I use linux. I prefer it over Windows for many reasons. It’s more resistant to viruses, less of a target, but that doesn’t mean that malware or other viruses are impossible. If someone were to trick me into running something and even worse, trick me into using my administrator password to install something system wide, it could be the same end result as a windows malware infection. To be fair Microsoft has improved their security over the years. They are still the most likely platform though to get a drive by virus just by visiting a site (with no user interaction.) That much said, Mac users and Linux users should avoid being smug. Why? They aren’t completely safe. No one is. Social engineering is the most common (and most effective) path to getting malware on a computer.
I’ve done computer service for a number of years. Mostly small groups, home users, small businesses. But sometimes at larger organizations. It has many times amazed me that people let me at their computer by explaining that I’m there to look at the computers and _________ sent me back. I many times remember Face from the A-team…. “Hi I’m billy bob and this is my assistant sparky – we had a trouble ticket filed about the _______ and need to check out your workstation.” I can’t think of any time that I ran into someone new that wanted to call and check with someone else. Not once in ~15 years.
Recently there’s news of Mac Shield a malware for the mac that resembles rogue antivirus software on windows. Apparently a popup appears claiming that your mac has an infection and your administrator password is needed to remove it. Once it receives the administrator password…. game over you NOW have malware and it’s going to serve up illicit content over a public webserver, it’s going to collect passwords, bank account logins, credit card numbers and who knows what else on your nice secure smug mac.
The key learning moment here should be that it’s the user that was vulnerable – not the system!
Smugness should step aside.
Now, if you’re a mid size company that hires outside computer help – do you have a procedure for making sure that the person showing up is who they say they are? if you are large enough for an in house it department – are there name tags and ways to know that this guy that says he’s “the new guy” in IT really IS with your company?
Unfortunately in most organizations you can’t have a quick look from an IT person everytime you have a popup claiming that you have a virus. So, it’s important to become familiar with the legitimate popups of your antivirus software so you can discern better what is authentic and what isn’t. Sorry, but even that is no silver bullet. The malware writers are clever and who knows they may find a way to mimic whatever is preinstalled on the system for antivirus.
Related PostsRelated Posts
- Network Security guide for the home or small business network - Part 17 - The Security Mindset This may be one of the most important entries in this series. An important defence against those that would try to access your network is to constantly have the "security mindset". Ask yourself "do I need this, how could it be exploited, what are the implications of this"... When it......
- Collection of Open Source software for Windows This is a quick link to a downloadable cd of open source software for windows. There is a sizable list of programs. It appears as though some are not open source, but are free. If you have a fast enough connection to download it, you might find it very useful.......
- Microsoft's quick response to network worms.... This is an ironic title because frankly, Microsoft has seemed to be slow in solutions for the recent zotob worm. Of course, they announced the vulnerability and accompanying update to solve the issue to begin with, but after the virus started propagating what do we see from Microsoft? They have......
- Finding Unclaimed and Abandoned Money and Property With years under our belts, baby boomers have had many opportunities to lose and forget about money and other property that belonged to them. This is officially called "unclaimed property" by federal and state government. It makes sense at our age to find out if we have any unclaimed property......
- Windows 7 Sales Spike to Overtake Mac OS X [/caption]Proving there is no accounting for taste Microsoftâs latest attempt at a decent operating system, Windows 7, is now running on 5% of the computers online.Â The daily average of online users as measured by Internet metrics company Net Applications showed that an increase last week put Windows 7 above......
- Musician Profile for Joshua Bell Award-winning violinist Joshua Bell was born on December 9th, 1967 in Bloomington, Indiana. Legend has it that his mother started him in violin lessons after finding that he had stretched rubberbands across the handles of his dresser in order to play notes he had overheard when she played piano. In......
- The virus arms race? is locking down systems the key?
- Network Security guide for the home or small business network – Part 3 – Antivirus
- Facebook Fan Check Virus
- Network Security guide for the home or small business network – Part 13 – Your own worst enemy
- Administrative access on linux systems