# Are Macs susceptible to malware from merely visiting a website?

**URL:** <https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911>\
**Category:** Factual Questions\
**Created:** [January 27, 2012, 9:59pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911 "2012-01-27T21:59:53Z")\
**Posts on this page:** 13\
**Page:** 8

<div class="post-metadata">

**Author:** ![Larry\_Mudd](https://avatars.discourse-cdn.com/v4/letter/l/f14d63/32.png) [@Larry\_Mudd](https://boards.straightdope.com/u/Larry_Mudd)\
**Post date:** [April 5, 2012, 1:35am UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/141 "2012-04-05T01:35:38Z")

</div>

[Here is the specific update.](http://support.apple.com/kb/HT5228)

---

<div class="post-metadata">

**Author:** ![Francis\_Vaughan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/francis_vaughan/32/3093_2.png) [@Francis\_Vaughan](https://boards.straightdope.com/u/Francis_Vaughan)\
**Post date:** [April 5, 2012, 2:12am UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/142 "2012-04-05T02:12:14Z")

</div>

Yeah, Apple have not exactly covered themselves in glory with this one. Since they took over responsibility for Java on the Mac they have not kept pace with updates, and this one was fixed by Oracle in January, yet only now do Apple scramble to get a fix out. Being a long time Mac fanboi, I’m not pleased. With luck they will be stung by the adverse publicity this generates and lift their game. Exactly what will be done about sorting out existing infections remains to be seen. Apple need to have a really solid story about this.

---

<div class="post-metadata">

**Author:** ![RaftPeople](https://avatars.discourse-cdn.com/v4/letter/r/6f9a4e/32.png) [@RaftPeople](https://boards.straightdope.com/u/RaftPeople)\
**Post date:** [April 5, 2012, 4:42am UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/143 "2012-04-05T04:42:01Z")

</div>

> [@Fubaya](#):
>
> I just now got a chance to look at that and I don’t know what this is supposed to prove. It is basically a survey showing how long it takes for different operating systems to issue patches. Turns out microsoft is the quickest and Red Hat was second,…

While it’s important to fix things quickly, that metric says nothing about the number of vulnerabilities for a particular OS.

I think it’s ok to say MS is good at fixing, but to present that as an argument for Win being more secure than the other OS’s being compared is illogical.

---

<div class="post-metadata">

**Author:** ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)\
**Post date:** [April 5, 2012, 5:09pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/144 "2012-04-05T17:09:15Z")

</div>

> [@Fubaya](#):
>
> In 2010 there were 4 new Windows viruses _per minute_ and 0 for Linux. No one thought to make a single one that targeted half the servers on the internet?

Because Servers are not browsing the web  
Because Server admin teams don’t fall for “For $300 you can get lifetime virus cleanup services.”  
Because server admin teams often run in isolated test environments before rolling out to the working servers.

Its kinda like asking “Why don’t more people rob police stations, there is lots of cash, drugs, and guns there”

and thats just the locker room…😃 …even more in the evidence storage area.

---

<div class="post-metadata">

**Author:** ![Anaglyph](https://avatars.discourse-cdn.com/v4/letter/a/ed8c4c/32.png) [@Anaglyph](https://boards.straightdope.com/u/Anaglyph)\
**Post date:** [April 12, 2012, 9:18am UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/145 "2012-04-12T09:18:13Z")

</div>

There’s recently been [a Trojan reported](http://www.bbc.com/news/technology-17675314) that exploits a java security flaw in OSX v10.6 and 10.7, the [Java update](http://support.apple.com/kb/HT5244) released on April 3rd. is supposed to fix the java vulnerability by this “Flashback” malware

---

<div class="post-metadata">

**Author:** ![AaronX](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AaronX](https://boards.straightdope.com/u/AaronX)\
**Post date:** [April 25, 2012, 6:51am UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/146 "2012-04-25T06:51:37Z")

</div>

This article might be relevant.  
Apple Macs spreading Windows malware  
[http://www.todayonline.com/World/EDC120425-0000115/Apple-Macs-spreading-Windows-malware](http://www.todayonline.com/World/EDC120425-0000115/Apple-Macs-spreading-Windows-malware)

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [April 25, 2012, 11:19am UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/147 "2012-04-25T11:19:42Z")

</div>

550,000 Macs infected with [Flashback virus](http://www.h-online.com/security/news/item/Flashback-numbers-not-going-down-still-over-half-a-million-1547542.html)

> [@](#):
>
> Initial reports of drops in the number of systems infected with the Flashback Mac malware are being corrected – the adjusted number is now back to around 550,000 systems.

---

<div class="post-metadata">

**Author:** ![Kenm](https://avatars.discourse-cdn.com/v4/letter/k/bc79bd/32.png) [@Kenm](https://boards.straightdope.com/u/Kenm)\
**Post date:** [April 25, 2012, 7:07pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/148 "2012-04-25T19:07:13Z")

</div>

> [@AaronX](#):
>
> This article might be relevant.  
> Apple Macs spreading Windows malware  
> [http://www.todayonline.com/World/EDC120425-0000115/Apple-Macs-spreading-Windows-malware](http://www.todayonline.com/World/EDC120425-0000115/Apple-Macs-spreading-Windows-malware)

The revelation that Macs can pass on Windows viruses is like blowing the lid off the eons-old conspiracy of silence that water is wet.

An infected Windows machines sends an email to a Mac. The infection can do nothing to the Mac, but if the Mac forwards the infected email to another Windows box, the infection is spread to the second Windows box. This has been the case since Day 1.

“Revealing” this as new, or worse yet, news, is hilarious.

---

<div class="post-metadata">

**Author:** ![Blakeyrat](https://avatars.discourse-cdn.com/v4/letter/b/ecd19e/32.png) [@Blakeyrat](https://boards.straightdope.com/u/Blakeyrat)\
**Post date:** [April 25, 2012, 9:38pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/149 "2012-04-25T21:38:59Z")

</div>

> [@Arnold\_Winkelried](#):
>
> Yes, what I meant is that the file you download is usually an installer for the program and not the program itself.  
> Though, like I said, I just tried it with two programs I downloaded, and one of them did not show the message when I double-clicked on the “installer.exe”. I wonder why that is?

This is off-topic, but the answer is code-signing. Microsoft has a mechanism by which installers can “sign” themselves with an SSL certificate (much like a HTTPS website), and it trusts installers that are signed that way and doesn’t give you that dialog.

Then the question becomes, “well, owning a SSL cert doesn’t really make it secure, right?” which is a valid issue, but since it applies to every single HTTPS site on the web as well, Microsoft’s not any worse than anybody else about that.

I’m not sure if Apple has any form of code signing set up. If they do, and if the installer/application is signed, I wager it also would not ask about executing it.

---

<div class="post-metadata">

**Author:** ![Blakeyrat](https://avatars.discourse-cdn.com/v4/letter/b/ecd19e/32.png) [@Blakeyrat](https://boards.straightdope.com/u/Blakeyrat)\
**Post date:** [April 25, 2012, 9:49pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/150 "2012-04-25T21:49:20Z")

</div>

> [@The\_Niply\_Elder](#):
>
> Yes, I encounter this sort of thing very often too. This behavior is precisely the type of thing that supports my earlier argument that Windows does not have “baked-in” security features like Unix and Linux. Yes on the surface of things Windows has some sort of annoying popup that you click through. But very often it does not appear. My hypothesis is that this symptom comes from the same fundamental design rot that allows hackers everywhere violate Windows at will.
> 
> How is this kind of shit even possible? But it happens. And a million little variations of this kind of inconsistent behavior pervades Windows. You honestly cannot say with a straight face that Windows was designed with security in mind. Saying that it has security attached like a post it note is being a little too generous, a little too British overstatement 😉 .

Seriously?

Look, Windows trusts SSL-signed applications. This is no better or worse (from a security perspective) than Firefox trusting SSL-signed websites or SSL-signed Java applets.

Just because you don’t understand why Windows asks you for some applications and not for others doesn’t make it evidence of a lack of “baked-in security”, or that Microsoft’s programmers are bad at their jobs, or some kind of conspiracy on Microsoft’s part. It just means you don’t understand what’s going on.

As for your UAC complaint, it seems your problem in that case is that Windows 7 has _too much_ security, and won’t let your application get away with the crap it was getting away with on XP.

---

<div class="post-metadata">

**Author:** ![Mister\_Rik](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mister_rik/32/491_2.png) [@Mister\_Rik](https://boards.straightdope.com/u/Mister_Rik)\
**Post date:** [April 26, 2012, 2:25am UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/151 "2012-04-26T02:25:27Z")

</div>

> [@Blakeyrat](#):
>
> I’m not sure if Apple has any form of code signing set up. If they do, and if the installer/application is signed, I wager it also would not ask about executing it.

My Mac warns me every time I try to install something I’ve downloaded. However, it doesn’t warn about something being installed from a disk. I recently installed Adobe Photoshop CS5, and the installer also secretly installed a little 3rd-party utility called “Growl” that scans my whole Applications folder and looks for updates on the Internet. I didn’t know what this thing was that kept popping up alerts telling me about updates to this and that, so I found what it was and went to their web site. It turns out they were aware that it was getting automatically installed along with Photoshop, without user permission, and were kind of annoyed about that (and have told Adobe to desist). They had a handy uninstall utility for those of us who wanted to remove it.

---

<div class="post-metadata">

**Author:** ![johnpost](https://avatars.discourse-cdn.com/v4/letter/j/f17d59/32.png) [@johnpost](https://boards.straightdope.com/u/johnpost)\
**Post date:** [June 27, 2012, 3:52am UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/152 "2012-06-27T03:52:36Z")

</div>

they are no longer being called virus free by Apple.

---

<div class="post-metadata">

**Author:** ![old\_joe](https://avatars.discourse-cdn.com/v4/letter/o/58956e/32.png) [@old\_joe](https://boards.straightdope.com/u/old_joe)\
**Post date:** [June 27, 2012, 9:41pm UTC](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911/153 "2012-06-27T21:41:22Z")

</div>

Apple itself has changed its tune. as this article says

[Apple drops virus immunity claim for Macs](http://www.telegraph.co.uk/technology/apple/9355995/Apple-drops-virus-immunity-claim-for-Macs.html) so Apple no longer claims to be immune to virus’s (sp?)  
600,000 people got infected so we can now say that yes Macs get infected (big old roll eyes)!

PCmag says “Following April’s Flashback Trojan - which hit more than 550,000 Macs - Apple recently removed from its website the claim that its Mac operating system is not susceptible to PC viruses.”

So maybe now the fanboys can just stop, IT people have always known it would happen sooner or later. 500,000 to 600,000 infections would qualify for “out in the wild” I would think.

[Previous page](https://boards.straightdope.com/t/are-macs-susceptible-to-malware-from-merely-visiting-a-website/610911.md?page=7)
