The SANS Institute released a Top 20 Vulnerabilities on the 28th of November 2005, and horrors of horrors, Mac OS X, which has been Virus and Trojan free for the last 5 years was listed among the Top 20, and the only entire Operating System to earn the credit of appearing in this list.
Understandably, this created quite a stir amongst the Mac community, and several friends of mine who are Windows users sent me spite mail to say “Ha! The Mac is not so secure after all is it?” Well, I think this begs a reply of some sort. But, to do so impulsively would be foolish.
Mac OS X was launched in 2001 and has since then been virus and Trojan free. Isn’t that something to count for? To have an institution suddenly release a statement saying the OS is insecure doesn’t erase 5 years of track record. In the words of MacDailyNews, which I reproduce here in its entirety:
“Poppycock and Balderdash aren’t just a nice snack and a fun game anymore. What’s next, is the SANS Institute going to warn Madonna that a Best Actress Oscar is coming her way? Sheesh. Forgive us for not quaking in fear, but we’re not rushing to buy Symantec’s Norton AntiVirus 10.0 for Macintosh.
No operating system is invulnerable, but users of Mac OS X are so much safer than users of Windows, it’s impossible to overstate the discrepancy. Don’t run Mac OS X as root and don’t authorize applications that you don’t understand or trust. Use Software Update to keep your Mac up to date. Turn on your Mac OS X Firewall (System Preferences>Sharing>Firewall) if you wish. Run AntiVirus apps to screen out Windows viruses, so you don’t pass them on to Windows sufferers, if you’re feeling like a magnanimous network citizen.
Zero Mac OS X viruses, spyware or other malware, for five years and counting, and we’re running the one OS deemed a “major security threat” by the SANS Institute? Whatever.”
Clearly the report has hit a raw nerve, and rightly so. A statement made by one Mac user sums it up I think:
“Wow! I guess this means I will tell my clients to switch back to Windows systems because they are so much safer now than their Macs. What a load of bulls**t. I have yet to come across ANY expolitable security flaw for mac OS while I spend hundreds of hours a month patching Windows systems and fixing them because of actual problems caused by exploits. Until I actually see an honest to goodness remotely expoitable security hack I will continue to ignore these idiots at Symantec, etc.”
So, I leave the judgement to you. Alvin, if you can… you should read this entry. 