 |
|  |
 |
|
Lul Thyme
|
|
Quebec, Canada
Aug 2000 time: 05:21
|
|
quote: Originally posted by Asher
Believe what myth?
What is the point in investing time and energy into writing a virus to target something with 2% marketshare when you can hit something with 95%+ marketshare?
It's a psychological question more than anything else. People who write viruses are out for fame or have an appetite for destruction, neither of which lend themselves to tiny marketshares... |
While that's what I was saying.
All this is obvious to me, and Im asking if anybody really defends the other position (the myth you talk about)...
Did you even read my post?
|
|
|  |
 |
|
Asher
|
 |
Calgary, Alberta
Nov 1999 time: 22:21
|
|
quote: Originally posted by Atahualpa
Generally speaking, how old is Windows NT (which XP is based on, no?) and how old is Mac OS X? |
Are you talking about the kernel or the OS itself?
Windows NT is mid-90s, Mach is from the mid-80s.
quote: But anyway a security flaw != a security flaw and 100 flaws can be less harmful than a single other. You're playing marketing department if you just compare numbers. |
This is true to an extent -- for instance, a remote exploit versus local exploit.
It doesn't matter, there are remote exploits for virtually every system.
Hell, even the latest MacOS X patches fix remote buffer overflow vulnerabilities that allow arbitary code execution (not unlike Blaster...):
quote: # Cyrus IMAP
Available for: Mac OS X Server v10.3.8
CVE-ID: CAN-2004-1011, CAN-2004-1012, CAN-2004-1013, CAN-2004-1015, CAN-2004-1067
Impact: Multiple vulnerabilities in Cyrus IMAP, including remotely exploitable denial of service and buffer overflows.
Description: Cyrus IMAP is updated to version 2.2.12, which includes fixes for buffer overflows in fetchnews, backend, proxyd, and imapd. Further information is available from http://asg.web.cmu.edu/cyrus/downlo...d/changes.html. |
quote: Cyrus SASL
Available for: Mac OS X v10.3.8, Mac OS X Server v10.3.8
CVE-ID: CAN-2002-1347, CAN-2004-0884
Impact: Multiple vulnerabilities in Cyrus SASL, including remote denial of service and possible remote code execution in applications that use this library.
Description: Cyrus SASL is updated to address several security holes caused by improper data validation, memory allocation, and data handling. |
quote: However I still doubt that in OS X there are such easily exploitable vulnerabilites such as the Blaster attack, which doesn't even require user action, just a connection to the internet and the absence of a firewall (which was deactivated by default in pre-SP2 and how many OEMs shipped with an enabled firewall???). Flaws like these make MS look stupid. |
It was addressed and a fix made public 3 months before the attack happened. The user would need to have disabled automatic updates to be affected by this.
That doesn't make MS necessarily stupid, but the users affected.
It was a pretty embarrassing bug, but I don't think you understand much about it if you think MS is the only system that does that. RPC was actually first on Unix, not Windows.
MS overhauled RPC in SP2 and higher though, and should be much safer...not to mention the firewall.
You live, you learn.
Isn't OS X' firewall disabled by default, BTW?
|
|
|  |
 |
|
Lul Thyme
|
|
Quebec, Canada
Aug 2000 time: 05:21
|
|
quote: Originally posted by Asher
Your post wasn't very clear. That's why I asked for clarification.
I'm pretty sure more money is stolen from pickpockets as a whole than banks, for instance. |
Ok I guess the analogy wasn't all that clear but I meant just my pockets.
In any case as previous poster just said to, it is evidence.
|
|
|  |
 |
|  |
 |
|
Fve Crathva
|
|
You should do things because they are right, not because people will remember them in 5/10/20 years' time. So yeah, I'd take that approach to these retarded arguments.
Security through obscurity is a legitimate technique. It just shouldn't be relied upon.
SP
|
|
|  |
 |
|
Fve Crathva
|
|
Round teabags aren't nearly as useable as square teabags, mother****er. The square teabags may look less stylish, but the corners catch on the cup walls, so they don't just bob back up to the water surface like those trashy round teabags. Plus, square teabags are easier to assemble, so they don't come apart as easily as round teabags.
SP
|
|
|  |
 |
|  |
 |
|
Agathon
|
 |
Leafs 4TW!! - CPA
Dec 2002 time: 00:21
|
|
quote: Not all cases have emperical evidence or confirmatoin available...it's not practical in all of them. This is one of your worst arguments of all time, for the record. |
Then we should be sceptical instead of blindly assuming things like you do.
quote: So then shouldn't you be able to name them? |
The following explanations seens just as plausible (in fact I think it is more plausible, since there are zero viruses for OS X, and OS 9 had quite a few, and had comparable numbers of users).
It's hard to get software to install itself on OS X in a way that would compromise a machine without root access (a password) or physical access to the machine (that's why the only bad stuff so far has been a trojan that must be manually installed).
If you don't have an admin account, you can't even get that far.
Even if you could, if you tried to start it, the system would warn you that the app was starting and you could prevent it from running.
quote: Simple question: If the OS is capable of viruses, why are there none? |
Because "capable" is a vague term. Human beings are probably capable of travelling to Mars just as they are capable of going to the shops, but no one has yet done the former because its so much more difficult than the latter.
If we followed your logic it would be the case that Windows is only a swiss cheese operating system because of its popularity rather than its bad design or the lack of incentives to fix it properly.
Of course it is probably down to all three, but no-one really knows. That's why people still argue pointlessly about it.
But it's just dumb to say that it "must" be one to the exclusion of the others, which is what you are claiming, with flimsy evidence, in the other case.
But in the end it doesn't matter. In practical terms OS X is still more secure than Windows - for whatever reason.
|
|
|  |
 |
|  |
All times are GMT. The time now is 05:21. Apolyton Time is 00:21. |
top of page
|
|
|
Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
|
HTML code is ON
vB code is ON
Smilies are ON
[IMG] code is ON
|
|
|
|
|
|