The scalp of Mac OS X has been waved trophy-like after being hacked in controlled environments, yet security researchers are hard pressed remembering the last time a Mac was compromised in the wild.

Macs, according to most security experts and analysts, remain a safe computing option, however safe does not mean secure — its software, like software for PCs, is written by humans and contain flaws, which are technically exploitable.

But market share still provides some shelter to Mac users. Even though Apple's market share continues to grow quarter by quarter, the company's products account for just 5.8 percent of the total U.S. market for PCs, according to IDC.

"Market share equals money" to the hacker criminals of the world, according to Charlie Miller, a researcher at Independent Security Evaluators.

Miller made headlines last month by taking control of a MacBook Air as part of the CanSecWest conference's "Pwn to Own" contest. He used a previously unadvertised flaw in Apple's Safari browser to gain control of a system that was directed to a malicious Web site, earning himself and his team $10,000 and a new MacBook Air.

"Even if Apple moved to 10 percent market share, why spend the time on the 10 percent when you can just nail 90 percent with one bug?" Miller said. It's far easier, and far more lucrative, for hackers to spend their time going after the other 90-plus percent of computers in the world than it is to try to exploit flaws in the Mac.

Changing of the threat
Taking control of a computer through flaws in the operating system is a thing of the past, according to Mike Romo, product manager for Symantec's Mac product line. "Trojan horses and viruses are yesterday's news," he said. Today it's about using the browser as the entry point into the system or hacking Web sites.

At the CanSecWest conference, no one was able to take control of three laptops in play (the MacBook Air, a Fujitsu running Windows Vista Ultimate, and a Sony Vaio running Ubuntu) when attacks were confined just to the operating system. But Miller's Safari exploit, and the Flash flaw later exploited by Shane Macaulay, Derek Callaway, and Alexander Sotirov on the Vista laptop, show how security threats now focus on the browser, rather than the operating system.

Phishing and social engineering is the easiest path to someone's wallet versus trying to take over their system, Romo said. "The OS is not really the target anymore for these next generations of threats; it's taking advantage of the fact that people are spending more time online. People are much more comfortable with entering a credit card number than they ever have before," he said.

The debate about Windows versus Mac OS — at least in terms of security — is passé. More important today are the differences between Internet Explorer, Firefox, Safari and Opera. It's also about things like QuickTime, which Apple has patched extensively since the "Month of Apple Bugs" project last year.

Symantec distributed some research this week showing that 22 vulnerabilities were reported for Safari in 2007, compared with 88 in Mozilla browsers like Firefox, 18 in Internet Explorer, and 12 in Opera. It should be noted that counting the vulnerabilities is not the best way to measure the security of a piece of software, and can be explained in part by increased interest on the part of security researchers in investigating Firefox and Safari, as they become more widely used.

And, as the Symantec research highlights: "as security researchers have focused more efforts in discovering vulnerabilities in these browsers, the theory that this would result in much greater levels of malicious activity targeting these browsers in the wild has not yet been borne out."

Regardless how secure vendors make browsers, phishing scams like the Nigerian 419 e-mails, are almost impossible to track and protect against before people are affected. Social engineering is far more effective over time than trying to exploit a flaw in Vista or Mac OS X, Symantec's Romo said.

It is indeed a social problem, said Romo. People who are nervous around computers often just do whatever the computer tells them to do, Romo said. Apple's decision to ship a new of Safari to Windows users is a case in point — many people didn't realise that they didn't have to do what the computer was telling them to do.

Miller and Romo — both Mac users — worry that the need for greater security to protect people from themselves will force Apple to change the way the Mac handles certain tasks, potentially taking away some of the Mac's ease of use. Leopard already takes a step in this direction, Miller noted, though not nearly as far as the User Account Control feature introduced in Vista, to much derision. But Apple's not going to adopt Microsoft's security strategies for Mac OS X, until users demand it or hackers force its hand. They simply don't have to. Until then, quick, diligent patching and a wider embrace of the security community will more than do its part in keeping the Mac secure.

Education and "safe surfing" practices are as important to this era of security as anything having to do with counting flaws or patching practices. Maybe that's the third rail of technology writing: it's not always the mean evil corporation's fault; sometimes, it's yours.

Like this article? Click below to send it to your mobile for free!

Anti-Virus
13/10/2008 02:07 PM

It amazes me how people are so gullible in with infomation, even with weekly internet/credit card horror stories on all current affairs programs. No-one would tell a stranger their pin of their credit card, yet people are willing to type their full details into something that is stored online, so a number of strangers. I have no empathy for those who choose to give out their personal infomation to un-verified websites.

Report offensive content

  • Leave a comment

All fields marked with * are required

What do you think

Your e-mail will not be displayed

You must read and type the 6 chars within 0..9 and A..F

You must read and type the 6 chars.


  • XP to Vista: How to transfer your data

  • Microsoft to launch 'Windows Cloud' this month

  • 101 software tips, tweaks and tricks

  • Windows Mobile 7 delayed

  • HP considers own Linux-based OS

  • Sydney's Chatswood to get Apple store

  • Tweaking OS X

  • Advanced Mac keyboard shortcuts for power users

  • Apple Spaces: Separate work and play

More articles »

Find the right software

Brand
  • Multiple options can be selected

    • Microsoft Windows Vista SP1

      Microsoft Windows Vista SP1

      Microsoft pushes its first service pack for Vista out the door. Is it a salvation, a non-event or a flop?

    • Mac OS X 10.5 Leopard

      Mac OS X 10.5 Leopard

      The grace of Leopard's interface enhancements makes productivity more pleasurable with a Mac, as more than 300 functional and fun features top off this update.

    • Ubuntu 7.04

      Ubuntu 7.04

      Ubuntu is very user-friendly but not right for everyone. Oddly, both casual and advanced users will find this operating system wonderful, while day-to-day users may rail against Ubuntu's incompatibility with certain popular software applications.

    • Windows Mobile 6

      Windows Mobile 6

      Though it doesn't offer earth-shattering new features and interface issues remain, Windows Mobile 6 brings a collection of noteworthy improvements that makes its mobile devices easier to use and equips mobile professionals with more robust productivity tools.

    • Microsoft Vista Home Basic

      Microsoft Vista Home Basic

      If you're currently happy with Windows XP SP2, it is not worth rushing out to purchase Vista Home Basic. On the other hand, if you need a new computer right now, Windows Vista is stable enough for everyday use.

    More reviews »

    Membership benefits

    Create wishlists

    Create wishlists

    See a product on CNET.com.au that you want? Add it to your wishlist and send a hint to your friends and family. Sign up for a free CNET.com.au membership now!