FUD about Mac security or is there an element of truth?

An article on The Register by Security Focus suggests that Macs are a potential security nightmare for enterprises. Now, to a certain extent, this is all just FUD - confessed FUD since the issuers of the security warnings admit they're doing it to make people sit up and think about future issues. Reading through the article there are hints that people don't quite understand Macs and Mac security: why worry so much about firewall-less Macs on corporate networks, particularly when there are no ports open by default on a Mac that would need firewall protection?

Similarly, arguments that while there are viruses and exploits for Linux and Windows and there aren't on Macs, that's because the Mac marketshare is so low, don't really wash. After all, Linux marketshare is no better than Mac marketshare so should be targeted as little. The article also takes little account of permissions and the administrator verification requirement needed to do anything desperately evil on a Mac.

The citing of a root kit for OS X in the article also shows that the Mac is a target, but since the root kit hasn't broken out into the wild and it has no propagation mechanism, it clearly is far harder to exploit Mac vulnerabilities than it is to exploit Windows vulnerabilities.

Nevertheless, no computer is 100% secure and putting blank and easily guessable passwords on administrator accounts is going to leave you with a compromised machine sooner or later. So don't be complacent, but don't listen to all the FUD.

Technorati Tags: ,

Leave a comment

Recent Entries

  • MT 4.1 now out

    Movable Type 4.1 is now available, I notice. I gave it a try today and while there are obvious improvements everywhere, there are a couple...

  • MT4: Finally made it

    Finally. I've done it. I've made the switch. With the slight exception of MT Blogroll, which I can do without for now (but which...

  • MT4: nearly there

    Tried again with my bi-weekly MT4 upgrade attempt. We're nearly there now, I reckon. Simply Threaded was giving me some problems and not showing...

  • MT-MyBlogLog

    I've been trying to 'Voxify' my media blog of late. That's included comment threading, relative dates, changes to stylesheets, etc. But the biggest change...

  • MT4: not yet

    The observant will have noticed that I've still not migrated my blogs over to MT4. I did have an abortive attempt at it last...

Close