XML Feeds

.

[maxmsp] Re: [OT] botnets and OSX

Anthony Bisset abisset at dspaudio.com
Sat Dec 1 18:00:43 MST 2007


Over the past 15 years very few worms & viruses have been written for Unix based environments. However, Microslofts Widows environment has and will continue to be a target due to it's poor security architecture (which creates a whole sector of the economy, thanks M$).  

OSX has had a good run. 

If we look at Linux and it's security history, very little in the way of worms or viruses surfaced in the last 10 years and most of these were unsuccessful.

Risk / Exposure / Vulnerability... These are simply factors of time. A large easy to exploit hole in the OSX network implementation will eventually be found by a bad guy and put to use, but how?

A BoT net is unlikely as OSX exploits are rare and security patches could be issued quickly once Apple knew of the problem, so the discoverer would want to utilize his new found power against specific targets for specific reasons in a stealthy way.
Besides, building an army of zombies or onion routers is easy enough using Widows targetted worms.  

Advice?  

- Keep backups

- Know the value of your information both to yourself and others.  Have real perspective not paranoia, and enjoy the occasional leak when if/when it happens... Life is fun.

- Disable unneeded network services, keep your firewall on, use WEP on your wireless access points, use https whenever possible, rotate passwords, use different passwords per each system, avoid spyware looking products, disable GUI scripting languages (Applescript).  

- As far as max patching goes, while unlikely someone could use a max patcher to hack your machine.  If you need to be paranoid, save your max patchers to text, then search for "/bin/bash" or "shell" or other system level commands like applescript stuff, etc.

- Don't buy one of those crappy "secure your computer" adware/malware/spyware unless you really understand what it's doing and that you want that function.

Know your mind, know your body, know your drug

-a+b




More information about the maxmsp mailing list