled by ecotax (Score:1) Saturday March 26 2005, @02:33PM
    • Re:Cancelled by BlueDjinn (Score:1) Saturday March 26 2005, @02:45PM
    • 1 reply beneath your current threshold.
  • That's Just Dumb by Comatose51 (Score:2) Saturday March 26 2005, @02:38PM
  • What motivates virus writers? by zerofoo (Score:2) Saturday March 26 2005, @02:41PM
  • Internet Explorer for Macs? by matt me (Score:1) Saturday March 26 2005, @02:44PM
  • It's already cancelled by Anonymous Coward (Score:2) Saturday March 26 2005, @02:45PM
  • Contest Cancelled by stellertony (Score:1) Saturday March 26 2005, @02:54PM
  • It's canceled by Lord Duran (Score:1) Saturday March 26 2005, @03:02PM
  • Ive always wanted to see Norton in Aqua. by OSX1337 (Score:1) Saturday March 26 2005, @03:07PM
  • From TFA by InternationalCow (Score:2) Saturday March 26 2005, @03:08PM
  • Cancelled by SJS (Score:2) Saturday March 26 2005, @03:17PM
  • And this is why I use Mac OS X (Score:5, Informative)

    by boredman (169127) on Saturday March 26 2005, @03:20PM (#12055682)
    I get no end of amusement from people claiming that Mac users buy Macs because "they don't know anything about computers," or something to that effect. The fact of the matter is, this particular Mac user sees his computer for what it is: an appliance. It's not a platform, a political party, or a religion. It's a machine, not entirely unlike a toaster or Cuisinart.

    When choosing a computer, I took into consideration:
    1) What I need it to do.
    2) How I plan to interact with it.
    3) How much effort I need to put into maintaining it.
    3a) How much effort I need to put into making sure my machine stays mine (i.e. not compromised by some bored malcontent.)

    So, over the course of several decades, I test-drove a few different machines, running different OSs (disclosure: I ran DOS and Windows variants up to and including XP, various Linux distributions, and Mac OS X.) It became glaringly obvious that OS X was far and away the OS of choice for the amount of time and effort I intend to invest in using and maintaing my computer.

    I'm not a BSD advocate or a network security guru because, quite frankly, the subjects absolutely bore me to tears. However, even I can appreciate the simple, quiet wisdom of turning most networking services OFF on a fresh install of an OS (as does OS X.) Just think how much more secure our computing environment would be if people only enabled the services they absolutely needed.
  • HAHAHAHAH by GISGEOLOGYGEEK (Score:2) Saturday March 26 2005, @03:45PM
  • Those L33T Mac hackers by dantheman82 (Score:1) Saturday March 26 2005, @03:46PM
  • Very easy? by NitroWolf (Score:2) Saturday March 26 2005, @04:36PM
    • Re:Very easy? by Graymalkin (Score:2) Sunday March 27 2005, @01:58AM
  • Let's reverse it... by midifarm (Score:2) Saturday March 26 2005, @04:47PM
  • What an Ultramaroon!

    The problem with Symantec's FUD bombs isn't that it's impossible to infect a Mac, it's that Symantec's software doesn't patch exploits... it just catches known malware (well, except for spyware, that's apparently OK) after it's already got to you... hopefully before it has a chance to run.

    So the problem is... unless there's an actual virus out in the wild, there's nothing for Symantec's software to check for.

    And since it hooks into the OS, at a fairly deep level, any bugs or incompatibilities in their software are effectively new system bugs. So they can only make your computer less reliable and stable. It's not sensible to install AV software in the absence of viruses. It can't possibly help, it can only hurt.
  • Contest Update by gt_swagger (Score:1) Saturday March 26 2005, @04:59PM
  • named Switchback [lowendmac.com] which infected OSX Macs, but nobody noticed it.

    There are others such as Renepo.B [symantec.com]
    MacOS MW2004 Trojan [symantec.com], MP3 Concept [symantec.com], Opener [macintouch.com], and a sound driver virus [harmony-central.com].

    I think clearly the only virus myth about OSX, is the myth that OSX has no viruses that can infect it. Apparently there are at least several examples of OSX viruses, and that number seems to grow. It may even double every year.

    I've always felt that using a computer without virus protection was like having unprotected sex without a condom with multiple partners. Back in the old days, when they used to say that the Commodore Amiga had no viruses, and that only MS-DOS suffered from viruses, Amigas got their own viruses that infected their systems. Usually it was one of those Amiga demo programs that people downloaded from BBSes to show off the Amiga's graphics and sound. Someone would infect it with a virus and pass it around. Amiga users felt that the Amiga virus was a myth, and many got hit. Now I see the same thing happen for OSX, only OSX is on the Internet and is subject to more danagers than the BBS world once offered.

    So yes, the facts speak for Symantec, that OSX viruses exist, and possibly they could grow in number.

    This bone-headed stunt of offering a contest to virus infect two Macs only shows how gullable people are. It was a phoney contest.
  • Well at least... by Hachey (Score:1) Saturday March 26 2005, @05:49PM
  • Elderly Users by kd5ujz (Score:2) Saturday March 26 2005, @05:53PM
  • Cracking Contents Prove Nothing by christose (Score:1) Saturday March 26 2005, @07:04PM
  • Jack has been active lately ... (Score:4, Insightful)

    by adzoox (615327) * on Saturday March 26 2005, @07:06PM (#12057019)
    (Last Journal: Wednesday February 01 2006, @08:39AM)
    Wow, gone for a few minutes and you miss a lot.

    Jack has been active lately. He is notorious in the Mac Community.

    Everyone should read my article [jackwhispers.com] on his company and past in the Mac Community. It's called: Catch Me If You Can Part II: The True Story Behind MacMice

    Make sure to also see the about section [jackwhispers.com] to gain clarity on who writes Jackwhispers and why.
  • /. post ignores reality as usual (Score:3, Interesting)

    by geekee (591277) on Saturday March 26 2005, @07:14PM (#12057059)
    from post:
    "Symantec has been fanning the flames of totally bogus "Macs aren't more secure, it's just that Windows is a bigger target" technical-equivalence propaganda"

    Of course, in the article, the Symatec claim is actually backed up.
    from Symantec article:
    "In its seventh bi-annual Internet Security Threat Report, Symantec said over the past year, security researchers had discovered at least 37 serious vulnerabilities in the Mac OS X system."

    "Apple Computer has become a target for new attacks... The appearance of a rootkit109 called Opener in October 2004, serves to illustrate the growth in vulnerability research on the OS X platform..."

    "Symantec's concerns were echoed by James Turner, security analyst at Frost & Sullivan Australia, who said many of the people who bought Apple products were not concerned about security, which left them wide open to attack."

    "Look at where mobile viruses are going and they are not targeting Microsoft - they are targeting the market leader, which is Symbian,"
  • In spite of all that... by Ogman (Score:1) Saturday March 26 2005, @08:31PM
  • This was a lose-lose contest (Score:3, Interesting)

    by shodson (179450) on Saturday March 26 2005, @08:34PM (#12057456)
    (http://www.wiizy.com/)
    The fact that he shut it down ("chickened out") only gives credibility to the claim that "Windows is just a bigger target" crowd, which were not his intentions. If he kept the contest going, and the Macs had been infected, which probably would have happened eventually, then it would show that Macs are vulnerable too, which Mac software writers don't want, because Mac has benefited from the security lessons MSFT has learned the hard way and the perception, real or not, that Macs are more secure. Either way, it was a lose-lose for this guy and the Mac community.
  • Cancelled by sl4shd0rk (Score:1) Saturday March 26 2005, @08:49PM
  • Jackie was just looking for easy money... by Kildjean (Score:1) Saturday March 26 2005, @09:59PM
  • Hey Pandora... by KristoferP (Score:1) Sunday March 27 2005, @05:14AM
  • Had enough shooting to messenger? by Ilgaz (Score:2) Monday March 28 2005, @05:39AM
  • Jerks by dmacp (Score:1) Monday March 28 2005, @03:23PM
  • Darn by under_clocker (Score:1) Tuesday March 29 2005, @06:21AM
  • Re:Windows as secure as OSX? by aslate (Score:2) Saturday March 26 2005, @01:50PM
  • Re:Isn't this a crime? by anagama (Score:2) Saturday March 26 2005, @01:51PM
    • 1 reply beneath your current threshold.
  • I'm calling Bullshit (Score:4, Insightful)

    by John Seminal (698722) on Saturday March 26 2005, @01:53PM (#12055049)
    (Last Journal: Saturday February 21 2004, @08:07PM)
    I just got a new laptop that I had to install with XP for somebody. From behind a firewall, I installed SP2 and all patches. Just to test that it was secure , I plugged it into the net directly... bad idea. Less than 10 minutes and it was full of spyware

    I am calling bullshit on this obvious lie. You had a clean instal, behind a firewall, with all the service packs installed, and in just 10 minutes after that with a direct connection to the net, someone infected it with spyware? That has to be bullshit.

    I have been running Windows 2000 for years, and there is no spyware. And I am not doing anything special. I make sure to fdisk the mbr before an instal, just to make sure someone did not hide something on the hard drive before the instal. I do the instal off-line. Add a software firewall, then connect through a router to the net to get the service packs. I have never had any spyware on my system ever. I disable active-x from IE, and when I did my instal the only net protocol I install is tcp/ip, I do not instal the other 2- client or file & printer sharing.

    Come on, when will all this anti-windows BS stop? The only reason people can hack it is because users don't instal service packs and because they open links in emails that use active-x. I gaurentee if those two problems are resolved, it will become 99.9% harder to infect a machine- a hacker would not just be able to run software, he would have to know your system and activly fight to get in, which would be too much work for him.

    [ Parent ]
  • Re:Windows as secure as OSX? by Harassed (Score:1) Saturday March 26 2005, @01:55PM
  • Re:Windows as secure as OSX? by thecwin (Score:1) Saturday March 26 2005, @01:56PM
  • Re:Windows as secure as OSX? (Score:3, Informative)

    Now that's interesting.. I did a similar experiment a while back [slashdot.org]

    If you only read the headline, you might think I was agreeing with your position. However, my results were that the SP2 box went untouched for a couple weeks. And that none of the boxes that were infected had spyware, they had worms. It's also extremely rare that spyware gets on via any other mechanism besides web browsing.

    So, I'd be curious to see the data you have to back up your claim.
    [ Parent ]
  • Re:More Proof Symantec Writes Viruses by w3woody (Score:2) Saturday March 26 2005, @02:02PM
    • Re:More Proof Symantec Writes Viruses (Score:5, Informative)

      by w3woody (44457) on Saturday March 26 2005, @07:05PM (#12057006)
      (http://www.alumni.caltech.edu/~woody)
      *sigh*

      I don't know why I bother with the tin-foil hat brigade, but it is an explicit terminatable offense at Symantec to write--or help in writing--a virus. They just clean out your desk and have security escort you out of the building that day, no appeal. Your stock options and stock purchase plan options are immediately revoked, you lose back vacation pay, and you get no severence. Just a bootprint on your ass as you're kicked out the door.

      But of course I'm part of the conspiracy, so you'll probably think I'm either a dupe or a lying spokes-hole.

      I like being part of conspiracies; I worked many years ago for JPL in the same building the Weekly World News claimed housed an alien spacecraft that was being studied by the military--and the tinfoil hat brigade didn't believe me then when I told them it was just so much hokem...
      [ Parent ]
      • 1 reply beneath your current threshold.
    • 1 reply beneath your current threshold.
  • Re:Windows as secure as OSX? (Score:3, Informative)

    by plumby (179557) on Saturday March 26 2005, @02:04PM (#12055134)
    This kind of statement always puzzles me. I have two PCs permanently connected to the net, my wife has another, and so do both my parents and my sister in law (some of the most computer illiterate people that have actually managed to make it onto the net), and I've checked all of them for spyware on a reasonably regular basis over the past few years. The only one that's ever been infected with spyware (unless you are talking about things like cookies) was one of my PCs - and this was entirely my fault for installing some dodgy P2P software and not reading the Ts&Cs properly.

    What spyware were you infected with? How did you detect it?
    [ Parent ]
    • 1 reply beneath your current threshold.
  • Re:Windows as secure as OSX? by Avantare (Score:1) Saturday March 26 2005, @02:53PM
  • Re: Large Prize NO LONGER Offered - by Anonymous Coward (Score:1) Saturday March 26 2005, @03:58PM
  • 34 replies beneath your current threshold.
(1) | 2