PCWorld Forums

PCWorld Forums: Flashback Still Plagues Macs - PCWorld Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Flashback Still Plagues Macs

#1 User is offline   PCWorld 

  • Advanced Member
  • PipPipPipPipPipPipPipPip
  • Group: PCWorld BOT
  • Posts: 103,894
  • Joined: 01-August 07

Posted 22 April 2012 - 04:26 AM

Post your comments for Flashback Still Plagues Macs here
0

#2 User is offline   jbelkin 

  • Full Member
  • PipPipPip
  • Group: Members
  • Posts: 75
  • Joined: 30-December 06

  Posted 22 April 2012 - 10:20 AM

Has anyone independently verified any of these numbers other than a PRESS RELEASE from comapnies selling security services. So far, the actual number of people who have seen this virus/malware - ZERO. Press releases - 20. actual macs infected - zero?
0

#3 User is offline   imaginarynumber 

  • Member
  • PipPip
  • Group: Members
  • Posts: 35
  • Joined: 12-June 09

Posted 22 April 2012 - 11:14 AM

View Postjbelkin, on 22 April 2012 - 10:20 AM, said:

Has anyone independently verified any of these numbers other than a PRESS RELEASE from comapnies selling security services. So far, the actual number of people who have seen this virus/malware - ZERO. Press releases - 20. actual macs infected - zero?


So who would you believe?

Surely Apple attempting to provide a "fix", albeit it in a rather tardy manner, implies that there is an issue?
0

#4 User is offline   deepsand 

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 2,558
  • Joined: 28-August 06

Posted 22 April 2012 - 12:55 PM

View Postjbelkin, on 22 April 2012 - 10:20 AM, said:

Has anyone independently verified any of these numbers other than a PRESS RELEASE from comapnies selling security services. So far, the actual number of people who have seen this virus/malware - ZERO. Press releases - 20. actual macs infected - zero?

Proof, please.
While each is entitled to his own opinion, no one is entitled to his own facts.
0

#5 User is offline   nonseq 

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 4,470
  • Joined: 09-August 09
  • Location:Phoenix, AZ

Posted 22 April 2012 - 01:02 PM

View Postimaginarynumber, on 22 April 2012 - 11:14 AM, said:

View Postjbelkin, on 22 April 2012 - 10:20 AM, said:

Has anyone independently verified any of these numbers other than a PRESS RELEASE from comapnies selling security services. So far, the actual number of people who have seen this virus/malware - ZERO. Press releases - 20. actual macs infected - zero?


So who would you believe?

Surely Apple attempting to provide a "fix", albeit it in a rather tardy manner, implies that there is an issue?


Is Apple really "tardy?" How long did it take Oracle to provide a fix to Java?
0

#6 User is offline   RickDobbelmannqbtt 

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 291
  • Joined: 02-June 11

Posted 22 April 2012 - 01:21 PM

OPEN SOURCE > CLOSED SOURCE

Issue would be a non-issue if Apple would open their source. That is unless they do not want to expose all of their other holes they have not discouvered or have no idea how to fix.

After all what is OSX? OSX is a set of CLOSED SOURCE apps a gui stacked on top of a 100% free operating system called Darwin.

Darwin is an open source POSIX-compliant computer operating system released by Apple Inc. in 2000

Darwin forms the core set of components upon which Mac OS X and iOS are based and is licensed as public source

Where ALL developers come in to security problems is when they close their source on their own code. Which in a business model makes sense but as a security model doesn't. Flashback is the direct result of the closed source apps stacked on top of darwin.

Security through obscurity doesn't work.

I agree with most of you OSX is far superior to Windows with security. But OSX also relies on security through Security through obscurity for its set of apps and gui and other parts of the stack.

This post has been edited by RickDobbelmannqbtt: 22 April 2012 - 01:42 PM

0

#7 User is offline   deepsand 

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 2,558
  • Joined: 28-August 06

Posted 22 April 2012 - 02:18 PM

View PostRickDobbelmannqbtt, on 22 April 2012 - 01:21 PM, said:

Issue would be a non-issue if Apple would open their source.

Dream on. Linux had a vulnerability go undetected for 8 years. The only reason that no harm ensued is because the installed base is too small to be worth the effort to attack.

Open source aficionados are neither omniscient, omnipresent, nor omnipotent.

Why do you open source zealots always have to take discussions of a specific issue off-topic

This post has been edited by deepsand: 22 April 2012 - 02:20 PM

While each is entitled to his own opinion, no one is entitled to his own facts.
0

#8 User is offline   nonseq 

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 4,470
  • Joined: 09-August 09
  • Location:Phoenix, AZ

Posted 22 April 2012 - 02:37 PM

View Postdeepsand, on 22 April 2012 - 02:18 PM, said:

View PostRickDobbelmannqbtt, on 22 April 2012 - 01:21 PM, said:

Issue would be a non-issue if Apple would open their source.

Dream on. Linux had a vulnerability go undetected for 8 years. The only reason that no harm ensued is because the installed base is too small to be worth the effort to attack.

Open source aficionados are neither omniscient, omnipresent, nor omnipotent.

Why do you open source zealots always have to take discussions of a specific issue off-topic


And this is one claim made over and over again that has never been substantiated. Do we have to take the claimant's word? What, if any are his/her credentials beyond arrogance and pontification?

Rick, from here on in, don't just make claims about Open Source. Prove them. And not with empty jingoism and rantings of a zealot.

This post has been edited by nonseq: 22 April 2012 - 02:50 PM

0

#9 User is offline   imaginarynumber 

  • Member
  • PipPip
  • Group: Members
  • Posts: 35
  • Joined: 12-June 09

Posted 22 April 2012 - 02:59 PM

View Postnonseq, on 22 April 2012 - 01:02 PM, said:

View Postimaginarynumber, on 22 April 2012 - 11:14 AM, said:

View Postjbelkin, on 22 April 2012 - 10:20 AM, said:

Has anyone independently verified any of these numbers other than a PRESS RELEASE from comapnies selling security services. So far, the actual number of people who have seen this virus/malware - ZERO. Press releases - 20. actual macs infected - zero?


So who would you believe?

Surely Apple attempting to provide a "fix", albeit it in a rather tardy manner, implies that there is an issue?


Is Apple really "tardy?" How long did it take Oracle to provide a fix to Java?


Granted a "potential vulnerability" was reported to Oracle in July 2011. Oracle released a fix for it and 13 other flaws in mid February, Apple waited another 2 months before releasing their "fix". That strikes me as being tardy.

Even if Oracle had provided the fix quicker it is likely that Mac owners would still have been infected in the same numbers. The suggestion is that malware writers reverse engineer windows fixes safe in the knowledge that Apple will be slow to provide their own patches.
0

#10 User is offline   nonseq 

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 4,470
  • Joined: 09-August 09
  • Location:Phoenix, AZ

Posted 22 April 2012 - 03:18 PM

View Postimaginarynumber, on 22 April 2012 - 02:59 PM, said:

View Postnonseq, on 22 April 2012 - 01:02 PM, said:

View Postimaginarynumber, on 22 April 2012 - 11:14 AM, said:

View Postjbelkin, on 22 April 2012 - 10:20 AM, said:

Has anyone independently verified any of these numbers other than a PRESS RELEASE from comapnies selling security services. So far, the actual number of people who have seen this virus/malware - ZERO. Press releases - 20. actual macs infected - zero?


So who would you believe?

Surely Apple attempting to provide a "fix", albeit it in a rather tardy manner, implies that there is an issue?


Is Apple really "tardy?" How long did it take Oracle to provide a fix to Java?


Granted a "potential vulnerability" was reported to Oracle in July 2011. Oracle released a fix for it and 13 other flaws in mid February, Apple waited another 2 months before releasing their "fix". That strikes me as being tardy.

Even if Oracle had provided the fix quicker it is likely that Mac owners would still have been infected in the same numbers. The suggestion is that malware writers reverse engineer windows fixes safe in the knowledge that Apple will be slow to provide their own patches.


Had Oracle released earlier would Apple have taken as long to do their work? Probably. With a few exceptions, Apple has not rushed out fixes that may or may not have been complete or secure. At least that's my take. So, Oracle took 6 months to address the issue and barely an eyebrow is lifted. Apple, which is not responsible for Java, implemented their fix deliberately.

I have serious questions about the accuracy and veracity of Dr. Web's findings. It seems to be a play to gain public attention as well as acknowledgement from Apple. I think that given more scrutiny Kapersky Labs is far more accurate in their evaluation. But I'm not an expert so your or anyone else's opinion is just as valid as my own.

Again, I don't think that Apple is slow as much as deliberate. But that's just me.
0

#11 User is offline   kbconsulting 

  • Newbie
  • Pip
  • Group: New Member
  • Posts: 6
  • Joined: 03-October 11

Posted 22 April 2012 - 03:32 PM

[/quote]

So who would you believe?

Surely Apple attempting to provide a "fix", albeit it in a rather tardy manner, implies that there is an issue?
[/quote]

I don't think any of this is real, I have talked to about 100 Mac users and not a single one has it, but many have put on security software that is useless as they read about threats. And if they can "sinkhole" the servers they could simply issue comp ands for the "infected" machines to self remove it, but that would not make them any money or provide the fear that they feed off.
0

#12 User is offline   deepsand 

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 2,558
  • Joined: 28-August 06

Posted 22 April 2012 - 03:49 PM

View Postkbconsulting, on 22 April 2012 - 03:32 PM, said:

Quote

So who would you believe?

Surely Apple attempting to provide a "fix", albeit it in a rather tardy manner, implies that there is an issue?


I don't think any of this is real, I have talked to about 100 Mac users and not a single one has it, but many have put on security software that is useless as they read about threats.

As for the 100 users cited, how many of them have the specific Java app/version in question installed on a vulnerable OS? Of those that meet both necessary conditions, how many of them scanned their machines for said malware?

And, how would they know that the security software they installed is useless?

View Postkbconsulting, on 22 April 2012 - 03:32 PM, said:

And if they can "sinkhole" the servers they could simply issue comp ands for the "infected" machines to self remove it, but that would not make them any money or provide the fear that they feed off.

Why on earth would the creator of a piece of malware include in it its own uninstaller?

Sounds like another who believes that there is a conspiracy amongst the providers of security information and products to deliberately create a need and demand for their services. :rolleyes:

This post has been edited by deepsand: 22 April 2012 - 03:50 PM

While each is entitled to his own opinion, no one is entitled to his own facts.
0

#13 User is offline   zeth006 

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 408
  • Joined: 21-March 08

Posted 22 April 2012 - 04:21 PM

View Postkbconsulting, on 22 April 2012 - 03:32 PM, said:

I don't think any of this is real, I have talked to about 100 Mac users and not a single one has it, but many have put on security software that is useless as they read about threats. And if they can "sinkhole" the servers they could simply issue comp ands for the "infected" machines to self remove it, but that would not make them any money or provide the fear that they feed off.



So you actually went out and interviewed all 100 of them and verified what security software they were running?


What if I told you I interviewed 1,000 Mac owners who all reportedly were hit by Flashback? Should everyone believe me? :lol:
0

#14 User is offline   deepsand 

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 2,558
  • Joined: 28-August 06

Posted 22 April 2012 - 04:25 PM

Your 1000 beats kbconsulting's 100.

You win. :D
While each is entitled to his own opinion, no one is entitled to his own facts.
0

#15 User is offline   imaginarynumber 

  • Member
  • PipPip
  • Group: Members
  • Posts: 35
  • Joined: 12-June 09

Posted 23 April 2012 - 07:30 AM

View Postkbconsulting, on 22 April 2012 - 03:32 PM, said:


I don't think any of this is real, I have talked to about 100 Mac users and not a single one has it, but many have put on security software that is useless as they read about threats. And if they can "sinkhole" the servers they could simply issue comp ands for the "infected" machines to self remove it, but that would not make them any money or provide the fear that they feed off.


I should imagine that any white hat attempts to send commands would be illegal.

when you refer to the panic installing of AV software are you suggesting that it is useless because Macs can't be infected?

I understand your cynicism regarding AV firms reporting exploits but the reports are being confirmed by respected and established firms, firms who understand the risks of crying wolf.
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users