-
Website
http://www.matasano.com/log -
Original page
http://www.matasano.com/log/985/the-silly-new-mac-os-x-trojan-or-hohuma/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
Press Controls
3 comments · 2 points
-
ChrisMtso
12 comments · 1 points
-
Eric Monti
11 comments · 1 points
-
StatlerAndWaldorf
12 comments · 3 points
-
Dave G.
7 comments · 1 points
-
-
Popular Threads
"I just IM’d my buddy Ryan, who has a Mac, to determine whether he runs AV on his machine. His response: “I don’t think so.”
Mac users are so arrogant and clueless about security, they don’t even know if they have AV installed in the first place. I love it.”
So I suppose that makes us clueless about security, huh?
The most secure systems in the world can't defend against user ignorance...
In general, this thing is the most well-behaved malware installer I've seen - nice clean well-indented perl scripts with explanatory variable names and all. So I can't imagine they'd have obfuscated the function of their plugin either.
http://www.blackfriarsinc.com/blog/2007/11/mac-...
There is very little about the "Unix architecture" that makes Unix safer than Win32.
The distinction people are actually talking about is not "Unix vs. Win32". It's "single user environment" versus "server environment".
From a security perspective:
OS X has more in common with Windows XP SP 2 than it does with Solaris 10.
Windows Server 2007 has more in common with Solaris 10 than it does with Windows XP SP 2.
Perhaps I'm missing something here, but Gadi's comment seems to be the work of a half-brained moron, rather than a BugTraq $uper$tar. Oh well... what can you do...
Oh, and for the record, I'm not saying that there will not be a yield for this trojan; I'm just saying we're not talking OpenSSH remote root 0day here. Or xnu remote root 0day. Whatever.
The users who find it ok to run questionable files on their machines. We forgot to create a patch for them. Would this be like a nicotine patch?
"To this day, I am not entirely convinced that it makes sense to invest in security before it costs you."
So you are saying you should wait until after blaster hits before investing in security?
sheesh
Waiting until its "worth it" to invest in security means you have to be compromised many times over before you will get a good ROI. Of course a single compromise can lead to a string of misdeeds that can cost a company hundreds of millions. This was TJX's plan, and look where it got us.
-JP
What should you invest in? OS X antivirus? No? Then what point are you making?
why not "invest" in teh free clamXav?
http://www.theonion.com/content/amvo/new_trojan...