<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:go='http://ns.gigaom.com/'
xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>GigaOM &#187; Apple</title>
	<atom:link href="http://gigaom.com/apple/tag/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://gigaom.com</link>
	<description></description>
	<lastBuildDate>Sun, 27 May 2012 14:23:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='gigaom.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/0db8f6557d022075dbbf010c54d46d93?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>GigaOM &#187; Apple</title>
		<link>http://gigaom.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://gigaom.com/osd.xml" title="GigaOM" />
	<atom:link rel='hub' href='http://gigaom.com/?pushpress=hub'/>
		<item>
		<title>The three-year itch: Why Apple needs to do more to keep older systems secure</title>
		<link>http://gigaom.com/apple/the-three-year-itch-why-apple-needs-to-do-more-to-keep-older-systems-secure/</link>
		<comments>http://gigaom.com/apple/the-three-year-itch-why-apple-needs-to-do-more-to-keep-older-systems-secure/#comments</comments>
		<pubDate>Fri, 20 Apr 2012 16:00:09 +0000</pubDate>
		<dc:creator>Dave Greenbaum</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Flashback]]></category>
		<category><![CDATA[Leopard]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Snow Leopard]]></category>

		<guid isPermaLink="false">http://gigaom.com/?p=512585</guid>
		<description><![CDATA[Apple recently introduced software updates and a removal tool for the “Flashback” threat on Macs. Users of Apple's current desktop OS, Lion 10.7.3, and the previous Snow Leopard 10.6.8, Apple’s got you covered. For anything older, Apple’s recommendation is disabling Java. That’s wrong, and here’s why.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=512585&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://gigapple.files.wordpress.com/2008/05/leopard.jpg"><img  title="leopard" src="http://gigapple.files.wordpress.com/2008/05/leopard.jpg?w=240&h=235" alt="" width="240" height="235" class="wp-image-176252 alignright" /></a>Apple recently introduced multiple software updates and a removal tool for the “Flashback” threat that takes advantage of an exploit in Java on Macs. For users of the current version of Apple&#8217;s desktop OS, <a href="http://support.apple.com/kb/DL1515">Lion 10.7.3</a>, and the previous OS, Snow Leopard <a href="http://support.apple.com/kb/DL1516">10.6.8,</a> Apple’s got you covered. For anything older than that Apple’s <a href="http://support.apple.com/kb/HT5244">current recommendation</a> is to <a href="http://support.apple.com/kb/HT5241">disable Java</a>. That’s wrong, and here’s why.</p>
<p>Apple’s “<a href="http://support.apple.com/kb/HT5244">solution</a>&#8221; of <a href="http://support.apple.com/kb/HT5241">disabling Java </a> on versions prior to Snow Leopard isn’t realistic for users that still intend to keep their Mac on the Internet, since web-based Java is still popular, especially for proprietary corporate applications. If you are on a Leopard (10.5) or older system, Apple&#8217;s solution means that you could try to enable Java only while you are using websites that require it and then immediately turn it off afterward (a common example of usage is for remote control programs such as GotoMyPC and Logmein). To be fully secure though, the better solution is to upgrade your OS. However, upgrading your Mac&#8217;s OS could introduce incompatibilities with existing software that will require further costs to upgrade. Plus, if a user hasn&#8217;t upgraded to Snow Leopard &#8212; an admittedly old OS &#8212; yet, they may have a good reason for doing so.</p>
<p>Apple updates its operating system at a much faster pace than Microsoft. Leopard was superseded by Snow Leopard in August 2009 and Windows XP was superseded by Vista in November 2006, yet Microsoft is still providing critical security updates for XP until <a href="http://windows.microsoft.com/en-us/windows/products/lifecycle">April 2014</a>. Microsoft is providing more security updates for more versions of their operating system while Apple is starting to abandon users after less than three years.</p>
<p><a href="http://gigapple.files.wordpress.com/2009/02/applecare1.jpg"><img  title="applecare1" src="http://gigapple.files.wordpress.com/2009/02/applecare1.jpg?w=240&h=227" alt="" width="240" height="227" class="alignleft  wp-image-178710" /></a>To be fair, a majority of Mac users have already moved to either Snow Leopard or Lion, according to estimates <a href="http://marketshare.hitslink.com/report.aspx?qprid=10&amp;qptimeframe=M&amp;qpsp=158&amp;qpcustomb=*2">from Net Market Share</a> so most Mac users will be protected from this security flaw after installing Apple&#8217;s latest updates. Windows XP, meanwhile, is still on a majority of PCs according to that <a href="http://marketshare.hitslink.com/report.aspx?qprid=10&amp;qptimeframe=M&amp;qpsp=158&amp;qpcustomb=*1">same study</a>, even though its successor, Windows 7, was released in July 2009. Microsoft is doing this right by continuing to provide security updates for its older operating systems, which sort of makes sense given Microsoft’s constant battle with malware over the years. But Apple isn&#8217;t.</p>
<p>With Apple’s accelerated OS release cycle, leaving Leopard&#8217;s Java security unsupported after less than three years is unfair to users and a potential class action lawsuit waiting to happen since Apple’s extended warranty (AppleCare) is designed to support the Mac for three years. That MacBook you bought in May 2009 has a problem that Apple knows about, and Apple’s solution is to simply disable portions of the OS provided by Apple for your computer.</p>
<p>At the very least, Apple should be required to either patch a security flaw in any computer still under AppleCare or provide a free update to a currently supported version like they are doing for<a href="https://www.me.com/snow-leopard"> MobileMe users</a>. Two years is simply too short of an upgrade cycle to expect users to keep up with in order to maintain the security of their systems.</p>
<p>If Apple continues this &#8220;current and previous version&#8221; approach towards security, Snow Leopard users are going to miss out on security updates when Mountain Lion 10.8 comes out this summer, only two years after they upgraded to Snow Leopard. Apple needs to step up to the plate and provide security updates for at least three years &#8212; otherwise Mac users could be more secure wiping an older Mac OS on that Intel-based Mac and installing Windows XP instead! At least then they’ll have until April 2014 before their computer turns into an unsecured ticking time bomb.</p>
<p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=512585+the-three-year-itch-why-apple-needs-to-do-more-to-keep-older-systems-secure&utm_content=calldrdave">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2012/03/the-new-it-manager-part-2-new-challenges-for-the-it-organization/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=512585+the-three-year-itch-why-apple-needs-to-do-more-to-keep-older-systems-secure&utm_content=calldrdave">New challenges for the IT&nbsp;organization</a></li><li><a href="http://pro.gigaom.com/2012/03/the-new-it-manager-part-1-trends-affecting-it-in-business/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=512585+the-three-year-itch-why-apple-needs-to-do-more-to-keep-older-systems-secure&utm_content=calldrdave">The new IT manager, part&nbsp;1</a></li><li><a href="http://pro.gigaom.com/2012/02/trends-challenges-and-chances-in-the-rising-mobile-deals-space/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=512585+the-three-year-itch-why-apple-needs-to-do-more-to-keep-older-systems-secure&utm_content=calldrdave">Opportunities and challenges for mobile&nbsp;deals</a></li></ul><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=512585&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/the-three-year-itch-why-apple-needs-to-do-more-to-keep-older-systems-secure/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	 <go:thumbnail>http://gigapple.files.wordpress.com/2008/05/leopard.jpg?w=130</go:thumbnail> 
		<media:thumbnail url="http://gigapple.files.wordpress.com/2008/05/leopard.jpg?w=143" />
		<media:content url="http://gigapple.files.wordpress.com/2008/05/leopard.jpg?w=143" medium="image">
			<media:title type="html">leopard</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/73eda5544ca42cec589784b7be68b664?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">calldrdave</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2008/05/leopard.jpg" medium="image">
			<media:title type="html">leopard</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2009/02/applecare1.jpg" medium="image">
			<media:title type="html">applecare1</media:title>
		</media:content>
	</item>
		<item>
		<title>Apple Releases Security Update to Address Mac Defender Malware</title>
		<link>http://gigaom.com/apple/apple-releases-security-update-to-address-mac-defender-malware/</link>
		<comments>http://gigaom.com/apple/apple-releases-security-update-to-address-mac-defender-malware/#comments</comments>
		<pubDate>Tue, 31 May 2011 21:16:07 +0000</pubDate>
		<dc:creator>Darrell Etherington</dc:creator>
				<category><![CDATA[@CNN]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[mac defender]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[Snow Leopard]]></category>
		<category><![CDATA[Software Update]]></category>

		<guid isPermaLink="false">http://gigaom.com/?p=352991</guid>
		<description><![CDATA[Apple promised to release a security update to address Mac Defender malware and its variants, and that update arrived Tuesday afternoon. Security Update 2011-003 is now available for all Macs running Snow Leopard, and brings file quarantine updates, as well as a malware removal tool.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=352991&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img  title="software-update" src="http://gigaom2.files.wordpress.com/2010/11/software-update.png?w=300&h=200" alt="" width="300" height="200" class="alignright size-medium wp-image-257912" /><a title="Apple Will Zap Mac Defender Malware With Update" href="http://gigaom.com/apple/apple-will-zap-mac-defender-malware-with-update/">Apple promised to release a security update to address Mac Defender malware</a> and its variants, and that update arrived Tuesday afternoon. <a href="http://support.apple.com/kb/HT4657">Security Update 2011-003</a> is now available for all Macs running Snow Leopard, and brings file quarantine updates, as well as a malware removal tool.</p>
<p>The OSX.MacDefender.A definition has been added to the OS X File Quarantine database, which means if a user downloads the malware, it will automatically pop up a dialog warning the user that the file will damage your computer, and provide an option to delete the file. The update also allows Apple to automatically update the known malware definitions list through daily updates. Users can opt out of this feature in Security Preferences, shown below.</p>
<p>The security update also automatically searches for and removes Mac Defender and its known variants upon install. If it detects the malware in your system, it will notify you once the update is installed.</p>
<p>It&#8217;s great to see Apple getting out ahead of this malware threat before it really gets out of hand, but as always, the first step to protecting your computer starts with you. Don&#8217;t ever install something when you&#8217;re not sure that it comes from trustworthy origins, and remember that if a website is telling you you&#8217;re infected without you having asked to begin with, it&#8217;s a safe bet that it&#8217;s not a genuine report.</p>
<p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=352991+apple-releases-security-update-to-address-mac-defender-malware&utm_content=etherin">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2011/05/the-case-for-increased-ma-in-2011-actions-and-outlooks/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=352991+apple-releases-security-update-to-address-mac-defender-malware&utm_content=etherin">The Case for Increased M&amp;A in 2011: Actions and&nbsp;Outlooks</a></li><li><a href="http://pro.gigaom.com/2011/05/the-structure-50-the-top-50-cloud-innovators/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=352991+apple-releases-security-update-to-address-mac-defender-malware&utm_content=etherin">The Structure 50: The Top 50 Cloud&nbsp;Innovators</a></li><li><a href="http://pro.gigaom.com/2011/05/californias-new-energy-data-privacy-rules-some-answers-many-questions/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=352991+apple-releases-security-update-to-address-mac-defender-malware&utm_content=etherin">California&#8217;s New Energy Data Privacy Rules: Some Answers, Many&nbsp;Questions</a></li></ul><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=352991&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/apple-releases-security-update-to-address-mac-defender-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	 <go:thumbnail>http://gigaom2.files.wordpress.com/2010/11/software-update.png?w=130</go:thumbnail> 
		<media:thumbnail url="http://gigaom2.files.wordpress.com/2010/11/software-update.png?w=210" />
		<media:content url="http://gigaom2.files.wordpress.com/2010/11/software-update.png?w=210" medium="image">
			<media:title type="html">software-update</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/188039e12983eb749171a75cfd01378d?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">etherin</media:title>
		</media:content>

		<media:content url="http://gigaom2.files.wordpress.com/2010/11/software-update.png?w=300" medium="image">
			<media:title type="html">software-update</media:title>
		</media:content>
	</item>
		<item>
		<title>Apple Will Zap Mac Defender Malware With Update</title>
		<link>http://gigaom.com/apple/apple-will-zap-mac-defender-malware-with-update/</link>
		<comments>http://gigaom.com/apple/apple-will-zap-mac-defender-malware-with-update/#comments</comments>
		<pubDate>Wed, 25 May 2011 13:00:03 +0000</pubDate>
		<dc:creator>Darrell Etherington</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[mac defender]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[os x]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://gigaom.com/?p=350233</guid>
		<description><![CDATA[Apple posted a short support article late Tuesday called "How to avoid or remove Mac Defender malware," which provides instructions on dealing with an existing malware infection, and also promises an update in the near future that will automatically seek it out and remove it.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=350233&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img  title="mac-defender-alerts" src="http://gigaom2.files.wordpress.com/2011/05/mac-defender-alerts.png?w=300&h=200" alt="" width="300" height="200" class="alignright size-medium wp-image-350242" />Apple posted a short support article late Tuesday called &#8220;<a href="http://support.apple.com/kb/HT4650">How to avoid or remove Mac Defender malware</a>,&#8221; which provides instructions on dealing with an existing malware infection, and also promises an update in the near future that will automatically seek it out and remove it.</p>
<p>Before the release of the support note yesterday, it was <a href="http://www.zdnet.com/blog/bott/apple-continues-to-tell-support-reps-do-not-help-with-mac-malware/3375">reported by ZDNet&#8217;s Ed Bott</a> that Apple support staff on the phone were indicating that they couldn&#8217;t provide instructions for dealing with specific instances of malware. The fix is not overly complicated, but explaining it individually over the phone to every affected customer would tie up a lot of customer service agents, and it could set a dangerous precedent for the future treatment of such situations.</p>
<p>The article promises that &#8220;Apple will deliver a Mac OS X software update that will automatically find and remove Mac Defender malware and its known variants,&#8221; and that the update will arrive &#8220;in the coming days.&#8221; Users will also receive an explicit warning notification if they happen to download this malware once the update is installed.</p>
<p>The step-by-step instructions for removing the Mac Defender malware involve using Activity Monitor to kill all running instances of the program and its equivalents (MacProtector, MacSecurity), then dragging the applications to the Trash, and finally, emptying the Trash. Apple also provides instructions for removing the malware&#8217;s login item, though the login item is no longer a threat once the application is removed from your system.</p>
<p>Glad to see Apple responding to the valid security concerns of its users. Let&#8217;s hope this isn&#8217;t the just beginning of the Mac&#8217;s serious malware woes.</p>
<p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=350233+apple-will-zap-mac-defender-malware-with-update&utm_content=etherin">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2011/05/the-structure-50-the-top-50-cloud-innovators/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=350233+apple-will-zap-mac-defender-malware-with-update&utm_content=etherin">The Structure 50: The Top 50 Cloud&nbsp;Innovators</a></li><li><a href="http://pro.gigaom.com/2011/04/connected-consumer-q1-the-over-the-top-vs-pay-tv-battle-heats-up/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=350233+apple-will-zap-mac-defender-malware-with-update&utm_content=etherin">Connected Consumer Q1: The Over-the-Top vs. Pay TV Battle Heats&nbsp;Up</a></li><li><a href="http://pro.gigaom.com/2011/04/smart-grid-apps-six-trends-that-will-shape-grid-evolution/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=350233+apple-will-zap-mac-defender-malware-with-update&utm_content=etherin">Smart Grid Apps: Six Trends That Will Shape Grid&nbsp;Evolution</a></li></ul><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=350233&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/apple-will-zap-mac-defender-malware-with-update/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	 <go:thumbnail>http://gigaom2.files.wordpress.com/2011/05/mac-defender-alerts.png?w=130</go:thumbnail> 
		<media:thumbnail url="http://gigaom2.files.wordpress.com/2011/05/mac-defender-alerts.png?w=210" />
		<media:content url="http://gigaom2.files.wordpress.com/2011/05/mac-defender-alerts.png?w=210" medium="image">
			<media:title type="html">mac-defender-alerts</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/188039e12983eb749171a75cfd01378d?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">etherin</media:title>
		</media:content>

		<media:content url="http://gigaom2.files.wordpress.com/2011/05/mac-defender-alerts.png?w=300" medium="image">
			<media:title type="html">mac-defender-alerts</media:title>
		</media:content>
	</item>
		<item>
		<title>Mac Malware and the App Store Coming of Age</title>
		<link>http://gigaom.com/apple/mac-malware-and-the-app-store-coming-of-age/</link>
		<comments>http://gigaom.com/apple/mac-malware-and-the-app-store-coming-of-age/#comments</comments>
		<pubDate>Tue, 24 May 2011 17:10:44 +0000</pubDate>
		<dc:creator>Dave Greenbaum</dc:creator>
				<category><![CDATA[Mac]]></category>
		<category><![CDATA[Mac App Store]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[os x]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://gigaom.com/?p=348727</guid>
		<description><![CDATA[MacDefender is the latest, and arguably the most significant Mac malware threat we've seen in a long time. Apple support reportedly isn't offering help over the phone to affected customers, but doing so could set a costly precedent, and there's arguably a better solution available long-term.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=348727&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div id="attachment_349869" class="wp-caption alignright" style="width: 310px"><img  title="mac-defender" src="http://gigaom2.files.wordpress.com/2011/05/mac-defender.png?w=300&h=200" alt="A partial screen from Mac Defender: Not something you want to see on your Mac." width="300" height="200" class="size-medium wp-image-349869" /><p class="wp-caption-text">A partial screen from Mac Defender: Not something you want to see on your Mac.</p></div>
<p>Although there has been scattered mac malware in the past, most malware to date have been proofs of concept or have piggybacked on illegal downloads. New malware program <a href="http://blog.intego.com/2011/05/02/intego-security-memo-macdefender-fake-antivirus/">Mac Defender</a> is a brilliant piece of social engineering that plays on fear of viruses and convinces the owner to pay money for removal of non-existent problems. Although Microsoft and PC manufacturers will help owners with malware problems (sometimes for an additional charge), AppleCare techs and Geniuses are currently <a href="//www.zdnet.com/blog/bott/an-applecare-support-rep-talks-mac-malware-is-getting-worse/3342">refusing to assist or even acknowledge the problem</a> according to reports. There’s actually a very logical justification for this.</p>
<p>It’s not about denying that Mac malware exists altogether. Apple has never actually denied that Macs get malware, but it hasn&#8217;t ever really sounded the alarm bell, either. Apple did include a copy of the anti-virus app Virex with .Mac subscriptions up until June of 2005, however. Apple in the past has also suggested anti-malware software, but now touts the Mac&#8217;s immunity to PC-based malware thanks to Snow Leopard’s robust <a href="http://www.apple.com/macosx/security">security</a>, stating only that “antivirus software may offer additional protection.&#8221; They do include some protection each time an OS update comes out, by patching any exploits previous malware took advantage of.</p>
<p>Mac Defender&#8217;s (a.k.a. MacProtector, but not to be confused with MacKeeper, which is a legitimate program) attack vector is unique on the Mac platform. While Windows users are familiar with fake programs that claim your computer is infected and then offer to remove said infection, Mac Defender’s reach will grow exponentially because Mac users aren&#8217;t as used to that strategy. While Apple can build in protection against this in the next software update, the success of MacDefender will serve as an example for the next slew of threats on the Mac.</p>
<p>Yes, the technically savvy are unlikely to fall for such threats. However, a large number of Mac users aren’t always technically savvy enough to read blogs and support forums. These are the customers more likely to call AppleCare and Apple Geniuses when they have technical problems rather than solve it themselves. Since Mac Defender is extremely easy to remove, reps are spending more time explaining why they can’t help users with malware rather than just explaining how to remove it.</p>
<p>Apple&#8217;s blind eye in this case is less about resource allocation in the short-term, and more about promoting the App Store as a safe software distribution channel so as to avoid a compounding of the time cost problem in the future. There&#8217;s some evidence that in a few cases, the <a href="http://www.pcworld.com/businesscenter/article/228240/mac_app_stores_slow_updates_expose_users_to_security_risks.html">Mac App Store can actually make Macs more vulnerable to attack</a>, but so far that only applies with Opera, which is a web browser, and therefore susceptible to unique vectors of attack.</p>
<p>If consumers fear the threat of rogue software infecting their Macs, they can either buy the line of anti-virus makers and install protection that they then have to manage and invest in themselves, or they can take refuge behind the protective walls of Apple&#8217;s Mac App Store. Independent developers who&#8217;d rather deal directly with customers than go through Apple&#8217;s marketplace may not like the idea, but customers who to take Mac security for granted will increasingly use the App Store to avoid headaches like those provided by Mac Defender.</p>
<p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=348727+mac-malware-and-the-app-store-coming-of-age&utm_content=calldrdave">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2011/05/the-structure-50-the-top-50-cloud-innovators/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=348727+mac-malware-and-the-app-store-coming-of-age&utm_content=calldrdave">The Structure 50: The Top 50 Cloud&nbsp;Innovators</a></li><li><a href="http://pro.gigaom.com/2011/05/californias-new-energy-data-privacy-rules-some-answers-many-questions/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=348727+mac-malware-and-the-app-store-coming-of-age&utm_content=calldrdave">California&#8217;s New Energy Data Privacy Rules: Some Answers, Many&nbsp;Questions</a></li><li><a href="http://pro.gigaom.com/2011/05/players-and-strategies-for-real-time-in-stream-advertising/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=348727+mac-malware-and-the-app-store-coming-of-age&utm_content=calldrdave">Players and Strategies for Real-Time In-Stream&nbsp;Advertising</a></li></ul><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=348727&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/mac-malware-and-the-app-store-coming-of-age/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	 <go:thumbnail>http://gigaom2.files.wordpress.com/2011/05/mac-defender.png?w=130</go:thumbnail> 
		<media:thumbnail url="http://gigaom2.files.wordpress.com/2011/05/mac-defender.png?w=210" />
		<media:content url="http://gigaom2.files.wordpress.com/2011/05/mac-defender.png?w=210" medium="image">
			<media:title type="html">mac-defender</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/73eda5544ca42cec589784b7be68b664?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">calldrdave</media:title>
		</media:content>

		<media:content url="http://gigaom2.files.wordpress.com/2011/05/mac-defender.png?w=300" medium="image">
			<media:title type="html">mac-defender</media:title>
		</media:content>
	</item>
		<item>
		<title>As iPad Popularity Grows, So Does Its Hacker Appeal</title>
		<link>http://gigaom.com/apple/as-ipad-popularity-grows-so-does-its-hacker-appeal/</link>
		<comments>http://gigaom.com/apple/as-ipad-popularity-grows-so-does-its-hacker-appeal/#comments</comments>
		<pubDate>Tue, 27 Apr 2010 19:00:59 +0000</pubDate>
		<dc:creator>Darrell Etherington</dc:creator>
				<category><![CDATA[iPhone, iPod, iPad]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[iPad]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://theappleblog.com/?p=44816</guid>
		<description><![CDATA[The iPad has been a pretty big success so far, especially for a category-busting product. But investors and Apple users aren't the only ones to have taken note of the product's success.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=174183&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img  title="iPad" src="http://gigapple.files.wordpress.com/2010/04/ipadheroshot.png?w=393&h=209" alt="" width="393" height="209" class=" alignleft" />Apple&#8217;s impressive growth as a company is a good thing for end users in a number of ways. Apple has more money to spend on innovative new product designs, for example, and its easier to get service and support for your products, not to mention software and accessories.</p>
<p>The iPad has been a pretty big success so far, especially for a category-busting product. But investors and Apple users aren&#8217;t the only ones to have taken note of the product&#8217;s success. The iPad is now being <a href="http://www.informationweek.com/news/security/vulnerabilities/showArticle.jhtml?articleID=224600439" target="_self">used as scam bait</a> to sucker in people who might not be that familiar with the warning signs of internet scams, which, not coincidentally, is just who the iPad seems directed at as a device.</p>
<p>So far, the scam only works on Windows PCs, but even if you&#8217;re a Mac-using iPad owner, make sure any friends and relatives using the other platform are aware of the ruse. Basically, you get an email telling you that iTunes needs to be updated in order to update your iPad device, and provides a link to the software in question.</p>
<p>Of course, instead of taking you to some kind of iTunes download, the link instead opens up a direct line to their sensitive information, if accessed via a PC. Specifically, the malware in question is Backdoor.Bifrose.AADY, which uses Internet Explorer to open a back door on your system and look around for software serial numbers and login data, including usernames and passwords for various sites.</p>
<p>People on Macs or other Apple platforms, like the iPad and iPhone, won&#8217;t be affected at all by following the link, but obviously it&#8217;s never a good idea to open suspicious links in emails in case that changes in future versions of the scam.</p>
<p>At least for now, the iPad itself hasn&#8217;t been a target for hackers and/or malicious code. Apple&#8217;s securely locked down content distribution system in the form of the App Store really helps things there, but it&#8217;s only a matter of time before it becomes a target in a big way, and this attack is the first sign of why that&#8217;s a dangerous prospect. You&#8217;ve no doubt seen the articles about people picking up the iPad as their first ever computer. That category of user is the ideal candidate for malicious software, since they&#8217;ve yet to experience the nasty side of the Internet and don&#8217;t have any built-in defenses against these types of scams.</p>
<p>The iPad is raising Apple&#8217;s profile, and that means trouble for those uneducated about Internet security risks. It could also mean problems for all Mac users in the long run, as the iPad draws more people to OS X in the same way the iPod and iPhone did before it. But for now, it&#8217;s still the most secure platform around, so enjoy it while it lasts.</p>
<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=174183&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/as-ipad-popularity-grows-so-does-its-hacker-appeal/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
	 <go:thumbnail>http://gigapple.files.wordpress.com/2010/04/ipad_large_thumb.png?w=130</go:thumbnail> 
		<media:thumbnail url="http://gigapple.files.wordpress.com/2010/04/ipad_large_thumb.png?w=210" />
		<media:content url="http://gigapple.files.wordpress.com/2010/04/ipad_large_thumb.png?w=210" medium="image">
			<media:title type="html">ipad_large_thumb</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/188039e12983eb749171a75cfd01378d?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">etherin</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2010/04/ipadheroshot.png" medium="image">
			<media:title type="html">iPad</media:title>
		</media:content>
	</item>
		<item>
		<title>10.6.3 is Imminent…Maybe the Malware&#8217;s Not Far Behind?</title>
		<link>http://gigaom.com/apple/10-6-3-is-imminent%e2%80%a6maybe-the-malwares-not-far-behind/</link>
		<comments>http://gigaom.com/apple/10-6-3-is-imminent%e2%80%a6maybe-the-malwares-not-far-behind/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 14:11:17 +0000</pubDate>
		<dc:creator>Liam Cassidy</dc:creator>
				<category><![CDATA[Apps]]></category>
		<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[10.6.3]]></category>
		<category><![CDATA[Mac OS X]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://theappleblog.com/?p=42682</guid>
		<description><![CDATA[It looks like we’re getting close to the official release of 10.6.3, the latest update to Mac OS X Snow Leopard &#8212; and, from what we’re hearing on the developer grapevine, it might prove to be the most extensive Snow Leopard update yet. TUAW reported on [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=174070&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img  src="http://juicebox.theappleblog.com/e/ff8527ace79a7766.jpg/d" alt="" width="195" height="200" class=" alignleft" /></p>
<p class="excerpt">It looks like we’re getting close to the official release of 10.6.3, the latest update to Mac OS X Snow Leopard &#8212; and, from what we’re hearing on the developer grapevine, it might prove to be the most extensive Snow Leopard update yet.</p>
<p>TUAW <a href="http://www.tuaw.com/2010/03/19/mac-os-x-10-6-3-imminent/">reported</a> on Friday that the latest build of 10.6.3 (known as 10D572, for those of you paying <em>obsessively</em>-close attention) was seeded to developers only two days after a previous build. Typically, ever-shortening intervals between build seeds indicates imminent release to the public. TUAW describes the latest build as focusing on “Graphics Drivers, Quicktime, Images &amp; Photos, Mail, and Security Certificates.”</p>
<p>Oh, what’s that? Want more details? OK, here’s the full rundown of features and fixes we can expect in 10.6.3;</p>
<ul>
<li>Compatibility issues with OpenGL-based applications</li>
<li>Performance improvements for 64-bit Logic</li>
<li>Changes to QuickTime X that increase reliability and improve compatibility and security</li>
<li>Printing reliability and compatibility with third-party printers</li>
<li>Issues resolved that prevented files from copying to Windows shares</li>
<li>Issues resolved with recurring events in iCal when connected to an Exchange server</li>
<li>Issues resolved that prevented files with the &#8220;#&#8221; or &#8220;&amp;&#8221; symbols in their names from opening in Rosetta</li>
<li>Issues addressed that caused background message colors to display incorrectly in Mail when scrolling</li>
<li>Issue resolved that caused machines using BTMM and the Bonjour Sleep Proxy to wake unexpectedly</li>
</ul>
<p>OK, as far as lists go, this one’s not not very exciting, I know. But, what if you fired-up Software Update and were offered the latest pre-release version of 10.6.3? Would <em>that</em> excite you? <span id="more-174070"></span></p>
<h3>Update Snafu</h3>
<p>According to TUAW’s Michael Grothaus, this is exactly what <a href="http://www.tuaw.com/2010/03/19/cool-weird-stuff-tuaw-reader-accidentally-downloads-10-6-3-pre/">happened</a> to one Mac owner last week. They don’t name him, probably to save him the email-avalanche from other Mac owners &#8212; not to mention the inevitable Cease &amp; Desist order from Apple (you just <em>know</em> Apple would bully the poor chap into silence, right?) but they do offer up this tantalizing screengrab of the autoupdate snafu:</p>
<div id="attachment_42703" class="wp-caption aligncenter" style="width: 570px"><a rel="attachment wp-att-42703" href="http://gigaom.com/apple/10-6-3-is-imminent%e2%80%a6maybe-the-malwares-not-far-behind/prerelease-osx/"><img  title="prerelease osx" src="http://gigapple.files.wordpress.com/2010/03/prerelease-osx.png?w=560&h=173" alt="" width="560" height="173" class=" alignleft" /></a><p class="wp-caption-text">Image courtesy of TUAW</p></div>
<p>Grothaus writes that the update “…weighs in at a whopping 1.19GB” and, at that size, I’m happy to wait until Apple has finished tweaking (and trimming) the code!</p>
<h3>Security</h3>
<p>But the thing I’m most interested in is whether 10.6.3 addresses the alleged boat-load of security exploits identified by hacker extraordinaire and security expert Charlie Miller. At this week’s CanSecWest security conference, Miller will discuss how he discovered them (all 20 of them) via a process known as ‘fuzzing’. His presentation is subtitled “An analysis of fuzzing 4 products with 5 lines of Python” and, according to security website <a href="http://www.h-online.com/security/news/item/Mac-OS-X-safer-but-less-secure-Update-957981.html">h-online.com</a>, those 4 products are all made by Apple;</p>
<blockquote><p>In cracking competitions, it is regularly the Apple systems which are cracked first by attackers. Miller has argued for some time that Mac OS X is among the comparatively insecure operating systems. Apple users are currently &#8220;safer, but less secure.</p>
<p>&#8220;Mac OS X is like living in a farmhouse in the country with no locks, and Windows is living in a house with bars on the windows in the bad part of town.&#8221;</p></blockquote>
<p>Miller said that the 20 exploits are all contained in closed-source Apple products, but pointed out that exploits could be found throughout Mac OS X due to bugs in many popular applications from different vendors;</p>
<blockquote><p>OS X has a large attack surface consisting of open source components (i.e. webkit, libz, etc), closed source 3rd party components (Flash), and closed source Apple components (Preview, mdnsresponder, etc). Bugs in any of these types of components can lead to remote compromise.</p></blockquote>
<h3>Sooner, <em>Not</em> Later</h3>
<p>It seems not a keynote goes by without Steve Jobs showing us one of his shareholder-and-media-friendly line charts illustrating Macintosh sales. You know the ones, always trending up-and-to-the-right. Apple is clearly proud the Mac is selling better than ever (in a <a href="http://gigaom.com/apple/apple-conference-call-maybe-just-maybe-cheaper-macs/">conference call</a> in late 2009, Apple announced that, for 19 out of the previous 20 quarters, the Mac grew faster than the rest of the market!)</p>
<p>Statements from Apple regarding sales are always kinda <em>tricky</em>; they’re usually vague enough to allow pretty much <em>any</em> positive interpretation but, for the most part, we can at least agree that the Mac has been enjoying fantastic growth. The old days of ‘security by obscurity’ are drawing to a close. Sooner, <em>not</em> later, Mac-specific malware will come. (You know, the <em>real</em> malware of Windows-exploit proportions!)</p>
<p>Miller says that “… in their minds, [Mac owners] don&#8217;t have a security problem until it affects their bottom line, which hasn&#8217;t been the case, yet.&#8221; And that ‘yet’ is the <em>real</em> issue here. Mac OS X 10.6.3 probably addresses <em>some</em> vulnerabilities &#8212; we can expect at least that much &#8212; but I wonder how obsessively Apple focuses on the security of its venerable OS, and, whatever its actual efforts, is it enough? Can Apple do what Microsoft <em>still</em> struggles to produce; a user-friendly, <em>user-proof</em> OS that isn&#8217;t riddled with vulnerabilities?</p>
<p>Every update to Mac OS X reminds me that the days of security-indifference amongst Mac owners are well and truly numbered.</p>
<p>Tell me I’m worried for no good reason, or scream at me and call me a moron for not already using security software, in the comments below.</p>
<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=174070&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/10-6-3-is-imminent%e2%80%a6maybe-the-malwares-not-far-behind/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
	 <go:thumbnail>http://gigapple.files.wordpress.com/2010/03/snowleopard_thumb.jpg?w=130</go:thumbnail> 
		<media:thumbnail url="http://gigapple.files.wordpress.com/2010/03/snowleopard_thumb.jpg?w=210" />
		<media:content url="http://gigapple.files.wordpress.com/2010/03/snowleopard_thumb.jpg?w=210" medium="image">
			<media:title type="html">snowleopard_thumb</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/84ffab8ffeac6bfee20144c0e9f0fe42?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">limalicas</media:title>
		</media:content>

		<media:content url="http://juicebox.theappleblog.com/e/ff8527ace79a7766.jpg/d" medium="image" />

		<media:content url="http://gigapple.files.wordpress.com/2010/03/prerelease-osx.png" medium="image">
			<media:title type="html">prerelease osx</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;ikee&#8221; iPhone Worm Progeny Not So Harmless</title>
		<link>http://gigaom.com/apple/ikee-iphone-worm-progeny-not-so-harmless/</link>
		<comments>http://gigaom.com/apple/ikee-iphone-worm-progeny-not-so-harmless/#comments</comments>
		<pubDate>Thu, 12 Nov 2009 16:45:51 +0000</pubDate>
		<dc:creator>Darrell Etherington</dc:creator>
				<category><![CDATA[hardware]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[jailbreak]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ssh]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://theappleblog.com/?p=35657</guid>
		<description><![CDATA[Earlier this week, we reported that the first iPhone worm had been created. It was called &#8220;ikee,&#8221; and all it did was change the default wallpaper on devices to an image of Rick Astley with &#8220;ikee is never going to give you up&#8221; printed across the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=173620&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p class="excerpt"><img  title="iphone-malware" src="http://gigapple.files.wordpress.com/2009/11/iphone-malware.jpg?w=147&h=201" alt="iphone-malware" width="147" height="201" class=" alignleft" />Earlier this week, <a href="http://gigaom.com/apple/jailbreakers-first-iphone-worm-discovered-features-rick-astley/" target="_self">we reported</a> that the first iPhone worm had been created. It was called &#8220;ikee,&#8221; and all it did was change the default wallpaper on devices to an image of Rick Astley with &#8220;ikee is never going to give you up&#8221; printed across the top. It was relatively harmless, if annoying, and the hacker responsible claimed that it was more of a warning than anything else.</p>
<p>Hopefully many heeded that warning, since now a new virus has surfaced that uses the same M.O. as ikee, but that has a much more malicious intent and effect. Specifically, the new malware mines personal data from your device, using the very same exploit ikee revealed earlier in the week. <span id="more-173620"></span></p>
<p>The new worm, dubbed &#8220;iPhone/Privacy.A&#8221; by <a href="http://www.intego.com/news/hacker-tool-copies-personal-info-from-iphones.asp" target="_self">digital security firm Intego</a>, affects only jailbroken iPhones, and grabs things from your device like address book contacts, text messages, photos, music, video, calendar entries and email messages. Basically, almost anywhere it can look for sensitive data, it will. The virus doesn&#8217;t seem to be able to access information stored by other applications on your iPhone, like password managers, but if you&#8217;re affected, the only safe course of action is a full wipe and restore.</p>
<p>Theoretically, according to iPhone security researcher Charlie Miller speaking to <a href="http://www.computerworld.com/s/article/9140699/Hackers_pillage_jailbroken_iPhones?taxonomyId=17" target="_self">Computerworld</a>, attacks based on the same exploit could do more than just mine data. Running up your phone bill, sending out bulk text messages and spamming your contacts are all well within the realm of possibility. Miller goes on to describe how easy it would be for a hacker to infect a device:</p>
<blockquote><p>This could easily be installed on a computer on display in a retail store, which could then scan all iPhones that pass within the reach of its network. Or a hacker could sit in an Internet café and let his computer scan all iPhones that come within the range of the Wi-Fi network in search of data.</p></blockquote>
<p>In order to secure your device against this kind of attack, there are a few options. First, change the default SSH password if you haven&#8217;t already. So far, that appears to be the easiest way to foil attempts to infiltrate your jailbroken device. The best way to prevent this and any kind of future attack along the same lines, however, is to not jailbreak your device in the first place, or to restore it to factory settings if you&#8217;ve already jailbroken. Of course, for many who use their devices with carriers who don&#8217;t officially offer the iPhone, that isn&#8217;t an option.</p>
<p>Miller suggested that Apple may want to consider re-engineering its security measures to account for jailbroken devices, but as that would mean tacitly acknowledging and even accepting a practice it stridently disapproves of, I think the best bet for jailbreakers is just to shut down all SSH access, if possible.</p>
<p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=173620+ikee-iphone-worm-progeny-not-so-harmless&utm_content=etherin">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2011/01/mobile-q4-all-eyes-were-on-android-4g-and-the-rising-tablet-tide/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=173620+ikee-iphone-worm-progeny-not-so-harmless&utm_content=etherin">Mobile Q4: All Eyes Were on Android, 4G and the Rising Tablet&nbsp;Tide</a></li><li><a href="http://pro.gigaom.com/2010/12/report-a-mobile-video-market-overview/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=173620+ikee-iphone-worm-progeny-not-so-harmless&utm_content=etherin">Report: A Mobile Video Market&nbsp;Overview</a></li><li><a href="http://pro.gigaom.com/2010/10/in-q3-the-tablet-and-4g-were-the-big-stories/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=173620+ikee-iphone-worm-progeny-not-so-harmless&utm_content=etherin">In Q3, the Tablet and 4G Were the Big&nbsp;Stories</a></li></ul><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=173620&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/ikee-iphone-worm-progeny-not-so-harmless/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/188039e12983eb749171a75cfd01378d?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">etherin</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2009/11/iphone-malware.jpg?w=220" medium="image">
			<media:title type="html">iphone-malware</media:title>
		</media:content>
	</item>
		<item>
		<title>There&#8217;s a Bounty On Your Mac: 43 Cents Per Malware Infection</title>
		<link>http://gigaom.com/apple/theres-a-bounty-on-your-mac-43-cents-per-malware-infection/</link>
		<comments>http://gigaom.com/apple/theres-a-bounty-on-your-mac-43-cents-per-malware-infection/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 15:00:24 +0000</pubDate>
		<dc:creator>Darrell Etherington</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[affiliate program]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[infection]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://theappleblog.com/?p=33085</guid>
		<description><![CDATA[Think affiliate programs are solely the province of SEO firms and experts? Think again. There&#8217;s such a thing as a malware affiliate program, and a very recent one targets Mac users specifically. It&#8217;s a sign that cyber-crime is beginning to target Apple more aggressively than it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=173415&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p class="excerpt"><img  title="security_shield" src="http://gigapple.files.wordpress.com/2009/07/security_shield.png?w=123&h=149" alt="security_shield" width="123" height="149" class=" alignleft" />Think affiliate programs are solely the province of SEO firms and experts? Think again. There&#8217;s such a thing as a malware affiliate program, and a very recent one targets Mac users specifically. It&#8217;s a sign that cyber-crime is beginning to target Apple more aggressively than it has in the past.</p>
<p><a href="http://blogs.zdnet.com/security/?p=4451" target="_self">ZDNet.com</a> reports that a group called the &#8220;<a href="http://www.virusbtn.com/conference/vb2009/abstracts/Samosseiko.xml" target="_self">Partnerka</a>,&#8221; which consists of Russian spam and malware affiliates, have begun to focus on the Mac. Their tactics involve using social engineering tricks (read: preying on human weakness) to install fake codecs and scareware programs (the kind that pressure you into installing and paying for bogus single purpose anti-malware software). <span id="more-173415"></span></p>
<p>The plans and methods of the &#8220;Partnerka&#8221; were revealed at the <a href="http://www.virusbtn.com/conference/vb2009/index" target="_self">Virus Bulletin Conference 2009</a>, where Sophos Labs researcher Dmitry Samosseikko talked about a site called Mac-codec.com which has since been taken down, that offered a bounty of 43 cents for each successful installation of malicious software on a Mac computer. According to Samosseikko, that&#8217;s a high price, and indicates that the Mac malware game is becoming more attractive to online crime organizations.</p>
<p>Even though the site is gone, the threat is not. These malware schemes work because they offer something many Mac users might be looking for. Partnerka&#8217;s Mac-codec.com was offering video players and fake video codecs that attempt to draw in people trying to playback video they&#8217;ve downloaded somewhere on the web. Previous DNS-changing trojan malware attempts depended on porn video lures.</p>
<p>Focus on the Mac platform might be growing for online criminals, but most malware plots still require you to make the first move. To help protect yourself from fake and harmful codecs, use <a href="http://perian.org/" target="_self">Perian</a> and <a href="http://www.videolan.org/vlc/" target="_self">VLC</a>, and if your video still won&#8217;t play back, just give up altogether. No video content is worth the theft of your private data, after all.</p>
<p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=173415+theres-a-bounty-on-your-mac-43-cents-per-malware-infection&utm_content=etherin">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2011/03/why-ipad-2-will-lead-consumers-into-the-post-pc-era/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=173415+theres-a-bounty-on-your-mac-43-cents-per-malware-infection&utm_content=etherin">Why iPad 2 Will Lead Consumers Into the Post-PC&nbsp;Era</a></li><li><a href="http://pro.gigaom.com/2011/03/the-near-term-evolution-of-social-commerce/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=173415+theres-a-bounty-on-your-mac-43-cents-per-malware-infection&utm_content=etherin">The Near-Term Evolution of Social&nbsp;Commerce</a></li><li><a href="http://pro.gigaom.com/2011/02/what-googles-honeycomb-means-for-apple-and-microsoft/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=173415+theres-a-bounty-on-your-mac-43-cents-per-malware-infection&utm_content=etherin">What Google&#8217;s Honeycomb Means for Apple and&nbsp;Microsoft</a></li></ul><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=173415&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/theres-a-bounty-on-your-mac-43-cents-per-malware-infection/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/188039e12983eb749171a75cfd01378d?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">etherin</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2009/07/security_shield.png" medium="image">
			<media:title type="html">security_shield</media:title>
		</media:content>
	</item>
		<item>
		<title>Snow Leopard Malware Targets Apple Users</title>
		<link>http://gigaom.com/apple/apple-users-targeted-with-snow-leopard-malware/</link>
		<comments>http://gigaom.com/apple/apple-users-targeted-with-snow-leopard-malware/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 15:26:02 +0000</pubDate>
		<dc:creator>Darrell Etherington</dc:creator>
				<category><![CDATA[CNN Big Tech]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[NYT Company News]]></category>
		<category><![CDATA[SYN Analysis]]></category>
		<category><![CDATA[10.6]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[os x]]></category>
		<category><![CDATA[Snow Leopard]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://theappleblog.com/?p=31808</guid>
		<description><![CDATA[Not that any TheAppleBlog readers would ever try to acquire software in a less-than-legal manner, but just in case you know someone who would, tell them to watch out for web sites claiming to bear Snow Leopard gifts. Like the Adobe Photoshop CS4 and iWork &#8217;09 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=173314&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img  title="trojan" src="http://gigapple.files.wordpress.com/2009/09/trojan.jpg?w=180&h=240" alt="trojan" width="180" height="240" class=" alignleft" /></p>
<p class="excerpt">Not that any TheAppleBlog readers would ever try to acquire software in a less-than-legal manner, but just in case you know someone who would, tell them to watch out for web sites claiming to bear Snow Leopard gifts.</p>
<p>Like the Adobe Photoshop CS4 and iWork &#8217;09 before it, Snow Leopard now has a <a href="http://www.techwatch.co.uk/2009/09/01/fake-snow-leopard-sites-warning/" target="_self">super-special malware edition</a> floating around the web. It&#8217;s a classic software honeypot scheme: You find a site advertising a free Snow Leopard upgrade, download a disk image file (.DMG), and it unleashes its trojan payload. <span id="more-173314"></span></p>
<p>Trend Micro is advising folks to avoid any and all sites advertising free Snow Leopard upgrades, since what you actually get is a new variant of the DNS charger trojan known as OSX_JAHLAV.K. The Apple-specific malware, once it makes itself at home on your computer, will redirect your Internet browser to phishing sites and malware-infected web sites. OSX_JAHLAV.K has a particularly nasty trick up its sleeve &#8212; it sends you to a site that advertises fake antivirus software that will notify you that you have an infection until you pay to register and have it removed.</p>
<p>Trend Micro&#8217;s advice is to pick up its Smart Surfing for Mac malicious URL-blocking software, which will cost you $50 a year in subscription fees. My advice is to think long and hard about how much you&#8217;re willing to pay down the road just to avoid spending $29 upfront for the 10.6 upgrade.</p>
<p>No doubt this will give antivirus companies cause to raise the red flags once more, and <a href="http://gigaom.com/apple/more-mac-viruses-similar-sources-time-to-worry/" target="_self">spout on</a> about how <a href="http://gigaom.com/apple/security-exaggeration-or-real-threat-is-this-the-end-of-an-apple-era/" target="_self">the end is nigh</a> for the days of OS X being the secure choice, but as before, smart browsing and downloading policies are still your best bet for a happy, safe Mac.</p>
<p><em>Photo courtesy of Flickr user <a href="http://www.flickr.com/photos/darcym/" target="_self">Darcy McCarty</a>.</em></p>
<p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=173314+apple-users-targeted-with-snow-leopard-malware&utm_content=etherin">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2011/03/why-ipad-2-will-lead-consumers-into-the-post-pc-era/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=173314+apple-users-targeted-with-snow-leopard-malware&utm_content=etherin">Why iPad 2 Will Lead Consumers Into the Post-PC&nbsp;Era</a></li><li><a href="http://pro.gigaom.com/2011/03/the-near-term-evolution-of-social-commerce/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=173314+apple-users-targeted-with-snow-leopard-malware&utm_content=etherin">The Near-Term Evolution of Social&nbsp;Commerce</a></li><li><a href="http://pro.gigaom.com/2011/02/content-farms-the-players-the-benefits-the-risks/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=173314+apple-users-targeted-with-snow-leopard-malware&utm_content=etherin">Content Farms: The Players, The Benefits, The&nbsp;Risks</a></li></ul><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=173314&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/apple-users-targeted-with-snow-leopard-malware/feed/</wfw:commentRss>
		<slash:comments>34</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/188039e12983eb749171a75cfd01378d?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">etherin</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2009/09/trojan.jpg" medium="image">
			<media:title type="html">trojan</media:title>
		</media:content>
	</item>
		<item>
		<title>iPhone OS 3.0.1 Released, Fixes SMS Exploit</title>
		<link>http://gigaom.com/apple/iphone-os-3-0-1-released-fixes-sms-exploit/</link>
		<comments>http://gigaom.com/apple/iphone-os-3-0-1-released-fixes-sms-exploit/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 18:58:36 +0000</pubDate>
		<dc:creator>Charles Jade</dc:creator>
				<category><![CDATA[CNN Mobile]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[NYT Company News]]></category>
		<category><![CDATA[SYN Straight News]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Software Update]]></category>

		<guid isPermaLink="false">http://theappleblog.com/?p=29819</guid>
		<description><![CDATA[Days after the SMS vulnerability was reported, in which a single character could be used to crash or even take over an iPhone, Apple has released a single-purpose update. The Knowledgebase Article makes it sound as potentially bad as it is. Impact: Receiving a maliciously crafted [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=173171&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p class="excerpt">Days after the <a href="http://gigaom.com/apple/unusual-character-hack-may-put-all-iphones-in-peril/">SMS vulnerability</a> was reported, in which a single character could be used to crash or even take over an iPhone, Apple has released a single-purpose update.</p>
<p><img  title="iphoneos_301" src="http://gigapple.files.wordpress.com/2009/07/iphoneos_301.jpg?w=499&h=343" alt="iphoneos_301" width="499" height="343" class=" alignleft" /></p>
<p>The <a href="http://support.apple.com/kb/HT3754">Knowledgebase Article</a> makes it sound as potentially bad as it is.</p>
<blockquote><p>Impact: Receiving a maliciously crafted SMS message may lead to an unexpected service interruption or arbitrary code execution</p>
<p>Description: A memory corruption issue exists in the decoding of SMS messages. Receiving a maliciously crafted SMS message may lead to an unexpected service interruption or arbitrary code execution. This update addresses the issue through improved error handling. Credit to Charlie Miller of Independent Security Evaluators, and Collin Mulliner of Fraunhofer SIT for reporting this issue.</p></blockquote>
<p>All iPhones were vulnerable to attack, regardless of OS version. The only defense <span style="text-decoration: line-through;">from having your personality rewritten or being possessed by a ghost</span> was to shut the phone off, which was hardly practicable. While it&#8217;s always nice to see Apple give credit to the those who discover an exploit, it&#8217;s unfortunate it took the researchers going public to get the company to move on this issue.</p>
<p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=173171+iphone-os-3-0-1-released-fixes-sms-exploit&utm_content=charlesjade">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2011/01/mobile-q4-all-eyes-were-on-android-4g-and-the-rising-tablet-tide/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=173171+iphone-os-3-0-1-released-fixes-sms-exploit&utm_content=charlesjade">Mobile Q4: All Eyes Were on Android, 4G and the Rising Tablet&nbsp;Tide</a></li><li><a href="http://pro.gigaom.com/2010/12/report-a-mobile-video-market-overview/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=173171+iphone-os-3-0-1-released-fixes-sms-exploit&utm_content=charlesjade">Report: A Mobile Video Market&nbsp;Overview</a></li><li><a href="http://pro.gigaom.com/2010/10/in-q3-the-tablet-and-4g-were-the-big-stories/?utm_source=apple&amp;utm_medium=editorial&amp;utm_campaign=waterfall?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=173171+iphone-os-3-0-1-released-fixes-sms-exploit&utm_content=charlesjade">In Q3, the Tablet and 4G Were the Big&nbsp;Stories</a></li></ul><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&#038;blog=14960843&#038;post=173171&#038;subd=gigaom2&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/iphone-os-3-0-1-released-fixes-sms-exploit/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bdc3550e79fc663c8208a504793eb760?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">Jade</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2009/07/iphoneos_301.jpg" medium="image">
			<media:title type="html">iphoneos_301</media:title>
		</media:content>
	</item>
	</channel>
</rss>
