Showing posts with label Mac OS X. Show all posts
Showing posts with label Mac OS X. Show all posts

Saturday, February 7, 2009

The UAC Debacle

As I’m sure you’re all aware (if you’ve been following the very popular Windows 7 beta) there has been some issues with how Microsoft is handling UAC (user access control) in Windows 7.  Initially they wanted to lower the default alert threshold so users wouldn’t be bothered when changing settings for Windows since it was a major complaint with the way Vista operated with UAC.  Then in an outcry from the security-conscious testers/observers Microsoft bends to their demands for it to be more like Vista (more secure but more alerts) considering malware on the system could lower or disable UAC and not prompt the user—leaving the system open to run anything without the users consent.

It just seems that Microsoft can’t please everyone and the user base can’t agree what they collectively want from the vendor.  Personally I feel that Windows should be as secure as possible and the user needs to adapt to the world in which we live where security is a survival trait—we can’t remain to be lazy and naive about real threats that exist and no Mac OS X isn’t the solution.  Apple handles their version of UAC the same way (high alerts) and they have already proven that they aren’t immune to attack.

Thursday, January 22, 2009

Trojan on Mac OS X - Massive Infections

I read this one over at macworld.com. Evidently some less than noble individuals placed a pirated copy of the new iWork 09 online, which was downloaded over 20,000 times. This turned out to be a Trojan horse that asked for the users' password and proceeded to install itself. This has been confirmed as an in the wild threat but fortunately the infection does not spread.

Security through obscurity is a phrase that has been used for years to describe the Mac platform in general and I tend to agree. The real question is how Apple will respond to threats such as these considering as their platform grows in popularity they will start to face the same problems that are affecting Windows users. The difference is Microsoft has had decades of addressing these problems and hardening Windows from a multitude of attack vectors, while Apple has seemingly skated by (getting back to that obscurity thing). I won't bash Mac users on this one, but a sense of humility would be nice in regards to security at the very least and in this area they could learn a lot from Microsoft.

Source