Spyware, OSX and Themes
Apple’s have been more secure than PCs for about as long as I can remember. It’s generally acknowledged, though, that a main reason for that is the lack of value in attacking one.
Seriously, writing a virus, some spyware or other piece of trojan software for the Mac would be pretty pointless with the market penetration they currently have. That’s not a dig - I’m a big Mac fan. I drool over the 17″ Powerbook whenever I pass one and if virtual pc for the mac were just that bit faster then I would seriuously consider it. But if you want market penetration for a piece of malignant code it’s not the platform to exploit.
With corporate and even home machines getting slowly more secure, the use of social engineering attacks, such as the email phishing scams for bank details, become more and more prevalent. One such misrepresentation attack that’s been around for ages, but appears to be on the increase is the use of flash, DHTML and other dynamic web content designed specifically to look like system dialogs. FUIs - Fake User Interface dialogs.
If you’ve spent any time at all on less reputable sites, for whatever reason, you’ll have seen them. Big exclamation icons with phrases like “you computer is infected with spyware, click here to disinfect”. Which should really read “this is an advert from a malicious spyware writer, click here to have your machine hijacked and/or infected”. If you want to see what I mean, look at examples of what was probably the first major campiagn of this type, by Bonzi. Oh, and the subsequent settlement to a class action lawsuit filed in Washington.
So, apart from the obvious benefit that a Mac isn’t vulnerable to the same exploits as a PC (a benefit you can get most of by browsing with Firefox instead of IE) there is another benefit. Everything on the Mac looks different. The window frames, the maximize, minimize and close buttons, the grey bevel buttons all look very different to a PC. This make it obvious to anyone using a Mac that the little dialog is an imposter and not part of the system.
As a poster on MetaFilter says so eloquently:
Of course, we Mac users are nothing but amused by those bogus “error” messages because, well… they don’t look like error messages to us, they look like cheap attempts to trick bumbling PC users into clicking through someplace they wouldn’t otherwise want to go…
You can achieve this effect on your PC, making it easier to recognise threats visually, by installing a skinning tool such as WindowBlinds. Making your windows look different to Windows could make the difference between clicking a dialog and not for many users.
Other, more traditional, tips & tricks can be found on Bruce Schnier’s blog.
Search
Right Now (ish)
- lmao: http://www.comparethemeerkat.com/ 17 hrs ago
- @alanjohndix because mature developers are still so flaky? in reply to alanjohndix 1 day ago
- @rsinger CTL + [two finger scroll on touchpad] to zoom? in reply to rsinger 1 day ago
- More updates...
Categories
- .Net Technical
- Blog on Blog
- commands I have issued
- Enterprise Architecture
- event
- Fiction Book Review
- Food
- Interaction Design
- Internet Social Impact
- Internet Technical
- IP Law
- Library Tech
- Music
- New Toy
- Non-Fiction Book Review
- Other Technical
- Personal
- Random Thought
- Resourcing
- Security And Privacy
- Semantic Web
- Software Business
- Software Engineering
- Talis Technical
- Uncategorized
- Working at Talis
- [grid::blogpaper]
- [grid::fatherhood]
Archive
- December 2008
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- January 2008
- December 2007
- November 2007
- October 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- September 2006
- August 2006
- June 2006
- February 2006
- January 2006
- December 2005
- November 2005
- September 2005
- August 2005
- July 2005
- June 2005
- May 2005
- February 2005
- January 2005
- December 2004
- November 2004
- October 2004
- September 2004
- August 2004
- July 2004
- June 2004
- May 2004
- April 2004
- March 2004
- February 2004
- December 2003
- November 2003
- August 2003
- July 2003
- June 2003
- May 2003
- March 2003
- January 2003
- May 2002
- March 2002
- August 2001
- May 2001
- April 2001
- January 2001
- December 2000
- November 2000
- December 1999
- November 1999
- July 1999