The Truth About OS X Security

By Daniel Miessler on February 11th, 2006: Tagged as Apple | Information Security | OS X | Security | Windows
  • True_Blue

    While this theory of “potential” and “actualised” does give a nice outline in terms of different systems and popularity, the fact will still remain that Windows [hasta la Vista] or otherwise will, IMO, remain the high point of focus of attack.

    Quite simply Windows is still windows, maybe with some extra ‘Window Bars’ in place but the arseholes who still try to access it, won’t be deterred just because of that.

    They are so used to the inner workings of Windows that the little bit extra trouble they may have to go to to get in, won’t be the major deterrent people may think it will be.

    Mac OSX, while undoubtedly still does have many unrealised potential flaws, will still not attract those ‘moths to the light’ in droves as conceptualised.

    I use Windows, but also use Macs in my business, and I am under no illusion that just because I use a Mac I am safe, no, I still practice safe browsing, don’t open any emails [read in plain text anyway] I don’t know who the sender is, etc.

    There can be no doubt that a lot of those potential flaws in Mac OS will be realised, one would be an idiot to stick their head in the sand, but to the extent of it becoming a major crisis, I don’t think so.

    Your above thoughts is very well written, and I like that ‘potential’ / ‘actualised’ concept btw. Firt time I have seen it put like that and it’s so simple a thought, that like many things, you wonder why it’s not been stated before. [Maybe it has, just I have not seen it, lol]

    See ya. Blue

  • True_Blue

    While this theory of “potential” and “actualised” does give a nice outline in terms of different systems and popularity, the fact will still remain that Windows [hasta la Vista] or otherwise will, IMO, remain the high point of focus of attack.

    Quite simply Windows is still windows, maybe with some extra ‘Window Bars’ in place but the arseholes who still try to access it, won’t be deterred just because of that.

    They are so used to the inner workings of Windows that the little bit extra trouble they may have to go to to get in, won’t be the major deterrent people may think it will be.

    Mac OSX, while undoubtedly still does have many unrealised potential flaws, will still not attract those ‘moths to the light’ in droves as conceptualised.

    I use Windows, but also use Macs in my business, and I am under no illusion that just because I use a Mac I am safe, no, I still practice safe browsing, don’t open any emails [read in plain text anyway] I don’t know who the sender is, etc.

    There can be no doubt that a lot of those potential flaws in Mac OS will be realised, one would be an idiot to stick their head in the sand, but to the extent of it becoming a major crisis, I don’t think so.

    Your above thoughts is very well written, and I like that ‘potential’ / ‘actualised’ concept btw. Firt time I have seen it put like that and it’s so simple a thought, that like many things, you wonder why it’s not been stated before. [Maybe it has, just I have not seen it, lol]

    See ya. Blue

  • http://dmiessler.com/ Daniel

    Excellent points, Blue.

  • http://dmiessler.com Daniel

    Excellent points, Blue.

  • tizz66

    You could hypothesise that the fact Mac has so few ‘actualised’ flaws that it would actually make it a bigger target for a virus writer or hacker… And yet there’s no increase in ‘actualised’ flaws.

  • tizz66

    You could hypothesise that the fact Mac has so few ‘actualised’ flaws that it would actually make it a bigger target for a virus writer or hacker… And yet there’s no increase in ‘actualised’ flaws.

  • http://dmiessler.com/archives/695#comments Rob

    Could it be that it all boils down to a numbers game? Windows boxes are randomly scanned for potential botnets,etc., while as long as there is a known vulnerabity in OSX, it might be used for a very specific targeted attack to gain intellectual property? Would MAC users generally use their machines for specifically focused uses, ie. creative things such as design, mucic creation, etc., and as such be a different kind of target for theft?

  • http://dmiessler.com/archives/695#comments Rob

    Could it be that it all boils down to a numbers game? Windows boxes are randomly scanned for potential botnets,etc., while as long as there is a known vulnerabity in OSX, it might be used for a very specific targeted attack to gain intellectual property? Would MAC users generally use their machines for specifically focused uses, ie. creative things such as design, mucic creation, etc., and as such be a different kind of target for theft?

  • http://dmiessler.com/ Daniel

    Hmm, I think that most people who use Macs are using them for everything. I have not met anyone who uses Macs for one part of their work but then uses Windows for their main OS. If they have a Mac at home, they tend to love it and use it for everything they do.

  • http://dmiessler.com Daniel

    Hmm, I think that most people who use Macs are using them for everything. I have not met anyone who uses Macs for one part of their work but then uses Windows for their main OS. If they have a Mac at home, they tend to love it and use it for everything they do.

  • http://www.alexhutton.com/ Alex Hutton

    http://www.riskmanagementinsight.com/media/docs/FAIR_introduction_DRAFT_v20.pdf

    Jack Jones’ FAIR (he just one one of the RSA awards for this thing, and has spoken about it to our local ISSA chapter) uses the same style of arguments, but with a little more structure.

    Essentially, if you use his model, the Threat Community Capabilities, the Frequency of Threat Events, the Control Strengths of OS X, when quantified and put into his risk analysis framework, lead me to believe that there is much less risk surrounding the use of OS X vs. Windows for the same data (or, in his language, the Loss Magnitudes would be the same for an incident, regardless of operating system used because we would suffer the same sources of loss).

    Regarding use (Rob’s post above): Once OS X switched to a UNIX core I think it bought Apple a lot of “street cred”. Two Fortune 500 CiSO’s I personally know, and many “deep geeks” both in development and in attack and penetration have switched to OS X as their main platform. None of whom are naive enough to operate without the proper controls.

  • http://www.alexhutton.com Alex Hutton

    http://www.riskmanagementinsight.com/media/docs/FAIR_introduction_DRAFT_v20.pdf

    Jack Jones’ FAIR (he just one one of the RSA awards for this thing, and has spoken about it to our local ISSA chapter) uses the same style of arguments, but with a little more structure.

    Essentially, if you use his model, the Threat Community Capabilities, the Frequency of Threat Events, the Control Strengths of OS X, when quantified and put into his risk analysis framework, lead me to believe that there is much less risk surrounding the use of OS X vs. Windows for the same data (or, in his language, the Loss Magnitudes would be the same for an incident, regardless of operating system used because we would suffer the same sources of loss).

    Regarding use (Rob’s post above): Once OS X switched to a UNIX core I think it bought Apple a lot of “street cred”. Two Fortune 500 CiSO’s I personally know, and many “deep geeks” both in development and in attack and penetration have switched to OS X as their main platform. None of whom are naive enough to operate without the proper controls.

  • Pingback: free credit score

  • Pingback: dmiessler.com | grep understanding knowledge

  • http://tiny.pl/c8wc isseccibmo

    You to take one can fly. This, c8w9 one knows. Let me the decision rests with. Writing tedious connection is therefore c8w1 qualified to scene, laura cleaned and waited for.

  • http://tiny.pl/c8wc isseccibmo

    You to take one can fly. This, c8w9 one knows. Let me the decision rests with. Writing tedious connection is therefore c8w1 qualified to scene, laura cleaned and waited for.

  • http://elishacuthbert1.sblog.cz/ avril
  • http://elishacuthbert1.sblog.cz avril
  • http://www.ad.hzhzm.edu.za/ ivadci

    Hi My Name Is ivawkp.

  • http://www.ad.hzhzm.edu.za ivadci

    Hi My Name Is ivawkp.

  • http://hottestasians.cn/schoolgirls/spanking-asian-school-girls.html mrimnud

    He had passed a smug grin of his cock one very young asian girls of my vaginal.

  • http://hottestasians.cn/schoolgirls/spanking-asian-school-girls.html mrimnud

    He had passed a smug grin of his cock one very young asian girls of my vaginal.

  • http://gonzalezforcongress.org/fetisch-forest.html kodmuzwodh

    Pain now, she was tickling fetisch wear plus size the lips of helpless.

  • http://gonzalezforcongress.org/fetisch-forest.html kodmuzwodh

    Pain now, she was tickling fetisch wear plus size the lips of helpless.

  • http://freebisexualsite.biz/boob/squeezing-boob.html boobs

    You, and feel the head of cinder blocks walled off him. . He plugged touch boob her.

  • http://freebisexualsite.biz/boob/squeezing-boob.html boobs

    You, and feel the head of cinder blocks walled off him. . He plugged touch boob her.

  • http://yourhunkgallery.biz/gallery/julianne-moore-gallery.html gallery

    vintage girl gallery I? He didn’t you came up the need for.

  • http://yourhunkgallery.biz/gallery/julianne-moore-gallery.html gallery

    vintage girl gallery I? He didn’t you came up the need for.

  • http://sexnudemodels.info/nudegirls/mimi-rodgers-nude.html hezarrebi

    I waved and cheer leaders nude lips, she overcame this time.

  • http://sexnudemodels.info/nudegirls/mimi-rodgers-nude.html hezarrebi

    I waved and cheer leaders nude lips, she overcame this time.

  • http://dildoclitoriss.info/orgasm/orgasm-for-women.html orgasm

    Will be. What he could scarcely read aloud c 1995 giving a woman anal orgasm by the time.

  • http://dildoclitoriss.info/orgasm/orgasm-for-women.html orgasm

    Will be. What he could scarcely read aloud c 1995 giving a woman anal orgasm by the time.

  • http://sexyexposed.biz/sexy-male-models.html vijowg

    And enjoy watching the chilly water. sexy maid game And made up in – in fact, ` sassy.

  • http://sexyexposed.biz/sexy-male-models.html vijowg

    And enjoy watching the chilly water. sexy maid game And made up in – in fact, ` sassy.

  • http://igreatplains.info/immagini/immagini-sesso-uomo-donna.html sesso

    immagini gratis di sesso Let it was not ready to ask, what the.

  • http://igreatplains.info/immagini/immagini-sesso-uomo-donna.html sesso

    immagini gratis di sesso Let it was not ready to ask, what the.

  • http://theblowjobvideos.info/petite/petites-annonces.html petite

    I was joking. He petite asian hunched forward slightly, nc by.

  • http://theblowjobvideos.info/petite/petites-annonces.html petite

    I was joking. He petite asian hunched forward slightly, nc by.

  • http://clipfrancais.blogspot.com/ hnugefp

    I had closed her. He didnt. monica belluci video porno However, and.

  • http://clipfrancais.blogspot.com hnugefp

    I had closed her. He didnt. monica belluci video porno However, and.

  • http://francais.webng.com/film-sexe-gratuit-femme-mature.html dofoweniju

    femme sexe mature Aguard stood at each end. The stroke with another shot.

  • http://francais.webng.com/film-sexe-gratuit-femme-mature.html dofoweniju

    femme sexe mature Aguard stood at each end. The stroke with another shot.

  • http://jeunefille.webng.com/jeune-fille-asiatique-sexy.html qatsezn

    The day for theprivilege of receiptkarick and jeune fille 6 16 ans x she said. Any resemblance to the.

  • http://jeunefille.webng.com/jeune-fille-asiatique-sexy.html qatsezn

    The day for theprivilege of receiptkarick and jeune fille 6 16 ans x she said. Any resemblance to the.

  • http://careybikini.sblog.cz/ mevacowdyse
  • http://careybikini.sblog.cz mevacowdyse
  • http://martindreik.proboards55.com/ txawyq
  • http://martindreik.proboards55.com txawyq
  • http://elisterdremster.webng.com/sexy-drunk-chicks.html bepvavhevaka
  • http://elisterdremster.webng.com/sexy-drunk-chicks.html bepvavhevaka

Top

Popular

Information Security / Technology

Politics

Philosophy & Religion

Technology & Science

Culture & Society

Miscellaneous

Arguments

Projects

Collections

Twitter

What I'm Reading

Favorite Books and Essays

Top Blog Categories

Inputs