Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Readers contend Mac's OS X is much tougher to crack than Windows
Sunspot.net ^ | 8/28/2003 | David Zeiler

Posted on 08/28/2003 8:07:20 AM PDT by Vermonter

Writing a column containing debatable comments from security experts is nearly as good at filling up your e-mail inbox as the SoBig virus.

Last week, I concluded that Apple Computer Inc.'s Macintosh OS X provided safer computing than Microsoft Corp.'s Windows operating systems -- in part because its small market share offers Internet villains too little opportunity to spread mayhem and partly because OS X ships with all of its vulnerable services turned off. This blocks potential attackers from gaining access to the system's software in the first place.

(Excerpt) Read more at sunspot.net ...


TOPICS: Miscellaneous; Technical
KEYWORDS: apple; computers; mac; macuser; macuserlist; osx; pc; unix; viruses; windows
I really don't mean for this to be a Mac versus PC thread, but this is the best description I've seen to date on why the Mac is less vulnerable to virus/worm attacks.
1 posted on 08/28/2003 8:07:21 AM PDT by Vermonter
[ Post Reply | Private Reply | View Replies]

To: *Macuser_list
ping
2 posted on 08/28/2003 8:07:46 AM PDT by Vermonter
[ Post Reply | Private Reply | To 1 | View Replies]

Comment #3 Removed by Moderator

To: Behind the Lines in CA
open-a-lot-of-ports-by-default

No, some distros suffer from open ports by default, during setup you can enable/disable ports, and on some distro's outside access of xinetd or other services is restricted..

4 posted on 08/28/2003 8:33:10 AM PDT by N3WBI3
[ Post Reply | Private Reply | To 3 | View Replies]

Comment #5 Removed by Moderator

To: Behind the Lines in CA
Linux suffers (suffered?) a bit from open-a-lot-of-ports-by-default syndrome

Red Hat was notorious for this. However, I installed RH 9 recently (easiest install I've ever done on any computer), and the install wizard let you chose what level of security to use, with pre-defined settings plus the option to change setting on individual services. So now, if the port is open, it's because the person doing the installation opened it.

6 posted on 08/28/2003 8:37:49 AM PDT by kevkrom (This tag line for rent)
[ Post Reply | Private Reply | To 3 | View Replies]

Comment #7 Removed by Moderator

To: Behind the Lines in CA

Not to bash Windows, but my wife and I have been operating off OS X since April of this year. Superb platform. Very few stability problems. I have Virex, of course. I will probalby invest in a mac based firewall soon enough.

No "outlook express" for me!

Be Seeing You,

Chris

8 posted on 08/28/2003 8:51:56 AM PDT by section9 (To read my blog, click on the Major!)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Behind the Lines in CA
I dont understand why all it is is a selection?
9 posted on 08/28/2003 9:06:20 AM PDT by N3WBI3
[ Post Reply | Private Reply | To 5 | View Replies]

To: Behind the Lines in CA
Regardless of all else, the simple logic of numbers makes the decision to attack Microsoft a no brainer.
10 posted on 08/28/2003 9:12:02 AM PDT by Tumbleweed_Connection
[ Post Reply | Private Reply | To 7 | View Replies]

To: section9
Regarding firewalls, I use OS X myself, and my firewall is a LinkSys BEFSR81 Etherfast cable/DSL router. I highly recommend their products. Mine is about three years old now, works like a tank. You forget you have it after a while, it just works and doesn't cause a fuss. Try one, you'll like it.
11 posted on 08/28/2003 9:14:05 AM PDT by Elliott Jackalope (OS X is my OS. That's why I like computers again.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Behind the Lines in CA
True... the real point is that no OS should install with services on by default. It should up to the box admin (whether that's just the home user or a multi-national company's IT guy) to explicitly open those things deemed necessary.

It's not like the guys in Redmond are dumb. It's just that the primary design concept of Windows has always been driven by a "desktop" view of the world. Networking and security are "add-on" concepts to that design framework, and they don't always fit well.

The Unix-like systems also have history on their side. They've had a 10-15 year head start on Microsoft on network security issues, and have learned not only how to prevent most problems, but to mitigate the damage from the ones that get through (e.g., no service should be running as "root" -- that way exploits are limited as to the type of damage they can do to the rest of the system). As a specific example, PHP-Nuke has some holes that have allowed websites to be defaced; it's not a Linux or Apache bug, but rather a user program (PHP-Nuke) -- the security settings prevent the PHP-Nuke exploit from doing anything else to Apache or to the OS as a whole.

12 posted on 08/28/2003 9:16:34 AM PDT by kevkrom (This tag line for rent)
[ Post Reply | Private Reply | To 7 | View Replies]

Comment #13 Removed by Moderator

To: Elliott Gigantalope

Thanks. I'll follow up on that.

Be Seeing You,

Chris

14 posted on 08/28/2003 10:19:02 AM PDT by section9 (To read my blog, click on the Major!)
[ Post Reply | Private Reply | To 11 | View Replies]

To: section9
Mac OS X has a built-in firewall that is probably adequate for your use. In the System Preferences, click on "Sharing", select the "Firewall" tab and click the "Start" button.

For advanced users, Mac OS X also has a built-in packet sniffer that will let you look at Internet traffic. Assuming you are using a broadband connection plugged into the Mac's Ethernet port, you can try this -

Start the Terminal program in Applications/Utilities/

Enter this command -

sudo tcpdump -i en0 -X

Then enter your password. You will then see the contents of each IP packet displayed in the terminal. You can start a web browser to generate some traffic if needed.

To end the tcpdump program, enter control-C on the keyboard.

15 posted on 08/28/2003 12:55:26 PM PDT by HAL9000
[ Post Reply | Private Reply | To 8 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson