Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What Mac Defender malware? The one that affected 0.1% of OS X users?

Not to mention: Mac Defender was a TROJAN. You HAD to install it yourself for it to work.

From Wikipedia: "Mac Defender (also known as Mac Protector, Mac Security,[1]Mac Guard,[2] and Mac Shield)[3] is an internet rogue security program that can be installed by unwitting users of computers running the Mac OS X operating system". The exact same thing can happen to any operating system. You can install malware YOURSELF even in OpenBSD.



Right, which would be rendered pretty ineffective by Gatekeeper, now, at least for people that don't know about the launch-from-disk trick or other workarounds (basically, the same people that would potentially be vulnerable).

Gatekeeper's a small, small step that doesn't add much inconvenience to developers, but it does help a bit and I'm surprised at how long it's taken to arrive at something so basic & logical.


I'd be surprised that people would just turn that feature off pretty quickly after getting a new Mac. There are tons of application out there that aren't sign and aren't malware. People will come to view this feature like the annoying warning about bad SSL certs.


Hm, that's a good point: "warning fatigue" that users get. I hadn't thought about it from that point of view; I guess how fatiguing it is will really depend on how quickly developers in general get aboard the "sign your application" train, so I'd be curious to see the response from the legions of independent Mac software developers that aren't using the App Store for delivery.


...or UAC on Windows Vista/Seven.


Most people don't install tons of apps (and many of those who do use the App Store). It's hard for me to think of seeing that dialogue once a week as onerous and I bet the vast majority of people don't install more than one app a week.


I guess Mac - sorry, OS X - users never install software they didn't mean to or that was misrepresented to them? What a pleasure it must be working with such a vigilant, critically thinking group of users.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: