Mac flaw could let hackers get scrambled data

A Mac security expert has uncovered a technique that hackers could use to take control of Apple Inc computers and steal data that is scrambled to protect it from identity thieves.

Prominent Mac researcher Dino Dai Zovi disclosed the software flaw at the Black Hat security conference in Las Vegas, one of the world's top forums for exchanging information on Internet threats.



About 4,000 security professionals are in attendance, including some who are really hackers. While experts ferret out software flaws to fix them and protect users, hackers use the same information to devise pranks or commit crimes.



It is not illegal to publish software that can be used to hack into computer systems, though it is against the law to use it to break into them.



Attacks on Apple computers are extremely rare, but security experts say that will change as Macs gain market share on PCs running Microsoft Corp's Windows operating system. Security experts have identified at least three viruses infecting Macs over the past year.



The most sophisticated of them is spread via pirated versions of Apple's iWorks software. It allows cybercriminals to take complete control of an infected Mac.



Another virus, OSXPuper a, is spread via infected websites that direct users to download what they say is a video player, but turns out to be malicious software. That software can subsequently download other types of viruses.



Dai Zovi, a security researcher and co-author of "The Mac Hacker's Handbook," said on Wednesday that once hackers start to put substantial resources into targeting Apple's computers, they will be at least as vulnerable as Windows machines.



"There is no magic fairy dust protecting Macs," he said in an interview.



The technique that Dai Zovi unveiled on Wednesday -- dubbed "Machiavelli" -- only works on machines that have already been victimized. It can take control of Apple's Safari browser, stealing encrypted data from a user's bank accounts.



An Apple spokeswoman could not be reached for comment.

Apple is the fourth-largest U.S. PC maker and continues to take market share. It held 9 percent of the U.S. market in the second quarter, according to Gartner.



"They are advancing. Our concern is that they are just not advancing as fast as they are gaining market share," said Charlie Miller, co-author of "The Mac Hacker's Handbook."



They said the Mac's operating system will be an easier nut to crack once hackers start to focus on it. That is because it has a lot more code in it than Windows, leaving room for more vulnerabilities and bugs that hackers can exploit.



While there is a limited supply of malicious software targeting Macs today, experts worry that the pendulum could quickly shift, leaving millions of Apple users unprotected.



"When the malware authors put out something that's really sophisticated we are going to have a whole population that is really vulnerable," said Joel Yonts, an expert in Mac security attending Black Hat.

Independent Comment
blog comments powered by Disqus
Career Services

Day In a Page

Is Ridley Scott the most macho man in movies?

Ridley Scott: The most macho man in movies?

His cinematic CV is unparalleled. Yet the Alien director is still obsessed with beating his rivals.
Being Gary Lineker: The clean-cut anchorman is this summer's Mr Sport

Being Gary Lineker

The clean-cut anchorman is this summer's Mr Sport...
Gallic gourmets are putting French cuisine back on the culinary map

Gallic gourmets put France back on culinary map

Overdone, out of touch and old-fashioned: French cuisine has never been at a lower ebb...
So Moorish: Mark Hix offers his own take on classic Moroccan dishes

So Moorish: Mark Hix's Moroccan dishes

Why not create a north African-inspired feast to share with your friends?
Sin and the single mother: The history of lone parenthood

Sin and the single mother

Maureen Paton explores the history of lone parenthood.
The outsider: Margaret Howell is British fashion's queen of minimalism

The outsider: Margaret Howell

The designer tells Susannah Frankel why she has never felt part of the fashion industry.
The 50 Best luggage

The 50 Best luggage

From chic cases to compact baggage, pack it all in this summer
For men only: A pilgrimage to Mount Athos in Greece

For men only: A pilgrimage to Mount Athos

On a secluded peninsula in north-east Greece lies an enclave that's way off the tourist map, especially for women...
48 Hours In: Faro

48 Hours In: Faro

More than just the gateway to the Algarve, this city has much to tempt you off the beach.
Here, the coast is always clear: Celebrating sixty years of Pembrokeshire's National Park

60 years of Pembrokeshire's National Park

Mick Webb reveals a land of puffins, tanks and Hollywood blockbusters.
Free Range: Meet the designers of tomorrow

Free Range

Meet the artists of the future
Feeding a hungry world – or meddling with laws of nature?

Feeding a hungry world – or meddling with laws of nature?

As scientists at Rothamsted's GM trials plead with activists not to sabotage their work, Michael McCarthy visits the battle field
Monkey meat that could be behind the next HIV

Monkey meat that could be behind the next HIV

Deep in Cameroon's rainforests, poachers are killing primates for food. Evan Williams reports from Yokadouma on a practice that could create a pandemic
Catcalls, whistles, groping: just another day for a young woman

Catcalls, whistles, groping: just another day for a young woman

Government urged to take abuse more seriously as London study shows 41 per cent are harassed
Jailing of Maori separatists stirs colonial-era resentment

Jailing of Maori separatists stirs colonial-era resentment

Militant Tuhoe tribe members defiant amid claims race relations had been set back 100 years