Tuesday, June 26, 2012

The Fight For Internet User Privacy

--
"Eternal vigilance is the price of liberty."- Thomas Jefferson 
"They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety."- Benjamin Franklin

Today we learned that advertising groups have FAILed to approve full support of the Do Not Track system. They insist upon user surveillance with or without targeted ads. Surprise. :-P

Mike Zaneis of the Interactive Advertising Bureau trade group says his industry will suffer if people can just switch off data collection. [Bolding = mine.]
I say:
THEN SUFFER, MARKETING-MORON BOZONS! User surveillance is NOT your right. Personal privacy is everyone’s right. Deal with it.

Let’s read from the USA Constitution Bill of Rights:
Amendment IV 
The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.
As an actual US patriot (as opposed to hypocritical political blowhards) and supporter of all US citizen rights, I hereby present:

The anti-tracking browser tools I use with Apple Safari. 

I'll start with the small stuff and work up to the all-out nuke solutions.

1) Do Not Track Plus, a free Safari extension from Abine. It provides ad sources with the 'Do Not Track' notification. The Plus is that it blocks over 600 tracking cookies and self-updates its tracking cookie list. It is compatible with Mac or PC for the following web browsers: Chrome, Firefox, Safari and IE. I use the Firefox extension version as well. It's not perfect, but it's a nice deal. Install it and forget it.

2) Incognito, a free Safari extension from Orbicule. This is another simple install it and forget it extension. It only blocks tracking cookies from Google Adsense, Google Analytics, embedded YouTube videos, Facebook, Twitter and B kontakte. Orbicule provide regular updates.

3) Ghostery, a free Safari extension. It is also available as a Firefox add-on and works in exactly the same way. Here's where we get more complicated. Ghostery is different in that it focuses specifically on what are called 'web bugs' and scripts, not tracking cookies. Web bugs are used as a more limited but sneaky method of user surveillance by advertisers and spammers. Therefore, use it in addition to a tracking cookie control extension or application. You can read about web bugs HERE.

Once Ghostery is installed, you have to go through an options setup process. I highly advise going through the setup carefully:

A) I prefer checking GhostRank ON. It helps the Ghostery developers to identify web bugs active on the Internet which allows them to be blocked in the future.

B) You will most likely want to UNcheck "Show alert bubble'. It drives me crazy and blocks part of web pages. You'll only want it on if you're getting serious about the surveillance at specific websites.

C) Leave 'Show bug script sources' ON. It's unobtrusive and may be interesting on occasion.

D) Leave 'Enable bug list auto-updating' ON.

E) Next we come to the Blocking Options. This is where Ghostery can cause you nasty troubles. It is possible here to check ON the blocking of something you actually do NOT want to block.

My favorite example of a problem is the web bug that Google forces you to use if you want to be able to use iGoogle, their terrific website where you can set up for RSS feeds, widgets and small games. I use iGoogle constantly. Having Ghostery block Google's forced web bug causes major problems. (Screw you Google for making me gag on your user surveillance! But I do like iGoogle a lot). In this example you will want to make sure you UNcheck 'Google Widgets'.

The best approach is to check ON the top box, which checks ON all the blocking. You'll then have to go down the list of well over 1,000 web bugs to UNcheck the web bugs you're required to use at particular web sites. This can be an obnoxious and tedious process.

My approach is to wait until I run into a problem accesses some aspect of a particular web page. I then go into the Safari (or Firefox) and turn OFF Ghostery. I reload the troubled web page and see if the problem went away. If it did go away, you'll want to go into the Options for Ghostery and figure out what you must now UNcheck. I like keeping a list of the UNchecked items I must use in Ghostery. I do this in a text file I keep with a folder I made for notes about Ghostery. (BTW: If turning off Ghostery didn't solve your web page problem, try turning off ALL your Safari extensions, via the convenient OFF - ON switch, and reloading the page.

Another approach is to use Ghostery to create a list of web URLs where you do NOT want Ghostery to block anything. You simply paste in the URL, hit the 'Add' button and it is added to the list. Clunky, I know. But if you want control, this is the state of the art.

If you'd like to learn more about Ghostery, they have a fairly active blog HERE.

4) Safari Cookies, free Safari extension from SweetPProductions, the makers of the Cookie app, #5 below. You may find the extension version of Safari Cookies to be adequate for your needs. Some people may be concerned that the installation requires SIMBL (aka SIMple Bundle Loader) which essentially adds some useful APIs not supplied by Apple. At one point in the past it caused Mac problems. Thankfully, I have had no problems with SIMBL for years since.

Compared to the full Cookie application, it requires the user to do a lot of manual maintenance of their cookies. Compared to the crap cookie control in every web browser I have ever used, this extension is a  nice godsend. But it does require some work. There are no automatic features apart from automatic updates via Safari. Also, it does not point out actual tracking cookies. That's for you to figure out. Therefore, you end up periodically killing off piles of cookies that you might rather keep.

This extension had a long series of bugs at one point, while the developer was getting a handle on it. I felt like a beta-tester, regularly sending bugs into the developers. But they were responsive and eventually stamped them all out. These days it is well worth using, especially for free.

5) Cookie, the $10 (on sale) application from SweetPProductions. This is the Bells-And-Whistles cookie control application. I like it a lot. I bought it, I use it. It has one silly bug whereby it typically brings up its preferences window when it boots, even when you've checked the box to tell it not to. Otherwise, this thing is well worth the cost if you want total cookie control with the least amount of effort. It has a 14 day trial period. Highly recommended.

When you open the Cookie preferences, the first thing you'll notice is that the thing is thorough: It lists not just plain old website cookies, but Flash cookies, Silverlight cookies and Databases dumped on your computer by various websites. Every one of these methods of placing data on your computer can be used for surveillance. I hate that.

There is a concept called "The Evercookie" that potentially allows user surveillance via any of a number of data sources retrievable from your computer. Plain old web browser cookies are only one of several sources of surveillance data. You can use the Cookie application to wipe out just about all the rest of these surveillance sources. Well, that is until HTML5 becomes standard on the Internet. HTML5 creates a number of new and obnoxious ways for websites to grab surveillance data. I'm expecting Cookie to keep up with all of them with time.

Setting up Cookie:

A) Preferences tab. Initially you do NOT want Cookie to remove any of your cookies. Leave the 'Remove' checkboxes UNchecked. This is recommended specifically during the period when you want to collect cookies in order to sort them as wanted or unwanted in the other four tabs. Read ahead and you'll see what I mean.

Once you have finished the period of time when you sort out the good cookies from bad, I recommend checking ON everything EXCEPT:
- Browser History, if you are the only user on your computer. Otherwise, you might want to periodically dump the history related data.
- 'and Hide Dock Icon'. I like the menubar icon for accessing the Cookie app. Alternatively, you can access it by Command-Tabbing over to it then hitting Command-Comma to bring up its preferences.
- Initially you do NOT want to have cookies removed

Where you may disagree with me is the use of the preferences for 'Remove'. The third checkbox is for remove "Every [ ] minutes while Browser is Open". This can potentially cause some problems with you being logged OUT of certain websites when a tracking cookie is removed. Again, Google has sunk to using this trickery on some of their websites. Therefore, you end up having to log into affected pages again and again. This can get annoying. But I found for my own personal use that setting up regular unwanted cookie removal was preferable. I have Cookie dump tracking cookies every few minutes. Test it and see what works for you.

B) Cookies Tab: Now we get into the initial setup tedium. I found the best approach was to spend some days surfing around the web to my usual places, then set aside a time to comb through the cookies list in order to check ON the cookies I like and leave the rest unchecked. The unchecked cookies will be from sites you've never heard of or from sites where you never log in.

For example, right now I have 41 cookies from google.com that are NOT tracking cookies. I log into the various Google sites for these cookies and want to keep them. Therefore, after hitting the 'Remove All Tracking Cookies' button, I check ON the rest of them via the check box for their directory header. Meanwhile, I see a pile of ad-rat websites that snuck a barrage of crap cookies onto my machine from gawd-know-what website. No way am I checking them on. Once I have checked on all those I want, I hit the button to 'Remove All Non-Favorites' and good riddance.

C) Flash Cookies Tab: I can't imagine ever wanting to keep any Flash cookies. Why isn't Flash dead already? But perhaps you have some very useful Flash game, app or video you use and would like to keep the related cookie. This is the place. It works just like the Cookies tab.

D) Silverlight Tab: If you use NetFlix, you'll want to keep its Silverlight cookie so you won't have to log into the Netflix site every time you visit. Etc.

E) Databases Tab: This list gets as complicated as the Cookies Tab list. It works the same way. Check ON the sites you visit regularly. Remove all the rest. If you don't recognize a listed website, you're most likely safe killing its database. If you figure out that you want that database, check it on later.

Where the Databases tab gets a bit strange is with the databases for Safari extensions. These websites will probably seem obscure to you, but they will keep returning over and over. The 'Type' column can help you as it will tell you when a database is for a "Safari Extension" or "Chromium Extension" etc.

--> For me, the Cookie app is well worth the investment. I want total control over my cookies and over who gets to surveil me on the Internet. I haven't found a better cookie control app. Combining it with Ghostery is as good as it gets at this time.


Other tools with which I am not well acquainted:


Cookie Stumbler from WriteIt! Studios. It has had a spotty reputation. Therefore, I have not worked with it. The 'basic' version is $7.90. It uses a 'heuristics engine' only for tracking cookie detection. The 'standard' version, including a single year 'known tracking cookie' subscription, is $19.90. There is also a free Safari extension version with 'basic protection against most common tracking cookies.' This summer there is also supposed to be an iOS version available. I personally don't see the point of an annual tracking cookie subscription. Any decent cookie analysis can detect a tracking cookie. The standard version is also is not as functional as the Cookie application.

Flush, formerly from MacHacks.tv. This abandonware was a free Flash cookie removal tool. It had good reviews while it lasted. I have no idea whether it still works or where you can download it. The developer's website has been abandoned as well.

If you know of other kewl or new user privacy tools, please let everyone know in the comments!


A good place to watch the progress (if any) of the Do Not Track system is the Electronic Frontier Foundation. Among other things, EFF offer instructions HERE about how you can turn on Do Not Track in various web browsers, including Safari. Just keep in mind that, for the time being, Do Not Track is merely a concept attempting to become reality. That's why the tools listed above, annoying as they may be, are likely to remain important for some time to come.

FIGHT for user privacy! Win it!  \(^_^)/
--

Thursday, May 31, 2012

Download.com Serves Malware To Customers.
It's easier to fall further down a hole
than to crawl back out again.

--
[Updated 2012-05-31 @ 11:45 pm EDT]


The Windows side of Download.com has ruined its credibility in recent months thanks to its General Manager and V.P. Sean Murphy turning the site into a malware rat hole. At least that is the message from an April 24th article at Insecure.org:


Download.com Caught Adding Malware to Nmap & Other Software


Quoting from the article:

In August 2011, Download.com was taken on a new path by their General Manager and V.P. Sean Murphy. They started wrapping legitimate 3rd party software into their own installer which by default installs a wide variety of adware and other questionable software on users machines. It also does things like redirect user search queries and change their Internet home page. At first their installer forced people to accept the malware or close the installer (see screen shot of infected VLC installer in this article). Later they added a non-default "decline" button hidden way on the left side of the panel. Also, the initial installer shown in the previous screen shot claimed the software was “SAFE, TRUSTED, AND SPYWARE FREE”. In an unusual show of honesty, they removed that claim from the rogue installer.
(The bolding is mine in order to point out the apparent culprit-in-charge).

If this report is factual, the self-destructive behavior of CBS's CNET Download.com website is particularly disturbing to me as I have known the guys at VersionTracker for several years. Today I wrote to the creator of VersionTracker for clarification and he replied:
I don't know what they do on the Windows side as I'm not part of that group but I do know nothing gets wrapped or added to files on the Mac side.
I can verify that there is no evidence implicating VersionTracker's Mac software downloads. I am constantly running anti-malware on my Macs as part of my studies of computer security. None of the Mac software I have downloaded daily from VersionTracker has been infected with any form of malware. I am loathe to advise avoiding the VersionTracker aspect of Download.com. 

Nonetheless, anyone concerned about maintaining maximum Mac security might wish to consider using another software download website. Despite its own ethical failures, I can equally recommend MacUpdate.com. 

(Note: MacUpdate has, IMHO, been a deliberate and persistent marketing pawn of ZeoBIT, the shameful developers of MacKeeper. This problem has been made evident by MacUpdate's tolerance of ZeoBIT paid 4 and 5 star MacKeeper review bombing. I should point out that the VersionTracker has tolerated the same paid positive review bombing. Of course, compromised user reviews are a trivial issue next to infecting customer downloads with malware).

Sigh. 
The Spirit of the Age in business remains: 
Abuse Thy Customer.

No wonder our human world is stuck in an ongoing, long term economic depression. :-P


Thankfully, I continue to have faith in VersionTracker's Mac download sub-site over at Downloads.com.
--

Thursday, May 10, 2012

Chaos In The Field Of Anti-Malware

--
Today I wrote a comment in response to an article at ZDNet by my colleague and anti-malware collaborator Ed Bott.


The subject of Ed's article brought to mind my main discomfort with the field of anti-malware. When I started studying the subject back in 2005, I was expecting something professional, along the lines of my extensive training in science. Instead I found the field to be remarkably chaotic.

Here is the comment I posted in response to Ed's article:

Common Terminology, Scientific Approach
As an amateur in the field of Mac malware and writer about the subject since 2007, I've consistently found that the anti-malware community, particularly the anti-malware business, is unscientific and uncooperative. It's full of contention with people arguing over what means what, who named what first, whose malware naming convention is the best, on and on. The result is a chaotic mess that obviously confuses anyone casually trying to understand what's going on. There is no overview organization for the field. There is no peer review. There are some standards, but breaking those standards is the rule.
Therefore, when casual viewers mess up their terminology or make incorrect emphatic statements, I tend to be forgiving. If the anti-malware community really was scientific by nature, I'd take a stricter view. But it's not. Therefore, casual viewers are going to get things wrong without having any thoroughly reliable source of information from which to gather knowledge or opinions. 
For example, I had a conversation with the owners of a software download site on the net a couple years ago which revealed they had no comprehension of common terminology applied to malware. Every malware was a 'virus' to them. In turn they were sharing this misunderstanding with their users, who in turn repeated the same misinformation within their social circles.
As an example of pointless contention between anti-malware companies, why did Kaspersky have to come up with its own name for a Mac Trojan horse series, 'Flashfake', for what had already been published as 'Flashback' months ahead of time?
In this field, confusion is inevitable.

Maybe with time and experience, the field of anti-malware will mature. Meanwhile, we flounder.
-- 

Tuesday, April 24, 2012

Flashback Malware and Java : FYI Notes


~~~~~~~~~~~~~~
I just posted an FYI set of notes over at MacDaily news to help sort out some misinformation regarding what has been occurring thanks to the Russian malware rats who write the Flashback series of malware. It may be helpful here as well.
~~~~~~~~~~~~~~


FYI:
The worst previous Mac malware infection was due to Trojan.OSX.iServices.A-C. It was a Trojan horse that was infiltrated into Warez versions of a few different Mac apps available at Torrent websites. The result was a botnet estimated to contain 10,000 Macs. That was in early 2009.

The worst estimate for the Flashback botnet (created by an estimated 19 different versions of the Flashback malware) was about 600,000 Macs. That is larger than the iServices botnet by a factor of 60.
All of the Mac malware previous to the recent few Java versions of Flashback, have been Trojan horses with infections preventable by basic safe user practices. The people who infected themselves are generally considered either to be Mac newbies or to be ‘LUSERS’ who would figure out a way to become infected if not for their account administrators.
The recent versions of Flashback have been unique in the history of Mac OS X malware because they were drive-by infections from websites that required no user interaction. The cause of this problem was two-fold:
1) Oracle don’t give a rat’s about Java and have allowed it to become the #1 source of third party security vulnerabilities for Mac users. Oracle don’t care.
2) Apple’s experiment with having Oracle provide timely updates of Java for Mac OS X has FAILed. Oracle don’t care.
My personal recommendations:
A) Don’t install Java onto Mac OS X 10.7. Most people never need it.
B) If you do install Java onto 10.7, or you run a previous version of Mac OS X, TURN JAVA OFF. This can be done in the Java Preferences app in your Utilities folder. Only turn it on again for critical uses, then turn it OFF when you’re done.
IOW: Java now sucks. Avoid Java as much as possible. 
Java is now even more dangerous than JavaScript, aka LiveScript, aka ECMAScript, aka JScript (by Microsoft), aka ActionScript (by Adobe). It is now even more dangerous than the real Adobe Flash Player plugins.
Hopefully this Java catastrophe has woken Apple up to being preemptive about Java security holes and their danger to Mac Java users. Oracle don’t care.
Ideally, Oracle will at long last allow Java to become an open source project. However, I don't see that happening in the near term as Oracle will be reaping some major bucks off Google for having ripped off Java technology for their Android OS. Oh well.

Sunday, April 15, 2012

Flashback Malware And
The Confusing Case Of
The Apple Flashback Malware Remover v1.0

--
[Updated 2012-04-18:
Symantec are now reporting that, according to their data collection, the Flashback botnet is down to 140, 000 Macs. That's still a vast number, but a remarkable improvement thanks to Apple's Java update and Remover. 


Also new: 
My net friend Al Varnell, who performs a great deal of vigilant work with ClamXav and the ClamAV project, has provided me with new information and insight reflected below. Of greatest interest is the fact that the Flashback malware series has been specifically aimed at Intel CPU Macs only. PPC Macs are immune.]


Apple has provided a separate tool for Mac OS X 10.7 users (only) for the removal of most versions of the Flashback malware. It is entitled (despite odd journalist claims to the contrary) the 'Flashback Malware Remover.' Apple also call it their 'Flashback malware removal tool.' The Software Update system in 10.7 is offering the tool to those who have no installed Java. Optionally, you can manually download it from Apple's Downloads site:


http://support.apple.com/kb/DL1517


Here is Apple's description of the Flashback malware removal tool:
About Flashback malware removal tool 
This update removes the most common variants of the Flashback malware. This update contains the same malware removal tool as Java for OS X 2012-003.If the Flashback malware is found, a dialog will be presented notifying the user that malware was removed. 
In some cases, the Flashback malware removal tool may need to restart your computer in order to completely remove the Flashback malware. 
This update is recommended for all OS X Lion users without Java installed.
Why does the description say 'without' Java installed? Because there have been quite a few versions of the Flashback malware that did not involve Java. Mac users who do not have Java installed (which is the default starting with Mac OS X 10.7) would never have been offered Java for OS X 2012-003 via Software update and therefore would never have run Flashback Malware Remover on their Macs via that update. Rather than leaving those users out in the cold, Apple have provided the Remover as a standalone installer application.


NOTE: The Remover only runs on Mac OS 10.7. I checked.


What is confusing about the Remover is that Apple have NOT provided an actual application tool. Instead Apple has provided an 'installer' package that runs within their Installer program and that is ALL that it does. 






Essentially, Apple took the Java for OS X 2012-003 installer and removed everything except the Remover process from the installation. In other words: NOTHING is installed on your Mac. Not-a-thing. And yes, that is freaky. The installer is the Remover. Get it? This is going to freak out and confuse quite a few Mac users. This has already been proven to be the case up on Apple's Discussion forums at their Support site. I can't blame them! It makes no sense, except that Apple had the Remover handy inside their Java for OS X 2012-003 installer, so they sped the Remover out the door within that same format.


Don't worry about it! Just run the installer and the Remover will run. Keep the .dmg file if you would like to run it again in the future. This is a great idea because the older Trojan horse versions of Flashback (of which there are reportedly 13 versions that don't use Java) are going to remain out in the wild on the Internet.


Please refer back to my previous article for details about how to avoid being infected with Trojan horse malware, along with other security rules and tips:

The Rules of Computing: Keeping Your Mac Secure

The Numbers:


Adding up all the Macs infected with ALL the variations of the Flashback malware, apparently well over 600,000 Macs were affected:



After Apple's three Java updates, the last of which included the Remover, the number dropped to half, less than 300,000 infected Macs:


Who's left in the Flashback botnet?

1) Users with Mac OS X 10.6 or 10.7 with Java installed who have not run the most recent updater or Apple's separate Flashback Malware Remover.

2) Users with Mac OS X 10.7 who never installed Java and have not yet run Apple's Flashback Malware Remover.

3) Anyone using Mac OS X 10.5 on Intel Macs. From the data of which I am aware, the Flashback malware code is directly ONLY at Intel Macs, making PPC Macs immune. It is not clear whether there has been infection of Mac OS X 10.4 Intel Macs. However, I continue to suspect there have. The Java security hole exploited by Malware.OSX.Flashback.N, the latest version (according to Intego) is apparently present in the last Java update for that version of Mac OS X.

Kaspersky has provided a web page where you can check if your specific Mac was infected with Flashback. However, I can't recommend it as the page requires you to enter your Mac's hardware UUID (Universally Unique Identifier). That's a bit like giving away your social security number and could be used by hackers to fake being you on the Internet. I suggest you only give it away to people you know and trust. Therefore, I'm not going to link Kaspersky's Flashback infection checking page here. If you'd like to use it, go digging around at the Kaspersky.com website.

Is this the time to buy Mac Anti-Malware software?
(Often wrongly called 'Anti-Virus' software). 

Probably not, unless you are dealing with the 'LUSER Factor' or unless you have an Intel Mac with Mac OS X 10.5 or 10.4. Even then, I suggest you first download and use Mark Allan's ClamXav software. It's FREE. My Mac Security friends and I work to keep the ClamAV open source project up-to-date with the latest Mac malware definitions. Install it, update its malware definitions and have it scan your entire boot drive.

There are also a number of free scanner versions of commercial anti-malware apps. I'd suggest checking out Sophos Free Anti-Virus for Mac. (I can no longer recommend the free PC Tools iAntiVirus app, which is drastically out-of-date).

If you'd like to buy the best Anti-Malware program, I continue to recommend Intego's VirusBarrier. They have a 30 trial version. I own it, use it and like it. It ships with excellent bells and whistles including its own firewall, Internet website protection, good background scanning that doesn't eat your CPU, and its own reverse firewall (similar to the renowned Little Snitch software). The only drawback is the yearly fee for malware definitions. I pay it and don't mind.

I have friends who like F-Secure Anti-Virus. They offer free online tools and a 30 day free trial. (Use the 'campaign code' on their AV page). The only reason I avoid F-Secure is that they are FUD mongers, attempting to scare Mac users with exaggerated reports about Mac malware. I don't deal with that.

Sophos is the best if you are running a small business or enterprise network of Macs. They also offer a free trial. I also like their free Sophos Security Monitor app for iOS devices. It provides timely computer security information.

The other anti-malware providers can be anywhere from OK to total CRAP. The crap includes (IMHO of course) anything from ZeoBIT and Symantec. IOW: Run away from MacKeeper and Norton Anti-Virus. 


Coming Up:


Over at my MacSmarticles blog, I will be posting an article about ZeoBIT paying their users to bombard Mac software review sites, a grotesque abuse of marketing.

Here at the Mac-Security blog, I will be providing a list of my favorite Mac security information sources.
--

Wednesday, April 4, 2012

CRITICAL Java Updates: Mac OS X 10.6 Update 7 and 10.7 Update 2012-002 (formerly 001)

--
[Updated 2012-04-06:
For users of Mac OS X 10.7, Java update 2012-002 has been released today to correct an error in the .DMG installation file for 2012-001. The 2012-001 installer has been withdrawn. I interpret this to mean that the flaw in 001 was critical. Therefore, please install Java for OS X 2012-002 IMMEDIATELY! It has been reported that over 600,000 (not a typo) Macs are now infected with the Flashback Trojan horse / botnet malware! This is unprecedented in Mac history. This Java update kills off a Drive-By method of Mac infection by the Flashback malware.]

If you haven't already installed the latest Java update for Mac OS X 10.6 Snow Leopard and 10.7 Lion, INSTALL IT NOW. No excuses. The best method of installation in this case is via Software Update, available under the Apple menu. There is currently a problem with the direct download version for 10.7 whereby it FAILs the fsck check the OS runs during DMG file verification. See details below.

This particular update is CRITICAL because there is an active exploit against the older version of Java that results in Drive-By infection of Mac machines without requiring the user to provide a password. This is unheard of on Macs. It is specifically a Java problem, NOT a Mac OS X problem. Don't blame Apple. Blame the lazy crapcoders at ORACLE.

Windows users have had this particular Java update for MONTHS. Supposedly Apple and Oracle have an arrangement whereby Oracle are now writing Mac updates for Java. But that arrangement is FAILing.

Earlier today I posted reviews of this update at both VersionTracker/CNET and MacUpdate. I have provided a somewhat redundant summary below which with details about how to turn OFF Java, which I highly recommend, as well as some rant action.

∞ ∞ ∞ ∞ ∞ ∞ ∞ ∞ ∞ ∞ ∞ ∞

Good: This CRUCIAL Java update patches an active exploit against Macs. Better a late update than never. Java is occasionally useful.

Bad: Java is now one of the most INSECURE Internet technologies. If you don't use Java, TURN IT OFF! Oracle and Apple are NOT providing Mac Java updates in a timely manner. This Java update for Mac provides an update that Windows users have had for months. For over a week, there has been an active malware exploit against Mac users with the unpatched version of Java.

It is terrific that Apple jumped on this exploit so quickly. However, Apple users MUST be provided with Java patches at the same time as Windows users. Delaying Java patches for Mac users is NOT acceptable.

I have verified that the direct download file of the 10.7 version of Java for OS X 2012-001,  FAILs the Mac OS X fsck check during file verification. This is evident in the Console. This is BAD. If you used this downloaded installer, IMMEDIATELY update to the Java for OS X 2012-002 installer!

The BEST way to install this update is from Software Update. You will find it under your Mac's Apple menu. This installation works perfectly.



Now For My Rant:


Java has become a BANE of the Internet. I have turned it OFF. I am sick of the recent Java exploits against Mac users. I don't deal with it. I suggest you turn Java OFF as well, unless you use it regularly.

HOW TO TURN OFF JAVA: 

If you use multiple web browsers (I use six) then the best and simplest way to turn Java OFF is via the Java Preferences app found in your Mac's Utilities folder. Follow these steps:

1) Open the Java Preferences app.


2) Under the 'General' tab, check OFF "Enable applet plug-in and Web Start applications". (Mac OS X 10.6 users: Instead uncheck the plugins for Java SE 6 in the box inside the window).

3) Quit the Java Preferences app.

4) VERIFY IT'S OFF: Open the Java Preferences app, again. Verify that the "Enable..." checkbox remains OFF. If you find it on again, check the damned thing OFF again. Quit Java Preferences. Verify AGAIN as required.

I add this VERIFY step because I personally have seen this checkbox turn on again. If you want to be extra-special certain the box doesn't turn on again, you can go down to the box under the 'General' tab and turn OFF both 64 and 32-bit "Java SE 6", then turn off "Enable". That definitely does the trick.

My #2 Rant: 


SHAME ON ORACLE. That company has RUINED OpenOffice. The LibreOffice branch is now off and running and far superior, leaving the source OpenOffice project irrelevant. Oracle has been just as obtuse with Java, which is now a DETRIMENT to the Internet.

Maybe Java will be made open source, at long last. That would help. Perhaps great developers like those on the LibreOffice team will grab it and make Java seriously great. Until then, BEWARE OF JAVA. I fully expect more Java exploit malware to come. (o_0) 



Now I go all sentimental: 

Remember when Java was supposed to be 100% secure, never able to access your computer directly, entirely safe in its sandboxed little Just-In-Time runtime machine? Remember 'write once, run anywhere'? Remember 'secure memory management'? Fun times in Fantasy Land. 
:-P

Thursday, February 16, 2012

Apple's Gatekeeper in Mac OS X 10.8 Mountain Lion

--
[Revised 2012-02-20 @11:30 pm]

Let's get happy! Apple has set up a new approach to nailing Trojan horse malware for the upcoming new version of Mac OS X, code named Mountain Lion, aka 10.8. AND! Apple did it right! It uses both and application blacklisting and whitelisting.  It also uses application security certificates (aka digital signing). Only Apple gets to provide them, as opposed to the ongoing SSL certificate highjacking mess with hundreds of certificate providers.

If this concept sounds familiar, it's because Microsoft started doing it with 64-bit Windows Vista, where it was a profound failure. Why a failure? Because Microsoft GOUGED their developers with punishing fees per security certificate. Developers ignored it. This resulted in, among other things, a lack of hardware drivers for 64-bit Vista. Profound OOPS factor! Eventually Microsoft got the clue and relented on their fees. Therefore, the 64-bit 7ista release received far better developer support.

Apple's approach builds upon Mac OS X Snow Leopard and Lion's XProtect anti-malware system by providing users with new Security & Privacy Preferences accessible options and warnings:



1) Allow applications downloaded from: Anywhere. You can choose to keep things the way they are now. However, Apple provides WARNINGS about potential problems known about specific programs found on their current blacklist. Similar to XProtect, the blacklist is updated over the Internet every day. Apple will also be daily revoking bad app developer security certificates.

Example:
You download an app off a random site off the Internet and Apple pops up a message warning you that this particular app is known to upload your entire Address Book to their server. That's dangerous! It could mean the developer could take that list and perpetrate a SPAM ATTACK! That SPAM could include links to Phishing sites, further malware, etc. Your friends will not be pleased.

This feature alone is going to infuriate the malware rats. Users cannot turn it OFF as long as you are the administrator for your account. I like it! The result is a great short-circuiting of most social engineering malware.

The drawback is more popup boxes on the screen that you have to dismiss, IOW an increased safety factor as well as an increased annoyance factor.

2) Allow applications downloaded from: Mac App Store. You can choose to only download software from Apple's Mac Store. This provides maximum security because as of Mountain Lion's release date ALL Mac Store provided apps will be sandboxed, whereby every app is limited to accessing only the Apple APIs it requires and the apps run within a restricted memory space. Think of all the memory corruption vulnerabilities constantly being patched in applications. Now the damage they can do will be severely limited.

Example:
You download a crappy xhumans-style app that plays you videos about moths. The app will not be able to rifle through your Address Book for suckers to SPAM. All developers will have to justify every API their app accesses as being critical to its functions.

This remarkable approach for protecting users from malware already gives malware rats painful anxiety hemorrhoids. The result for users is very similar to the wonderful 'walled garden' available to all iPhone / iPod Touch / iPad users. This is the ideal setting to lock into place for all the 'LUSERS' in our midst. It will be nearly impossible for them to infect their Mac. They cannot turn this off, as long as you don't provide them with the administrator password.

The drawbacks here are:
  • Paranoia about Apple ruling the software world.
  • The profit loss to developers by selling their apps via Apple's Mac Store.
  • The sense of losing our freedom to do as we like with our computers. 
But keep in mind that you can turn this feature OFF and continue to enjoy your freedom-filled life as a positive anarchist. (^_^)

3) Allow applications downloaded from: Mac App Store and identified developers. You can choose the compromise setting of using both the Apple Mac Store and make use of Apple's blacklist of dangerous apps, whitelist of safe apps and app security certificates. In other words, you can download whatever you like off the Internet, but Apple's lists will not only warn you of potentially bad software, it will prevent you from being able to install it at all.

Example:
You got this really kewl email telling you about an incredible application that will remind all your friends of your upcoming birthday, maximizing your receipt of birthday cards, congratulation messages and presents. You click the link to go to the website, which actually automatically downloads the software directly to your computer, like it or not. But then BAM! Apple's Gatekeeper STOPS the installation because this app is on their blacklist as potential scamware. Apple warns in a popup box that this app will not only grab your Address Book, but will PWN your Twitter account, Google+ account and Facebook account then grab all your friend contacts. The result could be a major scale SPAM, Phishing and linked malware attack on every single person you know.

This is a great default setting for everyone for every day use. You could be temporarily brain compromised, clicking on every link on the Internet, downloading goodness knows what, and the computer will stop you. And again keep in mind that you can turn this OFF, as long as you are your account administrator.

Meanwhile, malware rats will be restricted to only short term mass infection of suckers. Once Apple catches up with new malware on its blacklist, the malware rats will be ripping their hair out with consternation. What fun!

The Time and Sharing Problems:


It is difficult to keep Apple's XProtect perfectly up-to-date. On occasion it has taken Apple a number of days to provide malware signatures. We can expect a similar lag with their application blacklist and security certificate revocation.

Note that this is not entirely Apple's fault! Knowing the anti-malware community as well as I do, I can verify that it can be extremely hard to get a copy of the latest malware for analysis, signature creation and infection prevention. The anti-malware community is outrageously unprofessional in many respects. Therefore, there is almost NO SHARING of malware between anti-malware companies and providers. That includes sharing malware with Apple. If at some point the anti-malware community grows up and becomes serious, standardized and scientific in its approaches, all this competitive rubbish will go away. But don't hold your breath. We're still living in a metaphorical Wild West of computer security. Thankfully, Apple is taking the role as the new sheriff in town.

There is a wonderfully detailed article about Mountain Lion's Gatekeeper by Rich Mogull. You can find it on the TidBITS website:

Gatekeeper Slams the Door on Mac Malware Epidemics

Rich Mogull has also provided a follow up article with more technical details, available at his Securosis blog:


Meanwhile, Macworld has been providing a series of articles about Mountain Lion, including coverage of Gatekeeper that goes into further detail:

Mountain Lion: Hands on with Gatekeeper


No doubt, further details and analysis will be provided as Mountain Lion approaches. Please tell us about further information in the comments!
--