Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Reduce OS X security threats - ignore security software
ZDNet UK ^ | May 05, 2006, 16:20 BST

Posted on 05/05/2006 10:57:49 PM PDT by Swordmaker

McAfee wants you to buy into its picture of Macintosh security. We prefer an alternate reality

We were intrigued to receive a press release from McAfee today, warning us of vulnerabilities in Apple's Mac OS X operating system. Not only were these vulnerabilities growing at an alarming rate, said the release, but "as more companies deploy Mac systems running on the Intel platform in mixed environments, the risk of infection will most likely increase." Fortunately for all of us, a second release had the answer: "McAfee today announced antivirus support for Intel-based Apple computers. "

Phew. At last, the world is safe from the thousands of Intel-specific Mac viruses, worms, trojans and other malware that make today's OS X experience one long struggle against evil. Or it would be, were there any. Which there aren't. Not one.

It may be true, as McAfee says, that from 2003 to 2005 the number of discovered Mac vulnerabilities increased by 228 percent while Windows only saw a 73 percent increase. But that's like saying that in the last decade, deaths caused by choking on ice cream were up by 200 percent while deaths from smoking only went up by ten. Like the ice cream, shining light on McAfee's claims makes them melt away – when we asked the company how big the risks actually were, it admitted that there was "no significant risk" at the moment. But there might be in the future. People on Macs are complacent. Better safe than sorry.

Safety in this context means having a sober assessment of the risks and how to safely and effectively counter them. For as long as OS X has been in the wild, discovered weaknesses and example code have been used by interested parties to predict actual attacks. Nothing remotely serious has materialised. In fact, if you look down the CERT list of alerts for 2005, the only one that mentions an Apple product by name is one caused by a bug in Symantec's AntiVirus software for the Mac. Safe, effective risk management here involves taking the longest bargepole you can find and using it to not touch the snake oil.

McAfee should be ashamed of itself, for raising fears of risks that do not exist, for coupling risks to Intel chips by association – which borders on the libelous – and for encouraging the very complacency it claims to cure. This push to sell inappropriate solutions will damage security and hinder the fight against malware. It will introduce more complexity at the system's most vulnerable point, and discourage people from thinking about stuff like firewall configuration and proper privilege-based security. If you understand security, you will not buy this software.

OS X, like any complex computer system, is not invulnerable to attack. Educating users about modes of attack, keeping up to date with patches, watching for independent analysis of problems – all these are good ways to keep your guard up. Listening to someone crying wolf is not.


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: apple; computers; macintosh; osxsecurity

1 posted on 05/05/2006 10:57:53 PM PDT by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: 1234; 6SJ7; Action-America; af_vet_rr; afnamvet; Alexander Rubin; anonymous_user; ...
More Anti-FUD on the true threat levels to Mac OS X... PING!

Some more people are recognizing the FUD blizzard against Macs when they see it...

If you want on or off the Mac Ping List, Freepmail me.

2 posted on 05/05/2006 10:59:57 PM PDT by Swordmaker (Beware of Geeks bearing GIFs.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

McAfee's antivirus software for PowerPC's was formerly bundled with the .mac service. It was dropped. Anyone know why?



3 posted on 05/06/2006 3:50:13 AM PDT by spower
[ Post Reply | Private Reply | To 2 | View Replies]

To: Swordmaker
McAfee should be ashamed of itself, for raising fears of risks that do not exist

Talking dumb people out of money is not a crime is it ? I thought it was the basic principle of business. I mean how else do you explain the bottled water companies ......
4 posted on 05/06/2006 6:57:58 AM PDT by festus (The constitution may be flawed but its a whole lot better than what we have now.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: spower
When Apple went to OSX 10.4, the virus checker conflicted with the OS. I don't know the internals, but the checker never quit running, and would use up to 70% of the CPU time. I used it for several years, and the only thing it ever spotted were PC viruses.

.Mac offered it with Panther for a while, and recommended not running it with Tiger, then quit offering it alltogether.

5 posted on 05/06/2006 7:32:32 AM PDT by Richard Kimball (I like to make everyone's day a little more surreal)
[ Post Reply | Private Reply | To 3 | View Replies]

To: spower

YEp - the word is that between the lack of any real threat, some minor bugs in the McAfee software, and continued price increases on the Part of McAfee convinced Apple to drop the software.

What's really funny - McAfee only offers it's antivirus software (Virex) in minimum units of 5 licenses - at $200.


6 posted on 05/06/2006 1:07:21 PM PDT by TheBattman (Islam (and liberalism)- the cult of Satan and a Cancer on Society)
[ Post Reply | Private Reply | To 3 | View Replies]

Comment #7 Removed by Moderator

To: Swordmaker

What is FUD?


8 posted on 05/07/2006 5:18:36 PM PDT by Woahhs (America is an idea, not an address.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Woahhs
What is FUD?

The New Oxford Dictionary built into Mac OS X.4, says it is:


FUD |fuhd| - noun - fear, uncertainty and doubt, usually evoked intentionally in order to put a competitor at a disadvantage : [as adj. ] the FUD factor.

ORIGIN: acronym.


Dictionary.com goes a little farther and provides information on who coined the acronym:


FUD /fuhd/ n. Defined by Gene Amdahl after he left IBM to found his own company: "FUD is the fear, uncertainty, and doubt that IBM sales people instill in the minds of potential customers who might be considering [Amdahl] products." The idea, of course, was to persuade them to go with safe IBM gear rather than with competitors' equipment. This implicit coercion was traditionally accomplished by promising that Good Things would happen to people who stuck with IBM, but Dark Shadows loomed over the future of competitors' equipment or software. See IBM. After 1990 the term FUD was associated increasingly frequently with Microsoft, and has become generalized to refer to any kind of disinformation used as a competitive weapon.



9 posted on 05/07/2006 10:26:31 PM PDT by Swordmaker (Beware of Geeks bearing GIFs.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Swordmaker
The main reason there are no Mac viruses to speak of is that malicious programmers worry that if they ever actually made contact they might catch a Mac.
10 posted on 05/07/2006 10:32:53 PM PDT by BJungNan
[ Post Reply | Private Reply | To 1 | View Replies]

To: BJungNan
Now that's original!
11 posted on 05/08/2006 12:05:50 AM PDT by Swordmaker (Beware of Geeks bearing GIFs.)
[ Post Reply | Private Reply | To 10 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson