# Are Macs susceptible to malware from merely visiting a website?

**URL:** <https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911>\
**Category:** Factual Questions\
**Created:** [January 27, 2012, 9:59pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911 "2012-01-27T21:59:53Z")\
**Posts on this page:** 20\
**Page:** 5

<div class="post-metadata">

**Author:** ![Larry\_Mudd](https://avatars.discourse-cdn.com/v4/letter/l/f14d63/32.png) [@Larry\_Mudd](https://boards.straightdope.com/u/Larry_Mudd)\
**Post date:** [January 31, 2012, 3:32pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/81 "2012-01-31T15:32:22Z")

</div>

> [@Kenm](#):
>
> From 2009, [**one of many sites**](http://www.mac-forums.com/forums/os-x-operating-system/167703-true-mac-os-x-hacked-under-20-seconds.html) with this information:
> 
> > [@](#):
> >
> > Yes, Mac OS X was “hacked” during a contest… but only after the contest organizers removed any security measures and the “hackers” were given direct and local client access to the machine they were “hacking”.
> > 
> > In other words, in a real world environment they would not have been successful and the answer would be “No”. . . .
> 
> That is just a ludicrous out-of-ass assertion by an Apple fanboy desperately trying to reconcile their universe-shattering cognitive dissonance. It’s absurd to suggest that organizers of CanSecWest would disable security measures and then offer cash prizes to hack various platforms. This is a security community initiative with the aim of identifying and rectifying zero day vulnerabilities, and the exploits used are peer-reviewed and published after the vulnerabilities are addressed.
> 
> As well, [\*\* the 2008 contest regarding Safari:\*\*](http://www.mac-forums.com/forums/apple-rumors-reports/102560-mba-hacked-2-minutes-while-vista-ubuntu-stand-strong.html)
> 
> > [@](#):
> >
> > No one was able to execute code on any of the systems on Wednesday, the first day of the contest, when hacks were limited to over-the-network techniques on the operating systems themselves. But on the second day, the rules changed to allow attacks delivered by tricking someone to visit a maliciously crafted Web site, or open an e-mail.
> > 
> > That isn’t hacking, that is social engineering.
> 
> I cannot find anything saying a virus entered a Mac simply by opening a web page.

Your link above says exactly that, it’s just that the person describing it found it necessary to declare that attacks on mail clients or web browsers aren’t _really_ hacking, in order to preserve a belief in the intrinsic invulnerability of their platform which is held as an article of faith, even when it’s contrary to common sense. The protest that the “rules were changed” is meaningless, as the contest is traditionally structured to have different targets of attack on each day.

> [@Chronos](#):
>
> We’re not talking about things that propagate from infected machines to other machines. We’re talking about things that propagate from a website to machines that visit that website. For such a route of infection, what you see is what you get on the userbase.

Most malware is written with propagation in mind. Even for the small subset of malware which does not (say, exclusively limited to browser hijacking or pop-up display) Macs are not a practical target for much the same reason - rate of potential infection is not attractive enough to make the effort worthwhile, because the exploit will be noticed and patched before an attractive number of systems are affected.

The net result is the same, Apple or Linux users don’t have to worry about these sorts of attacks. It’s silly to argue that they’re impossible, though - minority systems actual security have exactly the same sorts of vulnerabilities - the immunity comes from their relative obscurity.

---

<div class="post-metadata">

**Author:** ![RaftPeople](https://avatars.discourse-cdn.com/v4/letter/r/6f9a4e/32.png) [@RaftPeople](https://boards.straightdope.com/u/RaftPeople)\
**Post date:** [January 31, 2012, 5:14pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/82 "2012-01-31T17:14:13Z")

</div>

> [@Chronos](#):
>
> Sure. My point is that it’s possible to build a truck that could move the Empire State Building, but no such truck actually exists, and thus it’s reasonable to say that the Empire State Building can’t be moved by truck. By analogy, it’s possible to create a webpage that would infect a Mac, but no such webpage actually exists, and thus it’s reasonable to say that a Mac can’t be infected by a webpage. Where does the analogy break down?

I think it breaks down in the following ways:

1. Someone did build a truck and it only took a few man weaks - it’s not as difficult as your analogy tries to imply

2. Just because you personally are unaware of a website with this type of malware doesn’t mean there aren’t any out there  
People that write these things for financial gain typically want them to be undetectable. That very attribute is giving you the sense that they must not exist, I think that is a naive conclusion given that we know people have demonstrated this type of malware.

---

<div class="post-metadata">

**Author:** ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)\
**Post date:** [January 31, 2012, 5:41pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/83 "2012-01-31T17:41:24Z")

</div>

> [@Kenm](#):
>
> From 2009, [**one of many sites**](http://www.mac-forums.com/forums/os-x-operating-system/167703-true-mac-os-x-hacked-under-20-seconds.html) with this information: As well, [**the 2008 contest regarding Safari:**](http://www.mac-forums.com/forums/apple-rumors-reports/102560-mba-hacked-2-minutes-while-vista-ubuntu-stand-strong.html)I cannot find anything saying a virus entered a Mac simply by opening a web page.

You will notice win7 also repelled day 1 efforts, they are not even bothering with direct peer to peer exploits for the last few years, the whole contest is attacking a machine by browsing or email.

From the wikipedia page

> [@](#):
>
> five seconds after the browser visited its specially crafted malicious web page, it had both launched the platform calculator application (a standard harmless payload to demonstrate that arbitrary code has been executed) and written a file to the hard disk (to demonstrate that the sandbox had been bypassed).

No they didnt install a virus, the simply proved you can force writing of files to the hard drive and run executable files. However if you can do that, you can do so with any program you might want to **including installation of viruses**.

No OS is somehow magically able to repel a virus because its a virus. A virus is a program if the program has permission to execute, it does, period.

---

<div class="post-metadata">

**Author:** ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)\
**Post date:** [January 31, 2012, 5:44pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/84 "2012-01-31T17:44:50Z")

</div>

> [@Kenm](#):
>
> No, it isn’t. The contest hacker was given the machine’s password.

Uh no, if they did they could have easily defeated it peer to peer.

---

<div class="post-metadata">

**Author:** ![Blakeyrat](https://avatars.discourse-cdn.com/v4/letter/b/ecd19e/32.png) [@Blakeyrat](https://boards.straightdope.com/u/Blakeyrat)\
**Post date:** [January 31, 2012, 6:09pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/85 "2012-01-31T18:09:17Z")

</div>

> [@Chronos](#):
>
> What’s the relevance of System 6 or 7 vira, anyway? Those were a completely, utterly, absolutely different operating system, from the ground up, from any modern Mac OS. All they prove is that virus writers will write viruses even for a minority OS, given the opportunity.

I wasn’t saying it was relevant to the topic (someone asked for a cite, so I dug one up!)

I was just:

1. Pointing out the absurdity (to me) that the company that made one of the LEAST secure OSes EVER now has a (apparently) unassailable rock-solid reputation for security
2. Reminiscing with a fellow Mac Classic user

---

<div class="post-metadata">

**Author:** ![Kenm](https://avatars.discourse-cdn.com/v4/letter/k/bc79bd/32.png) [@Kenm](https://boards.straightdope.com/u/Kenm)\
**Post date:** [January 31, 2012, 6:17pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/86 "2012-01-31T18:17:44Z")

</div>

OK. Giving the hacker all the information needed to enter the Mac after he failed for a full day without it (these “test rules” repeated each year), he broke in, which proves my Mac is as likely or more likely to load malware than any Windows system the tens or hundreds of thousands viruses and other malware written for that platform.

So a bank manager goes home for the night after turning off all burgler alarms and leaving the bank’s doors and vault open, and after pasting to the doorknob a map of the building’s layout with a huge “Welcome” in red letters printed at the top. The bank is robbed.

This starts a worldwide debate as to whether locked banks, locked vaults, functioning burgler alarms and no Welcome maps are any safer than a bank with all the security of a wide-open tent.

Got it.

---

<div class="post-metadata">

**Author:** ![Blakeyrat](https://avatars.discourse-cdn.com/v4/letter/b/ecd19e/32.png) [@Blakeyrat](https://boards.straightdope.com/u/Blakeyrat)\
**Post date:** [January 31, 2012, 6:28pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/87 "2012-01-31T18:28:09Z")

</div>

> [@Kenm](#):
>
> I ran a web search for vista beta viruses. Here are four links from the list of hits from that search, [\*\*[URL=“http://www.cheapest-computer-hardware-software.com/first-vista-virus.html”] **here** ](http://www.cheapest-computer-hardware-software.com/vista-beta-release-update.html)\*\*, [**here**](http://homepage.mac.com/rmansfield/thislamp/files/dee0be158ad161afef6f7b0d04a1ce88-46.html), [**here**](https://www.pcworld.com/article/122125/first_family_of_windows_vista_viruses_unleashed.html) and [**here**](http://www.v3.co.uk/v3-uk/news/1967136/windows-vista-virus-attack).
> 
> From 2009, [**one of many sites**](http://www.mac-forums.com/forums/os-x-operating-system/167703-true-mac-os-x-hacked-under-20-seconds.html) with this information: As well, [\*\* the 2008 contest regarding Safari:\*\*](http://www.mac-forums.com/forums/apple-rumors-reports/102560-mba-hacked-2-minutes-while-vista-ubuntu-stand-strong.html)I cannot find anything saying a virus entered a Mac simply by opening a web page.

Oh for cripes’ sake.

Ok, Pwn2Own is a STAGED contest. During the first stage, only network access to the (default configuration) OS is allowed-- I believe \*no \*machines have ever been hacked during the first stage before, but I’m not looking that up and I’m not providing a cite, so take that with a grain of salt.

The second stage, you are given a password and the goal is to prove you can break the “sandbox” the OS/browser creates between the Internet and the local filesystem. This is the stage at which the exact type of malware talked about in the original post of this thread is invariably demonstrated on Safari/OS X. The reason is, if you can defeat the sandbox, you can install executable code on the client’s machine. Obviously, you need to be able to log-in to the computer to do this, so obviously the password to the computer is provided.

There are also additional stages which aren’t relevant to the discussion.

Let’s be 100% clear:

1. Nobody’s saying Apple is completely incompetent at basic OS security (i.e. they lose stage 1 of Pwn2Own), that’s a ridiculous assertion. Don’t get your Apple-loving underpants in a bunch over this. That said, there is a lot of room for improvement from Apple on this front, and I would argue that (measured objectively) fully-updated OS X is not as secure as fully-updated Windows 7.

2. Pwn2Own provides the User password because, for \*the exact type of attack we’re talking about \*(that is, a user visiting a webpage, not a remote code execution), they need to log into the machine to open the browser and visit the damned webpage. Duh. Of course the password is provided. _That is the point._

3. Regardless of the security of OS X, it’s secure enough to defeat the casual “write it for a lark” virus writers, and doesn’t have the installed base to be desirable to the criminal virus writers. The guys winning Pwn2Own are “white hat” hackers, usually ones who have already reported the security hole to Apple, or who do so immediate after winning the contest. In one case, Pwn2Own was won using an exploit that Apple had already been made aware of weeks before, but at the time of the contest they still hadn’t patched it.

But the answer to the question asked in the original post of this thread is still yes. Yes, it’s possible. Yes, that exact scenario has been demonstrated-- several years in a row-- at Pwn2Own and elsewhere. Yes, yes, yes.

---

<div class="post-metadata">

**Author:** ![Blakeyrat](https://avatars.discourse-cdn.com/v4/letter/b/ecd19e/32.png) [@Blakeyrat](https://boards.straightdope.com/u/Blakeyrat)\
**Post date:** [January 31, 2012, 6:35pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/88 "2012-01-31T18:35:12Z")

</div>

> [@Kenm](#):
>
> OK. Giving the hacker all the information needed to enter the Mac after he failed for a full day without it (these “test rules” repeated each year), he broke in, which proves my Mac is as likely or more likely to load malware than any Windows system the tens or hundreds of thousands viruses and other malware written for that platform.

We’re not talking about “entering” the Mac (whatever that even means), you’re moving the goalposts. We’re talking about the Mac user visiting a website and, with no additional action on their part, ending up with a malicious program installed.

To demonstrate that exploit, you have to be able to log in to the Mac to visit the website in the first place. So yes, of course they give out the Mac’s password. How else could it possibly work?

---

<div class="post-metadata">

**Author:** ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)\
**Post date:** [January 31, 2012, 6:39pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/89 "2012-01-31T18:39:41Z")

</div>

> [@Finagle](#):
>
> To me, this would imply that Macs would be an even more appealing target. Especially because the kinds of hackers who would revel in this challenge are not “script kiddies” who attempt to hack systems using a cookbook of known exploits, but people who actually are willing to do the heavy lifting of creating new ones.

The next part of the problem is you have to move fast, new exploits are discovered all the time and are usually fairly quickly patched. So you basically have to

Know the OS well enough to find exploits on your own

Find a new exploit.

Find a way to propagate it

Exploit Opal

Benefit from it/seek recognition before its discovered by others and/or patched.

Therefore you end up needing a team to work quickly, teams usually cost money.

Every time you add another layer of complexity you make it less likely that someone to succeed. Only a small fraction of all users are mac users, a tiny fraction of those can program in mac environments, a tiny fraction of those know OS writing intimately enough to pick apart the OS, and only a small fraction of those are so inclined to do so.

You have alot of forces working against a virus, and not all viruses work well enough to infect a broad enough base. I have a certain begrudging respect for the people that do this kind of stuff, it is not easy.

---

<div class="post-metadata">

**Author:** ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)\
**Post date:** [January 31, 2012, 6:41pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/90 "2012-01-31T18:41:53Z")

</div>

> [@Blakeyrat](#):
>
> We’re not talking about “entering” the Mac (whatever that even means), you’re moving the goalposts. We’re talking about the Mac user visiting a website and, with no additional action on their part, ending up with a malicious program installed.
> 
> To demonstrate that exploit, you have to be able to log in to the Mac to visit the website in the first place. So yes, of course they give out the Mac’s password. How else could it possibly work?

The contestant does not need the password. They can have a judge log into the machine and visit the website without the contestant knowing the password.

---

<div class="post-metadata">

**Author:** ![Kenm](https://avatars.discourse-cdn.com/v4/letter/k/bc79bd/32.png) [@Kenm](https://boards.straightdope.com/u/Kenm)\
**Post date:** [January 31, 2012, 6:42pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/91 "2012-01-31T18:42:12Z")

</div>

> [@Blakeyrat](#):
>
> Don’t get your Apple-loving underpants in a bunch over this.

For the record, I’m not an I love Apple, right or wrong/purple Kool-Aid drinker/Steve-Jobs-is-Christ Mac maniac.

There’s plenty about Apple in general and this OS in particular I dislike, and with each update the list grows longer. I’m considering Linux.

---

<div class="post-metadata">

**Author:** ![Napier](https://avatars.discourse-cdn.com/v4/letter/n/ce73a5/32.png) [@Napier](https://boards.straightdope.com/u/Napier)\
**Post date:** [January 31, 2012, 8:25pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/92 "2012-01-31T20:25:08Z")

</div>

Question about the Mac password comments: Do we mean an admin password? Or just the password of a user, without admin rights?

It would be harder to put malware on a Mac without using a password that had admin rights attached to it. If users can prevent some exploit by not doing everyday work with admin rights, it’s worth working this way (I always have).

---

<div class="post-metadata">

**Author:** ![Roland\_Orzabal](https://avatars.discourse-cdn.com/v4/letter/r/c2a13f/32.png) [@Roland\_Orzabal](https://boards.straightdope.com/u/Roland_Orzabal)\
**Post date:** [January 31, 2012, 9:04pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/93 "2012-01-31T21:04:19Z")

</div>

**beowulff** , I actually quite like your Pope analogy, because it can be extended to illustrate the problem a lot of people are having with your position.

As you posit, it is extremely unlikely that the Pope is currently infected with AIDS. If you were to have sex with the Pope today, you could be pretty much certain that you’d remain disease-free, far moreso than if you banged your average streetwalker.

Now, imagine that fact is used to successfully convince every potential john in the world to have sex with the Pope instead. How do you think the odds would stack up then?

Same deal with Macs. Yes, if you personally were using a Mac right this moment, you would have a lesser chance of a passive malware infection than someone using an unprotected Windows machine. The problem is, that rationale isn’t sustainable. Convince enough people to go over to the Mac side, and the protection you’d gained from security-by-obscurity falls apart as malware authors target that platform instead.

I know your original question dealt only with the practicalities of the current landscape, but I (and, I imagine, others) honestly can’t help but read further into it…besides fodder for a “switch to Macs” argument, what use could there be for that information?

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [January 31, 2012, 10:59pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/94 "2012-01-31T22:59:10Z")

</div>

Sure - at some time in the future it may be possible that the malware situation on OS X is as bad as Windows. I’ve never stated that OS X is immune to attack.  
**But today is not that day.**  
To imply that OS X users need to worry about contracting malware by browsing a website _today_ is FUD of the worst kind. There _ **are** _ threats that Mac users need to be concerned with, and those are IMHO, far more dangerous than any drive-by attack is likely to be. Trojans and other social engineering attacks are much harder to prevent, and are much more likely to seriously compromise a user’s security (e.g. - giving away your bank account information).  
So, I prefer to rank the threats, and spend 0% of my worry about drive-by attacks (while at the same time, following all of the Mac news sites to see if anything significant develops).

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [February 1, 2012, 12:09am UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/95 "2012-02-01T00:09:07Z")

</div>

Can it really be the case that two (or three, or any number really) quite different operating systems are, at a technical level, equally vulnerable to attacks? It seems unlikely the chips would just happen to fall that way.

---

<div class="post-metadata">

**Author:** ![Larry\_Mudd](https://avatars.discourse-cdn.com/v4/letter/l/f14d63/32.png) [@Larry\_Mudd](https://boards.straightdope.com/u/Larry_Mudd)\
**Post date:** [February 1, 2012, 3:58am UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/96 "2012-02-01T03:58:32Z")

</div>

> [@beowulff](#):
>
> To imply that OS X users need to worry about contracting malware by browsing a website _today_ is FUD of the worst kind.

Sure it would be - that’s probably why you won’t find anything in this thread apart from people factually answering a GQ (“Yes, it is _possible_,”) while taking care to explain that it is not a practical concern and elaborating on the reasons _why_ the current user experience is that you can indeed browse where you like without undue concern about a rogue website installing malware on your Mac.

To modify your Empire State Building analogy so that it is actually isomorphic to the positions taken in this thread:

> [@](#):
>
> Question: Is it possible to build a 100-storey building outside city limits, or is this something you only find in certain urban centers?  
> Answer: Yes, of course it’s possible, but for practical reasons developers will never consider it outside of city centers - it just never going to be profitable to undertake such a project.
> 
> Objection: It’s impossible, the ground is simply too soft as you approach the suburbs to support such a structure. And never mind about the eccentric Saudi that’s built a tower in a remote area every year for the past decade just as an ostentatious display, those aren’t really 100 storey buildings - they’re uninhabited.

---

<div class="post-metadata">

**Author:** ![The\_Niply\_Elder](https://avatars.discourse-cdn.com/v4/letter/t/8e8cbc/32.png) [@The\_Niply\_Elder](https://boards.straightdope.com/u/The_Niply_Elder)\
**Post date:** [February 1, 2012, 8:15am UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/97 "2012-02-01T08:15:06Z")

</div>

> [@Larry\_Mudd](#):
>
> Well, start with the vulnerability you intend to exploit. Like, say you observe that you can disguise a .vbs file with a phony .txt extension in certain flavours of Windows, when it’s received as an attachment in Outlook, and get code to execute that way. Hurrah! Now to spread your creation, you’re going to have the code send an e-mail with such a deceitful attachment (containing a copy of itself) to the first 100 e-mail addresses in the user’s Outlook contacts.

Now I know that the thread has advanced a bit since this comment, but this kind of false belief held quoted above really baffles me.

The key in the adobe thread: 100.

Huh? 100? Now why in the world would any body do that?  
Why would any programmer hard code a limit to a code loop?  
Hard coding is a no-no in programming standards, period.

Hard coding to fixed numbers in loops always leads to errors, why is why it’s never done.

It’s much safer to put dynamic limits, such as [pseudocode]email.addressbook.length - 1 [/pseudocode]

And fundamentally the ridiculousness of the above assertion hinges on the fact that people with last names starting with ABC are not more likely to be hit with malware than people with last names starting with XYZ.

In the end, the OS with the best engineering comes out on top. Unix and Linux have five decades worth of system engineering and philosophy strengthening every line of code against each other.

Windows is pure utter rotten dipalidated outmoded pathetic laughable ugly shit.

---

<div class="post-metadata">

**Author:** ![The\_Niply\_Elder](https://avatars.discourse-cdn.com/v4/letter/t/8e8cbc/32.png) [@The\_Niply\_Elder](https://boards.straightdope.com/u/The_Niply_Elder)\
**Post date:** [February 1, 2012, 8:21am UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/98 "2012-02-01T08:21:48Z")

</div>

.?

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [February 1, 2012, 1:29pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/99 "2012-02-01T13:29:36Z")

</div>

> [@The\_Niply\_Elder](#):
>
> Windows is pure utter rotten dipalidated outmoded pathetic laughable ugly shit.

Now do OS X. _Pleaeeese?_

---

<div class="post-metadata">

**Author:** ![Rhythmdvl](https://avatars.discourse-cdn.com/v4/letter/r/85f322/32.png) [@Rhythmdvl](https://boards.straightdope.com/u/Rhythmdvl)\
**Post date:** [February 1, 2012, 2:31pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/100 "2012-02-01T14:31:04Z")

</div>

Few observations:

I can’t tell whether OS or political threads attract more fanboys.

I maintain Macs, Linux and Win boxes in our home office. I’m such a slut.

After _X_ years of seeing the “Hi Opal” reference, I’d never seen it seem so … tawdry. Not sure why.

Chronos, one of the bastions of rigour, has completely stunned me with such a hastily and sloppily constructed analogy. Rather than dig in your heels, ditch the ESB/truck analogy and think of something more apt. Your point will still stand but you’d be rid of such a bizarre distraction.

%@\*#ing articles about technology that have no date information should be pitted. WTF people?

This is interesting. Emphasis in [original](http://countermeasures.trendmicro.eu/targetted-attack-designed-to-infect-both-macs-and-pcs/):

> [@](#):
>
> In this case, following the link would be a **Very Bad Idea** , because it will lead you to a malicious website designed to infect \*\*both Macs and PCs \*\*with a DNS changing Trojan which at the time of writing has low-to non-existent detection rates by security vendors (although Trend Micro customers would already have been protected from visiting the known malicious site using our Smart Protection Network).

[Previous page](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911.md?page=4)

[Next page](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911.md?page=6)
