commentary With exploit code for an OS X vulnerability released recently and a compromised Australian university Mac server caught hosting malware in August, it may be time Apple admitted its platform is no more secure than any other.
While Apple users laud their systems as unbreakable pillars of security in a dangerous world, unsusceptible to the malware attacks that make life on Windows so hazardous, the headlines keep coming.
In August, the University of New South Wales was, no doubt, surprised to learn one of its Mac servers had been hijacked by baddies to host some malware disguised as a Microsoft patch. University system administrators interviewed by ZDNet Australia were puzzled -- the server was evidently running the latest version of OS X server.
It turned out the miscreants gained entry through a vulnerability in the server's TikiWiki code, a third party package that has nothing to do with Apple. Still, OS X didn't somehow, magically, prevent the attack as some users seem to think it's capable of doing.
Yes, it's true the average Mac user (like me -- shiny 20 inch G5 Rev B) doesn't have to contend with the malware that plagues Windows-based computers. Yes, it's true I'd prefer my mother use a Mac to avoid keylogging Trojans designed to capture her Internet banking passwords. But Apple's marketing these days seems to suggest its computers are immune to attack (The advert is also available on YouTube).
They're not, and it's dishonest for Apple to suggest otherwise.
There is little evidence to justify the claim that Apple computers are more secure than any other, and anyone who points to the low number of reported OS X security bugs, worms or viruses as proof to the contrary is misguided.
Macs are safer to use because of the lower number of reported bugs, but that does not make them more secure. It's an important distinction.
There's only one thing that makes Macs substantially safer than PCs, and it's called market share; a 3.8 percent market share, measured by net presence, to be precise.
If Macs were the dominant operating system with, say, 80 percent of the market, there is no doubt all the clever malware writers would devote their skills to engineering malware for Macs, not Windows-based PCs.
With all that brainpower going into compromising an operating system, there is little doubt the efforts would yield results.
In this parallel universe, switching to that boutique operating system made by the underdog with the 3-4 percent market-share, Microsoft, would seem like a great idea. Windows would develop a cult following for its inherently superior security.
The ironic part is Apple has, whether it knows it or not, ripped a leaf straight out of Microsoft's marketing playbook. You have to dig around for Microsoft's old Windows NT marketing material -- the company has removed much of it from its Web servers, perhaps out of shame -- but it reads much the same as Apple's current spiel.
"Intelligent design prevents the swarms of viruses and spyware that plague PCs these days," says Apple's Web site.
And this from Microsoft. "Windows NT Server is secure from the ground up," says a Microsoft Web site archive touting NT's apparent NSA C2 security compliance.
"Every process and feature was designed with C2 level security in mind. In fact, Windows NT Server is so secure that certain processes (identification and authentication, and the ability to separate a user from his/her functions) meet B2 security requirements, a level of security that is even more strict than C2."
In retrospect, it is kind of funny. More reading here.
Indeed, when Windows NT first rolled around in the '90s, Microsoft pushed the security angle hard. It was a new product, and there were few known vulnerabilities in the new server architecture. Of course, with increased market share came a deluge of vulnerabilities and everyone realised that it was, for the purposes of security, poorly designed and full of holes.
Users were not happy, and Microsoft was forced -- it took years -- to finally invest in security in earnest. The Redmond-based giant has learned its lesson.
Apple hasn't been through that humiliating process yet, and still thinks it's invincible. This could explain its lacklustre response to security vulnerability reports. Ask almost any security researcher what they think of Apple's response capability, and you'll usually get the same answer: "They're bad, but not as bad as Oracle."
It's hardly a glowing endorsement.
The argument being put forward here isn't that Windows is more secure than OS X, it's that currently there is no such thing as a secure operating system. OS X just hasn't been subjected to the torture test that comes with market domination. It is almost certain that there are dozens of undiscovered bugs in OS X.
Welcome to the wonderful world of operating system security.
And thanks to the computer-maker's decision to switch to an Intel CPU architecture, Mac malware has never been easier to write. Creating security vulnerability exploit code requires a fairly intimate knowledge of the CPU architecture on the target machine. The relative obscurity of the previous Mac architecture (Power PC) meant there were few malicious coders who could be bothered writing exploits for OS X.
Now it's been switched over to the more hacker-friendly Intel architecture, it's a fair bet that more exploits for OS X will emerge. Sure, the differences between Mac and Microsoft operating systems still mean malware will have to be customised for OS X, but the initial exploitation will be that much easier.
Apple, the message is this: Yes, you make beautiful computers. They're pretty, shiny, they have a nice interface and I love my Mac. Consumers are safer online using a Mac, too. But just as the security of New Zealand is rooted in its geographic isolation, not its military might, the security of your products has more to do with your small market share than their technical superiority.
Editor's note: An update to this commentary has been published here.

C'mon Zdnet, I know standards are slipping but geeez...the gimps you have "writing" for you now is beyond a joke.
The article lost all credibility about 3 sentences in.
The old "it's the marketshare" argument is sooooo 1995 and it has lost all credence with "proper" IT Security people, not just your CISSP clowns.
I can't be bothered even starting in on thios artcile except to say that's toilet paper and should be treated as such, and no, I don't even use Macs day to day (but I admire their purity).
So lift your game Zdnet and lets get some grown-ups here writing your articles, unless of course, you don't want them ?? Who pays for all that shiny advertising anyway?
Your author is either a fool that shouldn't be let enar a typewriter, or he's pushing an agenda as NO-ONE of any note has even comtemplated those sad, well worn arguments for over a decade now.
If Mac had 80% of the market then Win NR would STILL have the vast majority of the real world, "in the wild" viruses as it's TRIVIAL TO BREAK WINDOWS!
Do you need smaller words, less syllables ?? TRIVIAL ! Windows is the ONLY commodity OS where you can get pnwed by CLICKING ON A LINK or OPENING AN EMAIL and all your huffing and pussing and lying won't change that. It's not even a proof of concept on Mac or BSD or Linux and there sure as hell is NOT 114,000 different examples of this floating around IN THE WILD infecting millions of machines every day!
it's like car manufacturer X saying 'See/, a car from manufacturer Y got stolen so their cars are as bad as ours!' when the thief needed to follow you home, knock you out, take the keys, get a thumb-print, defeat the biometrics in the garage, then the car and then only manage to crane it onto the back of a truck for removal and it was the only one stolen that year when manufacturer X'c car doesn't even come with door locks or (pardon the pun) windows and they have a life expectancy until they're stolen of 15 minutes!
Ohhh..but if man Y's cars were so popular they'd be stolen constantly too...right?..right?... rubbish!!
Now go back to sleep.