Recent events call into question Apple's black box approach
Just a couple of weeks ago everyone was writing about the amount of vulnerable open source code being used by enterprises. For years we have all heard how insecure Windows is. Adobe has been the butt of jokes for their seemingly endless string of vulnerabilities. Through it all Apple and their fanatic base have taken a holier than thou approach about Apple being more secure by design. So secure in fact that you didn’t need to run security software on your Mac. Well now it seems the chickens have come home to roost and Apple may be a victim of its own success.
The recent Forefront malware incident highlights what many in the security world have long suspected. While open source, Windows and Adobe use were over and beyond critical mass levels, Macs for all of the talk were under 10% of the market. It wasn’t a big enough market segment for the serious malware players to go after. It was taken as a given in many sectors of the security field that when and if Apple reached a large enough share of the PC market we would see Apple malware, just like we see malware from other software.
In fact some people believed tha given Apple’s black box philosophy and their lack of experience responding to a major security breach, an Apple malware outbreak could even be worse. Well 600,000 infected Macs later, this appears to be exactly the case. The real shame here may be that the Flashback malware may have been around since 2011 and Apple for whatever reason choose not to address it. That is what the Mac security firm (I guess people won’t call that an oxymoron anymore) Intego says on their blog.
Having a long known vulnerability is one thing in security circles, having known exploitable code out in the wild is yet another thing. It would seem that this code was out there for almost a year. Apple did not have a formal response until over a half a million machines were infected. Then once they did formally respond, it would seem their lack of experience here bit them in the rear. They fumbled the response and that has led to even more scrutiny. Maybe doing those regular patch Tuesday’s isn’t so easy after all.
But this is an open source blog, so lets come back to that. Yes open source code can and does have vulnerabilities. So does Windows and so does other software code. And now we know, so does Apple code. In fact it is safe to say that vulnerabilities can and do exist in most if not all computer code. For me the issue is once a vulnerability is discovered what happens. In open source code it is fairly easy to go right in there and see the code that has or causes the vulnerability. With the “many eyes” on the code, any number of developers can seek to change the code and close the vulnerability, hopefully without effecting functionality. You can actually get your hands on the code in question.
In the case of Apple though, that is not a possibility. The black box mentality does not let you anywhere near the code. Steve Jobs would be doing somersaults if Apple made that code available. Now Apple is not alone in this. For that matter Microsoft doesn’t make vulnerable Windows code available either (though 3rd pary patches are sometimes available). But with Apple the very culture would seem to go against this concept.
So to those who bash the security of open source code, take heed. All code has vulnerabilities, how easy they are to fix and who has access to the code to make that fix may put open source security on a higher plane than those guys over at Apple!
In the meantime, I don’t think we will be seeing any more cute commercials that Apple is more secure than anyone else and Mac users should take this Forefront malware as a wake up call. The Mac has enough market share to make it worthwhile for the bad guys to target. Don’t be so smug to think you don’t need security software on your Mac anymore. There are lots of choices, go get some today!




