Friday, May 18, 2012

Apple: Viruses, Bugs And A Shrinking Reputation

They might be the biggest company in the world, but a raft of problems with new products are in danger of spoling the near-flawless reputation Apple has built for itself
With a mini iPad and a large screen, ‘liquid metal’ iPhone out this year, one could easily conclude that Apple – now the world’s largest company – is unstoppable.  But chinks in Apple’s armour are starting to appear and Apple’s customers are getting upset.  Their reputation for innovative design is unmatched but, like Microsoft in the nineties, Apple is now releasing software with bugs in it, hardware that’s faulty and customer service that leaves a lot to be desired.
I bought a new iPhone 4S recently worth £600 (Apple sells the most expensive smartphones) and immediately noticed signal issues.  Sure enough, when I walked around with an older iPhone on the same network side by side,  the signal bars on my new phone were lagging behind.  I was pretty shocked it didn’t work perfectly straight out of the box – given the furore over Apple’s previous iPhone 4 antennae issues and given that the newer phone uniquely actually has twin antennae.
Without a software update just a few days old, the iPhone 4S always favours a 3G signal, even in areas where that signal is sparse (its US centric virtual assistant, Siri, needs 3G to operate).   That’s seven months after the phone was released.   Before that, it was even worse.   For the first five months users were much more likely to get ‘No Service‘ as they couldn’t switch off 3G at all.   Even the Vodafone guy who sold it to me admitted after I returned to the shop, “The iPhone’s great – just not great as a phone.”
That’s not the only reason the iPhone 4S doesn’t always work straight out of the box.  To the consternation of most international travellers who buy local sims and swap them into different phones, Apple decided to introduce the ‘micro-sim’ in its iPhone 4 and 4S.  Unfortunately, the world’s mobile companies haven’t kept pace.  Sims come in 128k, 64k, 32k varieties and global telecom networks are not all using the same system.  iPhone customers with China Mobile are still waiting for a software patch to make their sim cards compatible with the iPhone 4S.  And China Mobile is the world’s largest telecoms company with 650 million subscribers.
Even the Vodafone guy who sold it to me admitted after I returned to the shop, “The iPhone’s great – just not great as a phone.”
China Mobile is too big for Apple to ignore though it has ignored plenty of customers in other countries. In fact, remaining silent is becoming a very common complaint about Apple.
Customers who have recently bought the new iPad are complaining that the device overheats, that the the battery status is not accurate and, most significantly of all, that it continually loses Wifi connectivity.  The Apple internet forums are jammed with complaints – and these forums tend to be where customers find out what’s really going on with Apple products.
Sometimes Apple’s silence can really have a devastated effect.  In April, 600,000 Macs were infected with the Flashback virus, designed to steal their bank passwords. I have a Mac and I get plenty of emails from Apple about their products.  But Apple support advised me not to get anti-virus protection as ‘Macs don’t get viruses’.  Why weren’t all Mac users emailed about this one?  In fact, Apple’s slow response to the virus has angered many IT professionals and almost certainly exacerbated global infection rates, leaving large swathes of users more vulnerable than they should have been.  Expect some lawsuits soon (on top of that just brought by the US government for ebook price fixing).
All this makes the minor bugs look… well, minor.  But when you experience them, it’s very frustrating.  iOS 5 for the iPhone came with a bug affecting battery life (after a long history of iPhone battery issues).  After the latest iPad software update, many users – myself included – had trouble retrieving IMAP emails.  After much internet searching I found that if I manually exit and restart the iPad Mail app it will work again for a while – hardly a great solution.   I have always used my Macbook Pro in clamshell mode (i.e. closed) when plugged into an external monitor.  The latest update prevents it.  And these bugs are not getting fixed or responded to.  Users generally have to wait months for new software updates in the hope that if enough people jam the message boards and forums with complaints, Apple will release the fix.
in a world where reputation is all,  you ignore customers at your peril.
This is all especially bad because Apple built its reputation not just on fine design but also on great customer service, stuff that just works straight out of the box and elegant, bug-free software.  That is no longer the case and in a world where reputation is all,  you ignore customers at your peril.
Finally, what of Apple’s flagship service – the iCloud?  Apple’s vision is a world where all your data, music, film, work etc is no longer on any physical machine.  It’s all stored in the iCloud – accessible as and when you need it – on any device.  Soon that is going to get critical mass and Apple is predicting a post PC world.  But what’s going to happen when something goes wrong.. when the unthinkable happens?  What happens when a virus gets into the iCloud and shuts it down?  If Apple’s flagship service sinks in a titanic global data earthquake, their much vaunted and vital customer loyalty would vanish.  This colossus of a company might well go down for good.

Monday, May 14, 2012

Kaspersky exec calls Mac OS "really vulnerable"

The Macintosh is an impenetrable fortress of malware-free computing, right? In recent years, we’ve certainly seen that image eroded a bit, thanks to a number of nasty outbreaks. And if you listen to Nikolay Grebennikov, the CTO of security software maker Kasperksy, things have the potential to be much worse. The executive told British site Computing that the company was invited to improve Cupertino’s security, only to discover that, “Mac OS is really vulnerable.” Grebennikov also had some rather unfortunate news for all the iPad and iPhone owners out there, telling the site, “Our experience tells us that in the near future, perhaps in a year or so, we will see the first malware targeting iOS.

Monday, May 7, 2012

Apple's OS X Lion Update Has Exposed Encrypted Passwords for Three Months

Face-paw
from securitywatch.com
Last Friday, a security researcher warned Mac users of a programming oversight in Mac OSX 10.7 Lion, that exposed encrypted passwords.

According to an email from David Emery, owner of DIE Consulting in Massachusetts, Apple accidentally left a debug option on in FileVault, OSX’s legacy encryption software.

As a result, the login password of a user who had logged in since the update in early February, was saved in plain text in a log file outside the encrypted area. In other words, anyone with administrator access to your computer—which could be anyone if you never log out of your account—can read the file containing the password, and log into the encrypted part of your disk.

The vulnerability affects FileVault users who upgraded from Snow Leopard (OSX 10.6) to Lion 10.7.3, but did not migrate to FileVault 2, the full-disk encryption software that came with Lion. According to Sophos, it does not appear to affect systems that started with Lion and upgraded to OSX 10.7.3.

"This is worse than it seems, since the log in question can also be read by booting the machine into firewire disk mode and reading it by opening the drive as a disk or by booting the new-with-LION recovery partition and using the available superuser shell to mount the main file system partition and read the file," Emery wrote.

Emery also noted that affected users who’ve also been backing up their data with Time Machine are essentially storing their unencrypted passwords over and over again.

Lion users should immediately activate FileVault 2, which can be found in the Security & Privacy setting in System Preferences. Click the FileVault tab to enable.

And hopefully, after a unacceptable delay in patching a Java vulnerability left hundreds of thousands of OS X users infected with Flashback last month, Apple will patch this three-month-old vuln sooner rather than later.

In late April, Flashback authors tweaked the Trojan's code slightly to elude Apple's legacy anti-malware tool, XProtect. Many security researchers have criticized XProtect for offering insufficient protection, as it relies on exact fingerprints of the malware and can be bypassed with a slight change to malicious code. XProtect was originally released last May as part of Snow Leopard OS X 10.6, in response to weeks of media coverage over another enduring piece of Mac malware called MacDefender.

Thursday, April 26, 2012

University of Iowa Student Macs Hit With Virus


University of Iowa freshman Cailie Furlong was studying online Wednesday — until she was blocked from the UI network.

Her computer, along with around 350 other Mac computers on campus, had been infected with the Flashback virus.

UI Chief Information Security Officer Jane Drews said computers received the virus from an infected website. Once installed, the virus allows its creator to access personal information such as account passwords.

"It's something to take seriously," she said.

Concern has been serious enough for the UI Information Technology Services to block infected Macs from accessing the campus wireless network. The UI's intrusion-detection system detects the Flashback virus — which accesses computers by exploiting a security flaw in Java — by catching the network activity of machines trying to access botnet, a network of hacked computers.

UI freshman Max Dehio also noticed his computer had been blocked Wednesday. He said the university IT services told him it will reformat every infected Mac on campus in order to remove the virus.

Dehio said he was surprised by the block.

"I think the university should send out an email before it kicks you off the network," he said.

Drews said some students with Macs should take precautions by getting the most current operating system — OS10.7 — and running software updates, installing antivirus software, and turning on firewall programs.

Because reformatting deletes everything on a computer, UI computer-science Associate Professor Doug Jones recommended students back up any important information.

"In general, the important thing to do is keep backups of anything that matters to you," he said. "[Because] a good thing to do if your computer does get infected is to wipe everything."

Cases such as the Flashback virus represent a decrease in antivirus effectiveness over the past few years, Jones said — especially for Macs, which are not considered as vulnerable to viruses as PCs.

"It's sort of disturbing that Macintoshes are being targeted now," he said.

Drews said Apple released a software update Tuesday to prevent Mac computers from being infected by the virus. UI ITS is testing the software to see if it clears the virus completely, she said.

If the software is effective, she said, the university will take that approach instead of reformatting and reloading infected computers.

Furlong said UI computer services were able to save all her documents and pictures, but everything else was gone.

"I couldn't do my homework last night," she said. "I couldn't even work in the ITC because it is all saved on my laptop."

Dehio said he completed all of his homework earlier in the week but was still concerned about the virus spreading around end-of-semester deadlines.

"I'm losing the time that I should be studying and researching for my essays," he said.

New Flashback Variant Emerges To Plague Unpatched Macs

from forbes.com
Security firm Intego has discovered a new variant of the Flashback malware, called Flashback.S. This new variant continues to make use of the Java vulnerability that Apple patched earlier this month.

What's different about Flashback.S is that it installs without prompting the user for a password (which the earlier version asked for, but didn’t actually require to install). Flashback.S installs files into the following locations:

~/Library/LaunchAgents/com.java.update.plist
~/.jupdate

After installation, the malware then goes on to delete all files and folders in the ~/Library/Caches/Java/cache folder in order to try to avoid detection.

Interestingly, this malware checks to see if Intego VirusBarrier X6, Apple’s Xcode development platform, or Little Snitch are installed on the Mac. If it finds any one of these programs installed it will abort the installation.

All that’s needed to become infected with this malware is for the Mac user to visit a website serving the malicious code (which are believed to be hacked WordPress blogs) using the Safari browser. It’s that simple. there’s nothing to click on and no password prompt.

Flashback infections are falling, but there are obviously enough Mac users out there who have not applied the Java patch to their system to make it worthwhile for the bad guys to develop and release this new variant.

Don’t be one of those people! If you’ve not done so already, you need to patch your system immediately! The easiest way to do this is to fire up Software Update and bring in all the updates your system needs.

If you’ve already patched your system, congratulations. You’re safe. However, there are still a few steps that you might lie to take to give yourself added protections.

First, I recommend that you download and install antivirus software. Sophos Anti-Virus for Mac Home Edition and ClamXav 2 are both excellent products and won’t set you back a dime. If you’d rather go for a paid-for solution then I suggest that you take a look at Intego’s VirusBarrier X6 or Internet Security Barrier X6.

Then, I recommend disabling Java in your Mac’s web browser. If you don’t use Java – and not many people do nowadays, which is why Apple doesn’t include it with OS X 10.7 ‘Lion’ – then I recommend uninstalling it completely so you get rid of a serious source of vulnerabilities.

Tuesday, April 24, 2012

Flashback Still Plagues Macs


from pcworld.com

Contrary to reports by several security companies, the Flashback botnet is not shrinking, the Russian antivirus firm that first reported the massive infection three weeks ago claims.

Dr. Web, which earlier this month was the first to report the largest-ever successful malware attack against Apple's OS X, said Friday that the pool of Flashback-infected Macs still hovers around the 650,000 mark, and that infections are continuing.
Also on Friday, Liam O Murchu, director of operations at Symantec's security response center, confirmed that Dr. Web's numbers were correct.

Optimism Refuted

Both Dr. Web's tally and its contention that infections are ongoing flew in the face of other antivirus companies' assertions. Kaspersky Lab and Symantec, which have each "sinkholed" select domains -- hijacked them before the hackers could use them to issue orders to compromised machines -- used those domains to count the Macs that try to communicate with the malware's command-and-control centers.

Earlier this week, Symantec said the Flashback botnet had shrunk by 60 percent and was down to 142,000 machines. Kaspersky claimed that its count registered only 30,000 infected Macs.
Not even close, said Dr. Web in a Friday blog post.
"The number is still around 650,000," said Dr. Web.
On April 16, the company continued, it said 595,000 different Macs were registered on the botnet, while the next day, April 17, the count was over 582,000.
Symantec's O Murchu said Dr. Web is right.
"We've been talking with them about the discrepancies in our numbers and theirs," said O Murchu in an interview Friday. "We now believe that their analysis is accurate, and that it explains the discrepancies."
When asked for comment, Kaspersky Lab said it was looking into the matter.

Malware Outsmarts Monitors

According to Dr. Web, counts by others were incorrect because of how the malware calculates the locations of command-and-control (C&C) servers, and how it communicates, or tries to, with those domains.
Dr. Web said it had sinkholed the primary Flashback C&C domains at the beginning of the month, and that after an infected Mac asks those servers -- controlled by Dr. Web -- for instructions, they then reach out to another domain.

Dr. Web said it did not know who controlled that follow-up domain, but O Murchu suspected it is another security company or researcher.
But Dr. Web did know what happens next in Flashback's complex communication scheme.
"This server communicates with bots but doesn't close a TCP connection," wrote Dr. Web. "As [a] result, bots switch to the stand-by mode and wait for the server's reply and no longer respond to further commands. As a consequence, they do not communicate with other command centers, many of which have been registered by information security specialists [including Kaspersky and Symantec].
"This is the cause of controversial statistics," said Dr. Web.
Firms that reported a decrease in the Flashback botnet attributed the decline to the Java update that Apple distributed April 3, the detect-and-delete tool it shipped on April 12, similar tools issued by several antivirus vendors and the intense media attention paid to the outbreak.
Dr. Web's numbers hint that all of that was in vain.
Flashback's primary attack vector has been a Java vulnerability that Oracle patched in February, but Apple fixed only seven weeks later. Apple maintains its own version of Java for Mac OS X.
The French security company Intego first spotted the Flashback variant that exploited the then-unpatched Java bug in late March.

Saturday, April 14, 2012

New targeted Mac OS X Trojan requires no user interaction

from zdnet.com

Summary: A new Mac OS X Trojan referred to as Backdoor.OSX.SabPub.a or SX/Sabpab-A is also exploiting Java vulnerabilities in a way that requires no user interaction. It is being used in targeted attacks.
Another Mac OS X Trojan has been spotted in the wild; this one exploits Java vulnerabilities just like the Flashback Trojan. Also just like Flashback, this new Trojan requires no user interaction to infect your Apple Mac. Kasperskyrefers to it as “Backdoor.OSX.SabPub.a” while Sophos calls it at “SX/Sabpab-A.”
After infecting a given Mac, this Trojan is like most: it connects to a remote website using HTTP in typical command and control (C&C) fashion to fetch instructions from remote hackers telling it what to do. The backdoor contains functionality to take screenshots of the user’s current session, upload and download files, as well as execute commands remotely on the infected machine. Encrypted logs are sent back to the control server, so the hackers can monitor activity.
The remote C&C website appears to be hosted on the free dynamic DNS service onedumb.com. Interestingly, the IP address in question has been used in other targeted attacks (known as Luckycat) in the past. This particular attack may been launched through e-mails containing a URL pointing to two websites hosting the exploit, located in Germany and the U.S.
The Trojan may have been created on March 16, 2012. It was compiled with debug information, meaning analyzing it wasn’t hard, but more importantly this seems to suggest it is not the final version. You can check for infection by looking for the following files:
/Library/Preferences/com.apple.PubSabAgent.pfile
/Library/LaunchAgents/com.apple.PubSabAGent.plist
The Java exploits appear to be pretty standard, but have been obfuscated using ZelixKlassMasterto avoid detection by anti-malware products. The low number of infections and its backdoor functionality indicates that it is most likely used in targeted attacks.
The good news is this means that this Trojan is not believed to be anything as widespread as Flashback, and if you’ve downloaded and installed the latest software updates from Apple that patch the Java vulnerabilities (or disabled Java), you’re safe. The bad news is these Trojans will just keep coming, likely at an increasing rate.
This Trojan further underlines the importance of protecting Macs against malware with an updated anti-virus program as well as the latest security updates.