![]() |
|
[Sentinel One] Macs aren't safe 'by design' - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: General (https://sinister.li/Forum-General) +--- Forum: World News (https://sinister.li/Forum-World-News) +--- Thread: [Sentinel One] Macs aren't safe 'by design' (/Thread-Sentinel-One-Macs-aren-t-safe-by-design) |
[Sentinel One] Macs aren't safe 'by design' - ConcernedCitizen - 01-10-2022 From the company's blog: Quote:Unlike Microsoft, Apple is not in the business of selling security software in an attempt to protect its own products, but it still actively promotes the security of macOS as one of the unique selling points of Macs over other hardware. Accordingly, Apple has a vested interest in discouraging the perception that third party security controls are required for Macs in the enterprise just as much as they are for other endpoints. This just came across my desk today so I thought I'd reiterate on the fact and give more background. My job entails dealing with threats (especially emerging threats) and I see it time & time again where people mistakenly believe their Mac and iOS devices are safe because Apple is inherently safer than Windows or some other OS. Let's look at some example numbers of why this isn't accurate to say. These are just the numbers of (disclosed) threats my company has discovered. The number of machines we saw introduced to malware within the Windows OS exceeded 3,000 individual signatures. Linux exceeded 300 signatures and, while low in comparison to Mac OS signatures at 500, that's still a very alarming number. In 2021: Google's threat seekers saw novel backdoor rootkits serving vulnerabilities unknown and unpatched - the likes of CVE-2021-30869. Before that, in 2020, the APT known as Milium that was targeted at MacOS which had been repurposed from previous malware campaign WildPressure. It included a new PyInstaller trojan dropper. It also affected unpatched devices and the number of infected computers is officially unknown. These attacks might seem few and far between when considering the attack architecture of most malware matches that of Windows or Linux, but the truth is that we need to stop assuming MacOS and iOS devices are inherently safer. Especially in 2022, where several emerging threats are predicted to be targeted at MacOS and Apple devices. According to the European Union Agency for Cybersecurity (ENISA), we are in the "golden age of ransomware" with a nearly 150% increase in these attacks - and they're not the only multifaceted structures we're facing so far. Since 2019, at the start of the pandemic, Ransomware-as-a-Service (RaaS) has become commonplace. Threat actors (SVR, NSO, etc.) aren't getting lazier - it's the companies who believe they're impenetrable - that are getting increasingly & alarmingly more complacent when they should be doubling down on security solutions. CISOs are continually in high demand in today's world. But companies are assuming safety exists simply because they don't disclose sources and specific details about their platform. In fact, as someone who frequently wears many types of hats, I can tell you that it only makes someone with the hacker mindset more interested and puts those vendors and operators at higher risk. RE: [Sentinel One] Macs aren't safe 'by design' - Bricker - 01-10-2022 And let us not also forget the 2014 Goto Fail bug. Taught a whole bunch of people the importance of using brackets at the cost of clean code RE: [Sentinel One] Macs aren't safe 'by design' - ConcernedCitizen - 01-10-2022 (01-10-2022, 08:17 AM)Bricker Wrote: And let us not also forget the 2014 Goto Fail bug. Taught a whole bunch of people the importance of using brackets at the cost of clean codeIf I'm understanding this correctly, Apple relies heavily on code-signing and built-in 'soft-fail' functions. The go-to fail bug exploiting a known (by Apple) code error with duplicate lines. This was patched soon after. The certificate revocation exploit was used for introduction of ransomware to devices through Apple's failed use of some of that same code-signing error from before, with tweaks to delivery and execution, but still similar. The code is not public so it can't be audited independently or peer-reviewed. The exploits are harder to patch and are therefore sought after by malware development campaigns and threat actors. You can't fix what you can't see. |