News
CONTINUED:
Macs are not invincible
The most serious incident was perhaps the public disclosure of a serious and easily exploitable flaw in the Apple operating system, which could be a conduit for intruders to install malicious code on computers running the software. Attack code that takes advantage of the security hole was quickly posted on the Internet.
The problem lies in the way Mac OS X associates files with applications, and it could be exploited to hit a Mac via the Safari Web browser or Apple Mail, experts said. Apple has said it is working on a fix for the flaw. So far, no attacks based on the bug have been spotted on the Web.
Overall, only a few currently known worms, viruses and Trojans target the Mac, McAfee's Schmugar said. Nevertheless, people should not ignore the danger. "There does not have to be more then 150,000 threats for Macs before it's a security concern," he said, referring to the number of known Windows pests.
A machine running Apple's operating system might actually be easier to hit than a Windows PC, Schmugar said. "There are fewer and less evolved defences around a Mac, because there have been fewer threats against it," he said. "The success rate for getting malicious code to run is probably greater."
The Mac maker is taking measures to sew up the latest hole in its operating system. "Apple takes security very seriously," a company representative said. "We're working on a fix so that this doesn't become something that could affect customers." The representative could not say when the patch would be ready.
Long recommends two tweaks to the OS X settings to make it more secure -- enabling the firewall, and disabling the "Open safe files after downloading" option in the Safari preferences. That last option, if not locked up, could be exploited to trick people into downloading malicious code onto their Mac, he said.
All in all, this is not significant enough to dent user confidence in Mac OS X as a secure operating system, said Ray Wagner, an analyst at Gartner. "Given that the most recent vulnerability does not spawn an attack before being patched -- an unknown -- there is not enough impact on the average user to cause a significant change in behaviour," he said.
Apple is advising its customers to consult its online safety guide, and to be cautious when surfing the Web. "Apple always advises Mac users to only accept files from vendors and Web sites that they know and trust," the company representative said.
Asked if the Mac, compared with Windows, is still the obvious safer choice for people on the Internet, Gartner's Wagner simply replied, "Yes."
More about Software
- Obama in sex video shocker? Oh wait, it's just spam September 11, 2008
- No black holes from Large Hadron Collider, say scientists September 10, 2008
- Michael Moore to premiere film online September 05, 2008
- Images: Touring Google's Chrome browser September 05, 2008
- Extensions promised for Chrome September 04, 2008

- Virgin Media and CView to rifle through your packets
- Motorola Milestone: The Droid drops exclusively on eXpansys until 2010
- Opinion: Apple owes Microsoft $30bn
- How MySpace can beat Facebook in 2010
- CNET UK Podcast 163: Is giffgaff the future of mobile tariffs?
- Technics 1200 and 1210 axed by Panasonic: Number's up for the ones and twos?

- Virgin Media and CView to rifle through your packets
- How MySpace can beat Facebook in 2010
- Want to try the new Google homepage? We show you how
- Windows 7 Family Guy clips outed, with bonus Sugababes
- Last.fm interview: Behind the music
- Truphone talks turkey with free calls on Thanksgiving
- Man arrested for not tweeting to teeming tween tumult
- The best of Photosynth
- Seesmic Desktop for Windows: Better for Twitter than TweetDeck?
- Microsoft and Murdoch ganging up on Google?
- Spotify launches on Nokia, Samsung, Sony Ericsson phones
- Behold: The Facebook 'magic circles' trick
- Free Office 2010 beta available to download
- Domino's mobile: When the noms hit your iPhone like a big pizza pie
- Twitter vs the world: Ten scandals that set Twitter alight



