Mac OS X with 100 bugs: Still safer than Windows?

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Apple has plugged around 100 vulnerabilities in OS X so far this year, but the malware threat to Mac customers is insignificant compared to users of Microsoft Windows.

So far this year, Apple users have been exposed to the kind of vulnerabilities that are more commonly associated with Windows. The Mac maker has plugged security flaws that could have resulted in OS X customers being "owned" by basic actions such as visiting a malicious website, watching a video file or opening an email attachment.

However, despite all these vulnerabilities, the Mac's resilient platform, its advanced automatic software update tools and the apparent lack of attention from malware authors means Apple users are far safer from attack than users of Windows.

"There are no viruses really for OS X — there have been a few — but, from that point of view, the likelihood of you getting hit on an Apple is insignificant compared to PCs," said Patrik Runald, senior security specialist at antivirus firm F-Secure.

"We have seen more vulnerabilities patched over the past 18 months in OS X than we have before, so it is not a foolproof operating system," warned Runald, but he suggested that OS X users were also safer because of the lack of attention from criminals.

The likelihood of you getting hit on an Apple is insignificant compared to PCs

Patrik Runald, F-Secure

"More bad guys are looking at Windows than they are at Apple," Runald said.

Software vendor CA's vice president of development, Eugene Dozortsev, isn't so sure that Mac users are that safe: "Actually, the Mac is as vulnerable as everything else... Don't make any false assumptions that there are no viruses on Mac. A lot of things like Trojans and email worms [affect the Mac] the same as they would in the PC world."

However, Dozortsev's colleague, Jakub Kaminski, director of content research, said: "There are a couple of specific [OS X threats] but, in the whole scale, in the whole picture, it is nothing."

One recent threat that affected some Apple users, called "Badbunny", was a worm that threatened OpenOffice documents. However, it was attacking the open-source office productivity suite rather than the Apple platform itself — Badbunny also affected Windows and Linux systems running OpenOffice.

Apple's iPhone could provide an attack vector for malware authors but the threat from the new device, which is only a few weeks old, is as yet unknown. Despite this, analyst firm Gartner has already published a report warning administrators to beware of the "must-have" gadget.

Gartner claimed the iPhone could "punch a hole" through corporate security systems if staff are allowed to use the phone for work purposes.

F-Secure's Runald said the threat from the iPhone is yet to be realised: "There is a lot of interest in the security community. We are getting our first iPhone in the lab this week and we will see what we can do with it. There have been thoughts about Safari [the browser] and some ideas about what else could potentially be used but, as of now, we just don't know."

Should the iPhone become ubiquitous, Runald said attacks would be likely.

"As the [iPhone's] popularity grows, we are going to see more threats targeting Apple. It... is logical — Windows is the primary operating system used today, which is why we see the most threats. Symbian is the primary operating system for mobile phones, which is why we see most threats for Symbian," he said.

Talkback

<I>Gartner claimed the iPhone could "punch a hole" through corporate security systems...</I>

Maybe they said that, but the linked article actually said, <I>"most"</I> smartphones come with easy-to-use tools to transfer files onto corporate devices, possibly introducing malware.

In contrast, the iPhone comes with a VERY circumscribed set of synchronizing tools that, as of now, only allow for transfer of very limited calendar events, contact names, etc., from the iPhone to limited files on the desktop PC. As yet, we have <b>no</b> identified way to transfer malicious content.

This offers about 1% of the risk level associated with users transferring data via a simple keychain/flash drive or generic MP3 player.

The linked article actually notes some important points about maintaining security zones for different needs and devices -- e.g., pointing out that the Apple-recommended approach to customized development can be both easy and very secure -- but you can't tell it from the misquote.

2000382116 11 July, 2007 17:30
Reply

Thanks for your comments, 2000382116. With reference to the "punch a hole" quote, it is actually contained in the linked article, in the fifth par. But I appreciate your insight into iPhone security.

RichardThurston 12 July, 2007 13:28
Reply

Hello? the linked article talks about "most" smartphones having tools to "punch holes" in security, while the iPhone design PREVENTS these types of uncontrolled transfers.

A simple sentence of opinion plus the simple fact that it doesn't apply to the iPhone.

2000382116 12 July, 2007 14:15
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

SPM

The 2 million number quoted is shipments not sales, an exact repeat of last year's dire sales of WP7. Sales to customers are likely to number only...

3 hours ago by SPM on Nokia earnings fail to shine despite Lumia
apexwm

It sounds like this is just another variable in the complex equation of Microsoft licensing, which often results in customers overpaying as it is....

5 hours ago by apexwm on UK customers to lose out in Microsoft licensing change
chonzchor

I am really thankful to you for this nice and beautiful information.I really like this. cable ties

5 hours ago by chonzchor on Currys £16.99 USB cable rip-off.
Brian Jones

What would be nice would be if Microsoft practiced consistent pricing between the US and Europe.

10 hours ago by Brian Jones via Facebook on UK customers to lose out in Microsoft licensing change
Karen Friar

@Scott Deagan: Ofcom dedicated a section to upload speeds - see page 19 onward of its full report:...

11 hours ago by Karen Friar on UK broadband speed climbs 22 percent
EUDataProtection

The EU proposals can all be read in full on the reform website: http://ec.europa.eu/justice/data-protection/minisite/index.html

12 hours ago by EUDataProtection on Firms face tough new EU fines for data breaches
Jake Rayson

Found out that Taskwarrior stores all data in plain text files: "Task writes all pending tasks to the file ~/.task/pending.data and all completed...

14 hours ago by Jake Rayson on Taskwarrior: command line task manager
ians1

"...based 6,000 miles away..." Indeed, so who do you complain to when things go wrong? I would not buy shares in Faecebook even if I could...

14 hours ago by ians1 on Facebook plans to raise $5bn via share launch
servermanagement

These are really very useful tips of backing up the system. Each tips are important and essential to prevent loosing all the data that we have....

17 hours ago by servermanagement on Ten ways to take the sting out of IT disasters
Scott Deagan

Why is the upstream never discussed? I'd like to see Ofcom explain to Internet users why people in the UK can only get a maximum of 10Mb/s upstream...

1 day ago by Scott Deagan via Facebook on UK broadband speed climbs 22 percent
Moley

Seemingly a very strange decision, even perverse. Mind you, the basis of the decision is hardly explained here or in Cnet. Perhaps we will hear...

1 day ago by Moley on Free Maps costs Google £400K in damages in France
Jake Rayson

@OccupyACAT: I had heard mention of the Emacs extension but not the Ubiquity project. Interesting to see an idea spread almost simultaneously! Re....

1 day ago by Jake Rayson on Ubuntu HUD Intenterface? Sublime already there!
markhumphryes

With no Flash support on LoveFilm, mobile devices running Android will not be able to use it - I presume - I tried a trial via my Galaxy Tab 10.1...

1 day ago by markhumphryes on Lovefilm drops Flash, kills Linux support
manek

And people wonder why there is caution about doing business with large, consumer-focused technology companies, most of which are based 6,000 miles...

2 days ago by manek on Facebook plans to raise $5bn via share launch
manek

Yes, frameworks and smarter compilers - but I suspect a lot of the code will have to be written with parallel processing as one of its fundamental...

2 days ago by manek on Parallel computing takes a step forward
Simon Bisson and Mary Branscombe

Well, this is why I'm both fascinated and slightly worried; parallel computing and concurrency and complex architectures don't seem to be something...

2 days ago by Simon Bisson and Mary Branscombe on Parallel computing takes a step forward
ians1

Let's hope that they take more notice of their shareholders than they do of their poor customers! I have never experienced customer service as bad...

2 days ago by ians1 on Facebook plans to raise $5bn via share launch
servermanagement

Thanks for the heads up. Will definitely check this HUD Intenterface.

2 days ago by servermanagement on Linux Minterface
Will A

Some more observations by an extremely frustrated user in Canada (apparently every country has a different set of "issues"): The web interfaces...

2 days ago by Will A on Cambridge researchers knock Verified by Visa
Jake Rayson

@zdnetukuser: I hope there's more conciliation and less bitterness in the graphical shell camps, I'd like to Ubuntu to succeed, I *want* to have a...

2 days ago by Jake Rayson on Linux Minterface