Why Mac users need to grow up about viruses

Graham Cluley
Graham Cluley: Mac users are just as human as Windows users

Pardon me for ranting, but I think I've had enough.

I've been working in the computer security industry for umpteen years, and have lost count of the number of times I've had to explain to a Windows user how they really shouldn't open unsolicited attachments, or how installing a codec to view a naked video of Angelina Jolie and Paris Hilton enjoying themselves in a bubble bath is a really bad idea.

Attacks like the Jahlav-C Trojan are not proof-of-concept threats. They are real, and regular Mac users can get themselves infected.

The thing is that Mac malware today is using the same tricks as Windows malware. When Apple Mac malware is planted on websites posing as a program to allow you to watch a saucy video, guess what? People install it! And when you install it, the malware downloads additional malicious components from a third party server.

That's exactly the same way so many Windows attacks work. You visit a website thinking you're going to watch a naked video of Paris Hilton, Angelina Jolie or some other Hollywood celebrity and it tells you that you don't have the right codec, or the right version of Adobe Flash to watch the movie. And when you upgrade yourself - BAM! - you've been infected.

Yes, there aren't as many Mac malware threats as Windows threats - not by a long shot. But they do exist, and we are seeing some hacking gangs writing malware for both platforms, and planting their attacks on webpages in such a way as to serve up a Mac threat when Apple users visit, and a Windows attack when PC users surf by.

The fact is that Mac users are just as human as Windows users. Mac fans aren't any less susceptible to social engineering tricks than Windows users. Mac users are just as keen to view a pornographic video as Windows users are.

Some Mac users in the past have argued that on Mac OS X you need to enter your system administrator username and password to install software, and that this is a defence.

Guess what? If you want to install a codec to watch a porn video, you will enter your username and password.

-------------------------------------------------------------------------------------------------------

Graham Cluley is senior technology consultant at Sophos, and has been working in the computer security field since the early 1990s. When he's not updating his other blog on the Sophos website you can find him on Twitter at @gcluley.