Lessons for IT, Apple in Flashback brouhaha
It's clear that OS X is now a target of malware purveyors
Computerworld - While the number of Macs infected by the Flashback malware is seemingly in decline now, the security reverberations for Apple continue. The discovery of the botnet a couple of weeks ago -- and Apple's response -- has prompted criticism by IT security pros, concern among Mac users and even some smug told-you-so's from Windows users who've watched for years while Apple and its fans derided the the omnipresent malware issues plaguing PCs.
Security by obscurity, if it ever existed, is no more.
Now that Apple and several third-party software firms have produced detection and removal tools, it's time to take stock of the situation and dig a little deeper. What does the Flashback debacle mean for Mac users, Apple itself and the businesses that have increasingly adopted Macs? And does it affect those with iPads and iPhones?
Just a drop in the bucket
Let's start with a reality check. The only reason this story got the attention it did is because for more than a decade Mac OS X has not been hit hard with any major malware threat. There have been some proof-of-concept pieces written; plenty of Macs have been infected with Microsoft Office macro viruses (that generally have no damaging effects on Macs, especially those running Office 2008, which didn't offer macro support); and there have been a couple of genuine malware alerts that didn't amount to a serious online threat.
A piece of malware like Flashback that targeted Windows PCs would've been a minor story in tech circles that ended with reports of anti-virus companies releasing updated malware definitions, Microsoft releasing a patch for the underlying vulnerability, and possibly a free detection and removal tool being pushed out to users. This is something that happens in the PC world all the time. But not on the Apple side of the equation.
Given the thousands of malware threats facing Windows PCs, this is barely a drop in the bucket. As a result, Apple came under much closer scrutiny than any other major company would have been in similar circumstances.
The good and the bad of Apple's response
Apple may have been subjected to more scrutiny than Microsoft, but there were some telling points in how it handled the situation.
First, the company made the unfortunate choice of trying to shut down the domain used by Dr. Web researchers seeking to determine the extent of the infection. A generous take would be that Apple took a misstep because this is a new experience for it. A more jaundiced view would be that Apple was trying to minimize information about the extent of Flashback infections. (The truth is probably somewhere in between.)
This much is clear: Apple didn't handle the initial situation well.
That said, it quickly released a fix as soon as its engineers could create the patch, made needed corrections immediately after that, and ultimately released tools that would protect uninfected Macs and remove any infections. Apple did this by leveraging its software update infrastructure so that users who regularly agree to accept Apple's Software Update notices were protected -- even if they had never heard of the threat.
Ultimately, the company dealt with the problem in a way that protected the most non-technical of users and did so at no cost to them.
Whether you like Apple or not, the move shows commitment to its users. Sure, it could have issued an initial patch, scheduled a follow-up release later on, and never looked back, but it didn't.
Still, Apple could've been more forthcoming and engaged the security industry more fully. Not doing so was typical of the company's propensity to keep all information to itself until its executives feel comfortable that they have the best solution at hand. Usually, that works to Apple's advantage. Not so this time.
Apple also focused its efforts around current Macs and the most recent releases of OS X. That isn't surprising. The company has been pretty open and consistent in pushing its platform forward and not offering extensive backwards compatibility.
What about security and antivirus companies?
One of the striking parts of this story was that almost none of the security and antivirus vendors offered up a solution much quicker than Apple did. F-Secure, which provided instructions for detecting the malware early on, was the first major security vendor to offer a quarantine and removal tool. Kaspersky and Symantec followed in quick succession. Apple's offering followed them.
- Apple breaks into Fortune 500's top 10
- Apple hijacks OS X devs to keep iOS on track
- Think different: Apple's $17B debt offers stark contrast to 1996's junk bonds
- To give back to investors, Apple goes for massive bond deal
- Yes Siri, no Siri, for the Mac
- Moves, mistakes prove Steve Jobs era at Apple over, say analysts
- Apple's WWDC sells out in under 3 minutes
- Apple CEO defends Mac line; analysts foresee iPad hybrids
- Apple's WWDC set for June 10-14, hints at fall launch of next iPhone
- Mac sales growth stalls -- here's why Apple doesn't care
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Case Study: Hospital Turns to Email Archiving Solution to Ensure Regulatory Compliances Read this case study to learn how a cloud-based email archiving solution enabled the hospital to meet government mandates and helps avoid thousands...
- Case Study: In-the-Cloud Email Service Replaces Three Point Products Read this case study for more information on a comprehensive in-the-cloud email service to help replace three point products.
- What does it take to deliver Security, Privacy and Trust at Mimecast? This whitepaper explains the process and controls that Mimecast put in place to deliver a secure, private and trusted SaaS platform for your...
- Your Data under Siege: Defeating the Enemy of Complexity Even if you have adequate antivirus protection, are there still holes in your IT security armor? Is lack of bandwidth to manage the...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
