News
CONTINUED:
Macs are not invincible
The most serious incident was perhaps the public disclosure of a serious and easily exploitable flaw in the Apple operating system, which could be a conduit for intruders to install malicious code on computers running the software. Attack code that takes advantage of the security hole was quickly posted on the Internet.
The problem lies in the way Mac OS X associates files with applications, and it could be exploited to hit a Mac via the Safari Web browser or Apple Mail, experts said. Apple has said it is working on a fix for the flaw. So far, no attacks based on the bug have been spotted on the Web.
Overall, only a few currently known worms, viruses and Trojans target the Mac, McAfee's Schmugar said. Nevertheless, people should not ignore the danger. "There does not have to be more then 150,000 threats for Macs before it's a security concern," he said, referring to the number of known Windows pests.
A machine running Apple's operating system might actually be easier to hit than a Windows PC, Schmugar said. "There are fewer and less evolved defences around a Mac, because there have been fewer threats against it," he said. "The success rate for getting malicious code to run is probably greater."
The Mac maker is taking measures to sew up the latest hole in its operating system. "Apple takes security very seriously," a company representative said. "We're working on a fix so that this doesn't become something that could affect customers." The representative could not say when the patch would be ready.
Long recommends two tweaks to the OS X settings to make it more secure -- enabling the firewall, and disabling the "Open safe files after downloading" option in the Safari preferences. That last option, if not locked up, could be exploited to trick people into downloading malicious code onto their Mac, he said.
All in all, this is not significant enough to dent user confidence in Mac OS X as a secure operating system, said Ray Wagner, an analyst at Gartner. "Given that the most recent vulnerability does not spawn an attack before being patched -- an unknown -- there is not enough impact on the average user to cause a significant change in behaviour," he said.
Apple is advising its customers to consult its online safety guide, and to be cautious when surfing the Web. "Apple always advises Mac users to only accept files from vendors and Web sites that they know and trust," the company representative said.
Asked if the Mac, compared with Windows, is still the obvious safer choice for people on the Internet, Gartner's Wagner simply replied, "Yes."
More about Software
- Obama in sex video shocker? Oh wait, it's just spam September 11, 2008
- No black holes from Large Hadron Collider, say scientists September 10, 2008
- Michael Moore to premiere film online September 05, 2008
- Images: Touring Google's Chrome browser September 05, 2008
- Extensions promised for Chrome September 04, 2008

- OpenOfficeMouse has frankly preposterous 18 buttons, joystick
- EMI Abbey Road Live: Instant gig recording
- Sony BDP-S760 Blu-ray player: Super bit-mapping reality enhancer
- Nokia Booklet 3G hits US: Hands-on verdict
- Lady GaGa Monster Heartbeats: They're plastic but they still have fun
- The 6 worst video game samples in rap music

- Google Voice heading for Europe?
- Twitter retweets rolled out to beta tweeters
- Beatles on a stick: Crave alternative headline competition results!
- Ordnance Survey and GeoVation map the future with mashup competition
- What does Google Suggest suggest about the state of humanity?
- The 10 dumbest Firefox add-ons ever
- Best iPhone Apps of 2009: CNET UK's Home Screen Awards
- MSN Music relaunches with free streaming
- Is it okay to call someone boring on Twitter?
- IT execs: 'UK will never create a tech giant'
- Firefox 3.6 beta tested in-depth
- Spotify's Daniel Ek to headline SXSW: Spotify coming to America?
- Windows 7 is a good name, trust us
- Interview: Lala co-founder Bill Nguyen on Google and the future of music
- Nokia exec: 'Apple taught the industry a painful lesson'



