It’s just as I envisioned the first real OS X malware: since it’s the only one, all eyes are on it, with a fix posted rapidly by third parties, and Apple responding soon after.
Hopefully we’ll never have more than one at a time...
"Sun (now Oracle) supplies Java for all other platforms. They have their own release schedules, which are almost always different than ours, so the Java we ship is always a version behind. This may not be the best way to do it."
Steve Jobs
Look up the definition of a virus then look up the definition of a trojan. Enjoy 🙂
Then thank God Apple doesn't endorse flash! 😀It's Flash and Java that cause all the problems.
You realize Apple makes and distributes Java for the Mac under license from Oracle? If you try to download Java for Mac from Oracle's site directly, you'll find this message:
The ONLY way to get Java on the Mac is from Apple. Apple may not preinstall Java on Macs anymore but when you want it, you get it from Apple. That's why updates for Java are also pushed out through the built-in OS software update. It's the way it's worked for years.
Oracle publicly released the fix for this security hole on Windows in February. Apple is the ONLY one who could have released the fix for Mac Java because it writes and distributes Mac Java. It waited until after Flashback installed itself on 600,000 Macs to release the fix. Who's at fault here?
Too the words right out of my mouth.
As much of a machead as I am... even *I* can't gloss over the fact Apple dropped the ball on this. It's their Java that got corn-holed and only they could fix it. Yet most everyone here still defends this incompetence. 😱 (And somehow Microsoft even gets dragged into it 🙂)
And so much for nothing being able to infect OSX without user permission. Apples Java version allows this to happen by default.
Is there any realistic chance that the guys who created this malware get caught?
I hope this lowlifes eventually get what they deserve.
You do not know what irony means.
It would be ironic if it said "Macs don't get viruses" and each Mac was contaminated with ebola.
Its still an issue with Java....even if there is a Mac version of Java updated/created by Apple, Java is still where this underlying Trojan lies affects the computer through and Apple is updating/fixing this as sees fit.
I thought irony was "like rain on your wedding day, or a free ride when you've already paid" lol 😛
... isn't ironic, don't ya think 😉
Very disappointed in Apple. The blame for how this was mishandled belongs to them alone.
Yes, to an unsavvy user, one might feel like it doesn't matter, but truthfully, OSX is a paradise compared to PC land and the sheer magnitude of exploitable environment there is to offer there.
They don't. This is a Trojan that's downloaded through a java exploit. Viruses are programs that run and do odd things without your permission. Trojans are different. Every computer is susceptible to Trojans, except for walled garden computers like the iPad and a few Linux distros.
As an aside, I often wonder who makes these viruses and trojans? I mean, is there a guy or group of guys just sitting around making these programs for fun or thievery? What do they do for a living, if their time is spent hacking systems and developing all these viruses, etc? Selling credit card numbers? A guy I met who once worked for McAfee in marketing joked that it's the companies that propagate these programs/viruses/what have you to increase a need for their product(s)... then he winked and kind of got us wondering. Then again, we all should probably wear tin foil hats LOL 😱
What exactly would Redmond have done? My guess is that they would of patched the bug back in February when Oracle released the patch as opposed to Apple's current practice of reactively releasing patches after an outbreak or after a security researcher gets fed up and publicly announces a vulnerability. It's worrying over the years how many instances there has been of researchers submitting a vulnerability to Apple, only to have Apple do nothing, and then when the researcher publicly releases the vulnerability Apple magically has a patch for it within a few days.
We can accuse Microsoft of many things, but not taking security seriously is not one of them. Yes, there was a time were they were hopeless but they got burned too many times and changed their attitude. They're not infallible and neither is their product but their attitude towards security and the security community puts Apple to shame.
Apple dropped the ball on this one. Things like this happen, Apple is not perfect and no one expects them to be. But instead of blindly defending them we, the Mac community and their customers, should be saying to Apple, "This is not acceptable, things have got to change. Waiting till after a serious outbreak to patch a vulnerability that was vendor patched months ago is not acceptable."
Blindly defending Apple and getting into pedantic arguments over definitions, validity of numbers, etc achieves nothing. Demanding better from Apple benefits everybody.