Does the Mac have an edge against state-sponsored hacking?
IDG News Service - When hackers broke into Google's computer network nearly two years ago, their first step was to take over Microsoft Windows machines running in the company's China offices. Would Google have been better off had those workers been running the Mac?
Not necessarily, according to researchers at iSec Partners, a security consultancy that is part of NCC Group. Speaking at the Black Hat conference in Las Vegas Wednesday, iSec founder Alex Stamos and his team of researchers took a look at the typical stages of the type of intrusion that hit Google -- called an advanced persistent threat (APT) attack -- and compared how the Mac would do versus Windows 7.
Their conclusion: Macs provide good protection against the initial phases of the attack, but once the bad guys are on the network, it's a whole different story. "They're pretty good for [protecting from] remote exploitation," Stamos said. "[But] once you install OS X server you're toast."
The problem is that many of Apple's server protocols -- mDNS, Apple Remote Desktop, the Mac Kerberos authentication, for example -- use weak authentication models that give the attackers ways of getting access to parts of the network that should be blocked. "Every password-based authentication mechanism in OS X has problems," Stamos said.
For example, Mac's Keychain software is vulnerable to what's known as a brute-force attack, he said.
That could be a big problem to a company facing a determined attacker, because it's pretty easy for APT hackers to get a foothold on a desktop, and they have shown that they're willing to do hard work in order to break into a network. Stamos, whose firm investigates hacking incidents, says that it's often easy to trick someone in any company into installing software that they shouldn't -- the first step in an APT attack. "Most people get malware because they intentionally install it," he said. "At an institution of thousands of employees, you have to assume that one of them going to get tricked."
In many APT attacks, the hackers first break into social media accounts belonging to friends of their victims. They mine them for information, and then use these accounts to send very realistic looking messages to people working within the company they want to hit. If they can trick an employee into downloading software or visiting a website laden with attack code, they can get a foothold in the network.
It's the next step -- moving around the network and getting access to corporate secrets -- that's tricky. And that's where Apple is at a disadvantage, according to the iSec research.
- Best iPhone, iPad Business Apps for 2014
- 14 Tech Conventions You Should Attend in 2014
- 10 Desktop Apps to Power Your Windows PC
- How to Add New Job Skills Without Going Back to School
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
Red Hat Enterprise Linux - The Original Cloud Operating System
Linux adoption is growing against a number of measures, such as the
number of supercomputers that run Linux and the size of the contributing...
- OpenStack Hype vs. Reality: CIO Quick Pulse Open-source architecture can enable IT departments to build infrastructure-as-a-service (IaaS) clouds running on standard hardware.
- Future Focus: What's Coming in Enterprise Mobility Management (EMM) Find out why Enterprise Mobility Management (EMM) solutions that are truly future-ready must be designed to enable Machine-to-Machine (M2M) capabilities and much more.
- The CIO's Guide to Enterprise Mobility Management (EMM) This guide will help those making an EMM platform decision make the best choice for their organization.
- Live Webcast Increasing the Value of Your Reports and Dashboards Learn how incorporating other analytical capabilities such as predictive modeling and visualization can increase the value of your reports and dashboards by providing...
- Testimonial: Cystic Fibrosis Trust Peter Hawkins, the Head of IT for Cystic Fibrosis Trust, discusses the role CommVault's Simpana software platform plays in improving the company's information...
- Increasing the Value of Your Reports and Dashboards Learn how incorporating other analytical capabilities such as predictive modeling and visualization can increase the value of your reports and dashboards by providing... All Management White Papers | Webcasts