Based on research across established dark web forums, threat actors are targeting macOS, with exploits trading for millions of dollars

  • roofuskit
    link
    fedilink
    55
    edit-2
    11 months ago

    Apple used to brag about how Macs didn’t get viruses. I used to laugh because it wasn’t that they were that much more secur but because their market share was too small to be a profitable target.

    Now they’ve cultivated the perfect target user base. A large collection of tech ignorant or adverse people who have lots of money to burn.

    • 🦘min0nim🦘
      link
      fedilink
      English
      2911 months ago

      Well, they were significantly more secure by default than Windows due to various design measures including the separation of user land. And old OS9 was friggin brilliant for a web facing machine back in the day.

      • @argv_minus_one@beehaw.org
        link
        fedilink
        English
        711 months ago

        OS9 ran absolutely everything with full privileges. It was not even remotely secure. It was basically Windows 95-level security.

    • @abhibeckert@beehaw.org
      link
      fedilink
      11
      edit-2
      11 months ago

      When did Apple brag about that? All I can think of is a brief ad campaign where the “PC Guy” had a cold. That’s hardly a claim that Macs have perfect security.

      Apple has, in fact, gone on the record as saying they don’t think the Mac is secure enough, and that’s why iOS is locked down as tight as it is.

      • @Hazzia@discuss.tchncs.de
        link
        fedilink
        7
        edit-2
        11 months ago

        I don’t recall if Apple themselves actually advertised for that, but it was definitely one of the commonly cited “data points” online when you were looking to buy a computer back in the late 00’s / early 10’s. Back then, I recall people also thought these fancy new-fangled devices called “smartphones” also couldn’t get viruses, regardless of OS, for the same reasons cited by OP

    • combustible_lemon_engineer
      link
      fedilink
      3911 months ago

      It may not even be that much of a real increase. The “1000%” increase chart in the article doesn’t have any y-axis label, which is suspicious. Plus percent increases from a small absolute starting point are misleading.

      Skimming article, it looks like increase is in dark web posts about MacOS zero days and CVEs rather than actual successful attacks.

      • @DragonTypeWyvern
        link
        15
        edit-2
        11 months ago

        During covid, the right wing dipshit-o-sphere tried to scare Asian people into thinking black people were out to get them.

        They’d link things like “San Francisco hate crimes against Asians up 500%!” and just counted on no one looking at the numbers, which in these cases were an increase of one per year to five (all committed by one crazy dude)

        Anyways, the reactions to that number were my first real internalization of the concept that the majority of people are just too lazy to check sources, which is something I knew but couldn’t quite believe until then.

        • @Hazzia@discuss.tchncs.de
          link
          fedilink
          13
          edit-2
          11 months ago

          IIRC, hate crimes against Asian Americans WAS a problem during covid, but it was driven pretty much entirely by said right wing dipshit-o-sphere because of Orange Julius’s “china virus” sentiments. If they were trying to spin that as “Look how dangerous black people are!!”, that is… actually completely unsurprising, almost to a diaappointing degree.

    • The Doctor
      link
      fedilink
      3211 months ago

      More and more, companies are giving their sysadmins and coders Macbooks rather than Wintel laptops. It’s been an upward trend in last eight or nine years. I’ve always thought it was to head 'em off at the pass so they won’t install un-remotely managed and un-monitored Linux distros on company equipment. At any rate, a lot of proprietary stuff winds up on corporate Macbooks, which means targets worth going after. As for availability of exploits for OSX, folks have been hoarding them for this kind of situation. These days, you wait for an optimum target environment before you unleash your 0-days.

      • @Kazumara@feddit.de
        link
        fedilink
        9
        edit-2
        11 months ago

        I’ve always thought it was to head 'em off at the pass so they won’t install un-remotely managed and un-monitored Linux distros on company equipment.

        For me it’s not working. Every day of having to use macOS drives me closer to doing this. It’s such a fucking annoying system, even after 2.5 years :-D

        • @Hazzia@discuss.tchncs.de
          link
          fedilink
          111 months ago

          My first smartphone was an iPhone back in 2011. I hated that damn thing so much and I can’t even remember the specific reasons why, but I know that I did, and that was years before they went “full Apple” so I will probably never willingly touch another one of their products for the rest of my life.

          • Sirence
            link
            fedilink
            511 months ago

            I remember why I hated my iPhone 3g so much. Mandatory iTunes, no multitasking, horrendous notification management, terrible skeumorph design everywhere, safari as mandatory browser which most websites were not compatible with… I could go on for a while.
            I hated my iPhone so much I sold it and thought I’d never buy another smartphone again because I assumed all of them were that shitty.
            Bought a gingerbread android a while later and it was just so much better in every regard.

            • The Doctor
              link
              fedilink
              111 months ago

              I’m stuck with an iPhone for work, too. I really don’t like it. Hell, the only thing I use it for is Okta OTP, I don’t even receive text messages on it. Handy to have a thing to act as a wireless hotspot once in a while, though.

  • interolivary
    link
    fedilink
    English
    2111 months ago

    Welp, maybe I’ll finally have to get around to installing some sort of anti-virus/malware software after 20 years of macOS and/or Linux. At least the system architecture isn’t quite as much of a dumpster fire as Windows’ is, but nothing is invulnerable when there’s enough incentive

    • meseek #2982
      link
      fedilink
      23
      edit-2
      11 months ago

      Naw. This is just FUD. I mean it’s coming from Accenture ffs.

      Keep calm and keep computing.

        • GreatAlbatross
          link
          fedilink
          English
          511 months ago

          “Does your company have macs? Mac attacks are up 1000% percent. If you don’t have the IT resources to install antivirus on all your shiny macs, you can pay us to do it for you.”

      • combustible_lemon_engineer
        link
        fedilink
        611 months ago

        Yep. Seems to be a sensationalized piece that basically boils down to “Mac market share in enterprise is now more than a rounding error, so hackers might start targeting it”

        • meseek #2982
          link
          fedilink
          211 months ago

          Anker did just that. Turned out you could just copy paste the url into VLC and watch someone’s feed without them even knowing. They suppressed the info and hid.

      • interolivary
        link
        fedilink
        411 months ago

        Yeah I’m not exactly in a hurry here, but more widespread malware is still just a question of incentive. macOS isn’t invulnerable, it’s just mainly been a smaller and less easy target so it’s not gotten the same sort of attention as Windows

        • meseek #2982
          link
          fedilink
          6
          edit-2
          11 months ago

          Every software has holes. Not saying macOS is bullet proof. But it’s much harder to infect thanks to its Unix core and the fact the entire OS is on a read only partition. That with their own anti malware tool (Gatekeeper) that took on a much more active roll in macOS’s defenses come Ventura.

          I’m far more worried Apple replaces macOS or closes it just like all their other OSes and we end up bouncing between jailbreaks.

    • Barry Zuckerkorn
      link
      fedilink
      English
      811 months ago

      The general recommendation is to configure your system to allow the use of the minimum number of privileges. If you don’t have the need to use software that doesn’t come from a trusted repository (like the Apple App Store itself, but also things like homebrew), go ahead and turn off the ability to run software from other sources. If you’re coding, make sure your code is properly sandboxed, and that you’re not blindly relying on untested packages (see compromised npm packages). Don’t give apps accessibility or other rights if they don’t need them, etc. And then stay current on all software updates.

      Even zero-days often rely on certain configurations, and you can always lock down the built-in apps to not auto-run or auto-preview things they receive. Some of it requires an active user maintenance to decide how to balance convenience versus security on your own system.

  • @crow@beehaw.org
    link
    fedilink
    English
    14
    edit-2
    11 months ago

    The trick is to use an operating system so niche and different that no one is prepared to hack it.

    • phi1997
      link
      fedilink
      1811 months ago

      For those who take this seriously: don’t. Security by obscurity does not work.

      • @mobyduck648@beehaw.org
        link
        fedilink
        5
        edit-2
        11 months ago

        I practice security through obsolescence instead, all my data is stored on 3 1/2” floppies and if I need to send someone a voice message I post it on a cassette.

    • The Doctor
      link
      fedilink
      English
      811 months ago

      I know a couple of greybeards who’re building a SCO UNIX virtual machine to troll skiddies. I wonder if they’re going to sneak it onto the network at hacker summer camp.