[HN Gopher] macOS now scans for malware whenever it gets a chance
___________________________________________________________________
macOS now scans for malware whenever it gets a chance
Author : pjmlp
Score : 111 points
Date : 2022-09-01 19:43 UTC (3 hours ago)
(HTM) web link (eclecticlight.co)
(TXT) w3m dump (eclecticlight.co)
| kylehotchkiss wrote:
| Does this mean it's safe to get rid of MalwareBytes for good?
| Hard to understand if this protection is as comprehensive as
| MalwareBytes is offering.
| TechBro8615 wrote:
| I'm pretty happy with a combination of this malware scanning
| and some Objective See products [0] that can alert me to new
| network requests or strange behavior like dylib hijacking.
| Currently I'm running LuLu (firewall) and BlockBlock
| (persistence monitoring), and I occasionally run the other
| utilities when I get suspicious of something.
|
| [0] https://objective-see.org/tools.html
| kylehotchkiss wrote:
| Great idea! Blockblock seems really lightweight. I am a big
| fan of little snitch for firewall (paid though!)
| sitzkrieg wrote:
| my only hope is that this makes erm, certain people at least give
| pause in the future before posting "but windows defender cant be
| turned off and scans all the time" in any threads about windows
|
| nm instantly too late ;)
| [deleted]
| cpressland wrote:
| Our business primarily uses macOS but we use Microsoft Defender
| ATP because we're an Azure and Microsoft 365 house. The
| performance hit is absolutely insane but I've simply not had
| enough time to debug it and see if it can be tuned to something
| more reasonable.
|
| Installing Homebrew is probably the biggest example, without
| Defender ATP, probably ~3 minutes. With Defender ATP, upwards of
| 15.
|
| I'd love to convince the powers that be that XProtect is enough,
| but I'd need some way of measuring and auditing it. Any
| suggestions?
| encryptluks2 wrote:
| Homebrew is abysmally slow as is. It is a shame it has the most
| packages as it is the worst package manager out of Windows,
| Linux and Mac now that winget is GA.
| saagarjha wrote:
| MacPorts nominally has several times more packages than
| Homebrew.
| yamtaddle wrote:
| I've extensively used: apt/dpkg (Debian and Ubuntu), rpm
| (Mandrake, Red Hat, Fedora), portage (Gentoo), and MacPorts.
| I also have some experience with package management on Void,
| Arch, and FreeBSD. I wanna say I used some unofficial package
| manager on BeOS back in the day, too, and I'm pretty sure QNX
| had one though I don't remember much about those.
|
| HomeBrew is my favorite of them, overall. Though Portage is
| pretty damn great, for what it is.
| oneplane wrote:
| It's extremely hard because you're essentially trying to use
| absence of proof as proof of absence. ("There is no malware,
| therefore the anti malware worked")
|
| Even 'known' detections and preventions won't do it because
| you'd have to extrapolate if it wasn't detected, if prevention
| of anything was actually needed. Take a detection of a Excel v4
| Macro loader, that's great to detect and prevent with ATP, but
| doesn't do anything on a Mac, and doesn't do anything on most
| PC's either.
|
| This is similar to comparing Sophos vs. Trend Micro for
| example. The products do similar things, have similar goals and
| similar methods.
|
| Ultimately the true protection doesn't lie in what AV you have
| or what EDR vendor you select, but how you deal with inevitable
| infections and loss of service. If you can treat the loss of a
| laptop (be it theft, fire or ransomware) the same way,
| regardless of the reason of loss, you're good. That also means
| encryption at rest and DLP at runtime. Neither are going to be
| in the AV vendor's product.
|
| The same applies to malware ingress. If you have good controls
| on mail (even if just for attachment and BEC scams), that
| already saves you a ton of issues. And if you don't use
| filesystem shares like it's the 90's, that helps a ton as well,
| because now there is no OS-native spreading method using
| existing mounts.
|
| The list goes on and on, and ultimately the whole AV vendor
| thing is just a tiny speck in the grand scheme. The biggest gap
| would be your audit capabilities, and having any controls vs.
| having no controls at all.
|
| Something as simple as bare minimum hardening (FDE, MFA,
| autolock), OSQuery or Kolide for health/security posture
| checks, non-SMB/NFS file access, and proofpoint or mimecast in
| your mail flow will have a bigger impact on most corporate
| setups than any anti malware vendor can do.
|
| Depending on the skill and education level of your users, you
| might even consider self-selection controls. Personally I use
| the Objective-see tools, XProtect and on-demand Sophos. The
| type of work I do doesn't fare well with traditional AV, but
| because I don't mind binary allowlisting, persistence lockout
| popups etc. and periodically confirming that I didn't miss
| anything using Sophos, I can get my work done and be secure
| enough at the same time. When I work at a regulated company
| I'll just use their supplied workstations and bill them extra
| by the hour.
| resfirestar wrote:
| Defender ATP isn't really comparable to XProtect because it's
| providing your company with detailed logs of what's going on
| with the device - file operations, network connections, data
| about every program executed and the command line, and so on.
| That's why it slows down Homebrew so much, it's creating a ton
| of files every time you run it. Setting up exclusions for
| Homebrew's directories might help with performance, but I'd
| understand if they say no. Bad guys use Homebrew too.
| pdimitar wrote:
| I've noticed periodical load on my system for months now, maybe a
| year.
|
| I'm not okay with it. Cements my decision that my next
| workstation will be Linux. macOS is getting way too non-user-
| controllable.
| saagarjha wrote:
| What is it?
| yreg wrote:
| You can turn off system integrity protection if you want to...
| olyjohn wrote:
| Try using MacOS in an enterprise. They locked the fucking power
| settings on me, even though I use my own power at home. So it
| goes to sleep after 10 minutes with no mouse movement, drops
| the VPN and all my SSH sessions, and then forgets my monitor
| layout.
|
| Computers work pretty damn well most of the time, but as soon
| as enterprise IT gets their hands on it, they clog it up with
| poorly written, well marketed security software. We have shit
| like privilege managers running so that we can install
| "whitelisted" apps. Still have MS endpoint protection, which is
| a total piece of shit. All the MDM shit that runs in the
| background, some password sync manager, a goddamn locally
| installed proxy that hijacks all your web traffic. JAMF always
| in there fucking crashing and doing who knows what.
|
| And we migrated our laptops when our company was bought out.
| And so the entire security suite was completely different. All
| the old security software was removed, but left cruft, and
| extensions and shit all over the computer. All our computers
| run like total dogshit until an OS reload.
|
| All this bullshit that makes our productivity crawl to a halt,
| just so that they can check some boxes on a security audit.
| mattlondon wrote:
| This would explain the beach ball I keep getting several times a
| day now I guess.
| tjohns wrote:
| I have not seen this behavior on any of my Macs, and what
| you're describing is not normal.
|
| I'm not saying that you're necessarily wrong, but there are
| many different things that could also cause this. Some
| investigation would be in order before making that claim.
| (Spotlight indexing via mdworker is the usual first culprit for
| this kind of behavior, in my experience.)
|
| You should be able to see what's causing the extra load by
| keeping an eye on Activity Monitor.
| yamtaddle wrote:
| Last couple times I got tons of beachballs system-wide for no
| clear reason, it was because I was doing Android dev and had
| the emulator running, or, earlier, because I hadn't yet
| switched to Safari. Both FF and Chrome did that to me, though
| Chrome was slightly better about it.
| olyjohn wrote:
| > I have not seen this behavior on any of my Macs...
|
| > (Spotlight indexing via mdworker is the usual first culprit
| for this kind of behavior, in my experience.)
|
| So you've seen this behavior enough times that you have a fix
| for it, but you've never seen this behavior on any of your
| Macs? What is it?
| happyopossum wrote:
| "this behavior" presumably being XProtect causing numerous
| beachballs/day... C'mon - let's be a little less snarky and
| a little more charitable.
| saagarjha wrote:
| I'd take a spindump personally.
| upbeat_general wrote:
| Is there a way to disable the scanning that doesn't involve
| disabling SIP which prevents you from running iOS apps?
|
| macOS really seems to try to frustrate power-users with these
| non-optional security features. I even had to make a separate
| note document with the commands/references to disable the various
| security features. I don't understand why they choose to
| frustrate this audience by making it so difficult.
| ubermonkey wrote:
| What non-optional features are you referring to?
|
| I don't recall having to do anything too onerous to run
| whatever software I've wanted to run on my M1.
| saagarjha wrote:
| You can run iOS apps with SIP disabled. You just cannot run
| encrypted apps.
| Gigachad wrote:
| Are most apps not encrypted?
| tartoran wrote:
| Windows defender is scanning every time im building anything in
| visual studio during which everything on the machine grinds to a
| halt. I have no idea what's hoping to find but the experience on
| Windows is execrable. If im listening to some audio it starts
| stuttering... Very beefy machine too: thinkstation desktop, 64gb
| ram, 8 cores, etc etc. I stopped caring and started relaxing
| because it's out of my control. And you guessed it, it's my
| office machine. At home I banished windows altogether.
| Someone wrote:
| You can tell Defender to not scan certain directories. See
| https://support.microsoft.com/en-us/windows/add-an-
| exclusion...:
| xeromal wrote:
| Yup. Defender is like "Oh, this game you've played for 600
| hours? Let me deadlock it just in case it decided to turn into
| a virus"
| sitzkrieg wrote:
| if you are able, add your project folder as an exclusion, and
| maybe msbuild.exe or maybe cl etc. cant hurt
|
| tho i have to say ive never had defender (or any io hits) cause
| audio to stutter outside of impending bluescreen from garbage
| device driver tier crashes
| tartoran wrote:
| Corpo machine that I have no priviledges to. Thats why I gave
| up and learned to relax instead.
| GordonS wrote:
| FWIW, I've found Defender to be far less resource hungry
| that the likes of Mcaffee AV.
| dragonsky wrote:
| Yah Macffee, worse than most virus in the amount of
| energy and time it wastes.
| GordonS wrote:
| Is Hyper-V enabled on your machine? If so, you could
| install a Windows VM, in which you could do as you needed.
| shultays wrote:
| Then ask IT?
| rosnd wrote:
| But why? You get paid either way, what is the point?
| [deleted]
| GekkePrutser wrote:
| Bringing free antivirus to Mac is a good thing IMO, especially
| since Microsoft has been doing the same for years.
|
| I'd like to see much more behavioral analysis like the leading AV
| companies do, rather than just fingerprinting but it's a good
| start.
|
| One thing I don't like about Apple's approach to security is
| locking the user out, making the OS like a black box. For me the
| user should always retain the last word. Until now most of their
| work has been in this direction (and the direction of iOS) but
| I'm pleased to see they're looking more into mitigation rather
| than just prevention now.
| yamtaddle wrote:
| > One thing I don't like about Apple's approach to security is
| locking the user out, making the OS like a black box.
|
| You can still turn off _an awful lot_ of the security features
| in macOS. Some require a reboot, but still, the option 's there
| for developers and power-users, if they prefer or require
| riskier operation.
| GekkePrutser wrote:
| Yes but that's all or nothing then. And you lose out on some
| functionality.
|
| There is no way for me to put my own configuration in the
| system and still have it persist. For example I change things
| in sshd_config (to turn off password auth), and PAM.
|
| This is not OK, there should be a way for me to sign files so
| they are marked as valid.
|
| I don't think the read-only OS partition or the SIP is a bad
| idea. The bad part is that Apple is the only one who controls
| it.
| jen20 wrote:
| What about editing `/private/etc/ssh/sshd_config` does not
| persist for you?
| yamtaddle wrote:
| That file is overwritten on OS updates. At least, it used
| to be.
| yamtaddle wrote:
| > There is no way for me to put my own configuration in the
| system and still have it persist. For example I change
| things in sshd_config (to turn off password auth), and PAM.
|
| Does putting your custom options in something like:
|
| /etc/ssh/sshd_config.d/disable-passwords.conf
|
| no longer allow custom sshd config to survive updates? It's
| like if you're configuring daemons on, say, Ubuntu the
| "right way" so you don't get a ton of those prompts during
| apt-updates asking you if you want to accept the
| maintainer's config file or roll the dice and keep your
| own.
| alwillis wrote:
| _I don 't think the read-only OS partition or the SIP is a
| bad idea. The bad part is that Apple is the only one who
| controls it._
|
| Not true.
|
| Most of Apple's features are for keeping newbies and users
| who _think_ they know what they 're doing from shooting
| themselves in the foot.
|
| Apple documents how to disable SIP [1].
|
| [1]: https://developer.apple.com/documentation/security/dis
| abling...
| saagarjha wrote:
| You cannot re-enable SIP with a different root of trust,
| it's Apple or nothing. That's unfortunate.
| bayindirh wrote:
| > One thing I don't like about Apple's approach to security is
| locking the user out, making the OS like a black box.
|
| If we're talking about prevention of execution of unknown
| applications, that's not existent. Right click any application,
| click open, and it'll show you the same warning with "Open"
| added. So, you can always override Apple's warning.
|
| I like how macOS makes you read the warning box before making a
| decision, tbh. Yes, it's no Linux in terms of flexibility, and
| freedom, but I like the OS nevertheless.
| behnamoh wrote:
| People have been talking bs about Windows for a long time,
| but I think Apple will do even worse than what MS did to
| Windows. As something gets more popular (in this case,
| macOS), unfortunately it falls victim to corporate greed
| (telemetry, forced updates, etc.)
| xenospn wrote:
| to be fair, microsoft has been awful at this from the very
| beginning and got progressively worse.
| dlivingston wrote:
| It depends on the profit motivators. Windows fell victim to
| telemetry and forced updates because Microsoft's business
| model might not be what you think it is.
|
| Apple has a simple business model for macOS. It exists
| _solely_ as a vehicle for selling Macs - premium computers
| with (most importantly) a fat profit margin.
|
| Keeping the customer wanting to buy new Macs (and maybe
| that new iPhone...and that Apple TV+ subscription...) is
| what drives their OS to be, generally, much less user-
| hostile than Windows. The user _is_ the customer; whether
| through direct hardware sales or through the subscription
| purchases those hardware sales lead into.
|
| Microsoft, in turn, sells Windows to OEMs and the business
| world via bulk licensing. You, the consumer, buying a
| Windows 11 license is not what's funding Satya Nadella's
| new private island. It's Initech Corp. buying 5,000 PCs
| with Windows because "no one ever got fired for buying
| IBM."
|
| _Disclaimer: this is largely all speculation, and if I am
| off the mark, do let me know._
| NayamAmarshe wrote:
| Making tech accessible and safe for people who don't know any
| better should always be welcomed.
|
| But when you do that yet hide things from people who do know
| better, you're not making tech accessible, you're making tech
| worse.
|
| I really don't like how these companies behave sometimes, their
| utopia involves people with 0% knowledge and 100% obsession.
| m463 wrote:
| > locking the user out
|
| I wish ios would allow me to firewall my phone, even from
| apple.
| inopinatus wrote:
| There are apps performing packet filtering by presenting as a
| VPN client. Can't stop Apple bypassing that when it wants to,
| however.
| kylehotchkiss wrote:
| Me too, little snitch for iOS would be fantastic at
| preventing so many apps from phoning home to analytics
| behnamoh wrote:
| I tried Mullvad VPN and chose "Block Ad URLS", but then
| iCloud sync stopped working!
| blacksmith_tb wrote:
| For that can't you use Private DNS / Encrypted DNS pointing
| to a PiHole or nextdns etc? My memory is that iOS you have
| to change the DNS settings for each network which is sort
| of a headache, but one-time at least.
| clairity wrote:
| that only works for network requests that use dns. some
| (including a number of apple & google services) go
| directly to an ip address, which is why a firewall like
| little snitch is still valuable beyond dns-based blockers
| like pihole, nextdns, and adguard (this is what i use on
| ios). you used to be able to install an application
| firewall on jailbroken iphones, but i don't think that's
| an option any more.
|
| on macos, i used to use hands off! from one periodic (and
| before that, metakine), but they've since disappeared. i
| now use lulu with pf firewall via murus lite as a backup,
| but may switch to little snitch again (used to have a
| license but was unable to upgrade it so switched to hands
| off! via a promo) for the better UX.
| green_on_black wrote:
| The issue is most users would be better served with a black
| box. If there's a way in, malice will get there, regardless of
| user and developer intent.
| noasaservice wrote:
| And this arrogant "we know better than you, plebes" is why I
| don't buy apple shit.
|
| My money, my hardware, my control. Not negotiable.
|
| (Edit: this applies to all their offerings. Iphone is already
| anti-user and effectively a rented device. Mac laptops are
| heading that way. Do not want.)
| _ph_ wrote:
| They give you pretty much all control of the hardware. The
| ultimate sign of that is, that you can install Linux on the
| ARM macs now. Apple even made some steps to make this
| reasonable. You do have full control of the hardware.
|
| On the other side, a booted macOS has certain limitations
| in place. Not even root is able to write to certain
| partitions and such stuff. This is not because "we know
| better", but because these limits provide some fundamental
| security. A partition which cannot be written to, cannot be
| modified by malware.
|
| You can boot into a mode where this protection does not
| exist, but for productive usage, it is a good idea to have
| that protection in place.
| gffrd wrote:
| ... and that's your choice!
|
| In their defense--both Apple's, and the public's--the
| general populace is, like, 99.99% OK with outsourcing those
| choices to a company that's way more
| interested/invested/capable in knowing better than they
| would be on their own.
|
| Is it arrogant if the public continues to reward/reaffirm
| it?
| oarsinsync wrote:
| > In their defense--both Apple's, and the public's--the
| general populace is, like, 99.99% OK
|
| Majority of customers purchase one of two options in a
| duopoly isn't really an endorsement of the options, but
| rather a critique on the lack of options.
| mhh__ wrote:
| I agree it's mostly between the customer and apple but
| just remember that most people don't know anything about
| computers at all.
|
| Even people who have _heard_ of Linux for example 's
| opinions will have mostly been set by people shilling for
| Windows and so on
| noasaservice wrote:
| This is a textbook example of
| https://en.m.wikipedia.org/wiki/Argumentum_ad_populum
|
| Or bandwagon fallacy.
|
| To use that as evidence is absurd and wrong at best.
| kriops wrote:
| Is it, though? Or is it evidence that Apple's products
| wins out on usability for the majority of use cases that
| are relevant to their customers? That is compared to
| Linux, where you have to make an active effort to acheive
| the same level of usability.
| _gabe_ wrote:
| Same here. I just finished reading Raymond Chen's _The Old
| New Thing_ , and it was really reassuring to read about the
| choices the Windows developers would make to always give
| the _user_ the final choice over the _programs_. Hopefully
| Microsoft still has devs like these working their on the OS
| now.
| rosnd wrote:
| BLKNSLVR wrote:
| Sad nerd here thinking that if your comment were true
| then it's also only sad nerds aren't turning into dull-
| eyed mindless drones tiktok'ing themselves into the bliss
| of ignorant oblivion of the total lack of agency in ones
| own life.
| rosnd wrote:
| There's also the option of doing better things with your
| life and not worrying about what software your phone
| runs, in reality your life has to be really fucking
| boring for it to make any difference whatsoever.
| yamtaddle wrote:
| You can turn off most of the stuff that's keeping it out of
| "your control". I write "most" only to hedge--I'm not aware
| of any that you can't (though there may be some).
| Sirened wrote:
| this might be dumb, but why do we even use scanning in this day
| and age? Why not use kernel callbacks which notify when
| executables and files load for, say, the first time after being
| modified? Surely that'd be less race-y and waste less battery?
| SmellyPotato22 wrote:
| Totally that's why Apple made endpoint security for security
| vendors. You can even pipe the events from the kernel with
| "sudo eslogger exec | jq" on the new macOS
|
| https://developer.apple.com/documentation/endpointsecurity
| jokethrowaway wrote:
| They already do it, that's all the notifications when you first
| run an executable.
| kube-system wrote:
| I just 'executed' an eicar test file in a terminal and
| nothing stepped in.
| simonh wrote:
| If you have XProtect active, it should step in if you try
| and open the EICAR file in a text editor. It may not if you
| try and "run" the file because it's not an executable
| binary. Have you disabled Gatekeeper?
| Sirened wrote:
| Right, which is why I'm baffled as to why they'd introduce
| scanning in 2022
| NateLawson wrote:
| A semi-legit app can later drop malicious code and run it.
| Think of a repackaged OSS project or pirated software that
| has an auto-updater built in.
| lalopalota wrote:
| which would be a new file, or one that has been modified
| since it was last run. which would be handled by the
| first run protection.
| melony wrote:
| In case of zero days, the AV can block the file before it
| exploits the kernel (or whatever other vector)
| GekkePrutser wrote:
| But this doesn't scan for zero-days, only for several
| major known malwares.
|
| If you want to catch real zero-days, you have to approach
| things very differently. Do behavioral analytics, seeing
| what a process is up to and if it's poking into things it
| shouldn't.
|
| Many leading AV suppliers like SentinelOne, Cylance,
| Crowdstrike do this and are very successful at it.
| However Apple is just starting in the antimalware market
| so I forgive them that they're just scanning for some
| known-bads for now.
| radicaldreamer wrote:
| I'm sure it works a lot better when alerts result in a
| human looking at the issue.
| simonh wrote:
| It will catch an infected file that simply passes through
| the computer without being opened or executed.
| robryk wrote:
| What do you mean by "passes"? Unless it's a file on a
| removable medium or a remote fs, it has to be created,
| which requires opening it. Scanning removable media upon
| insertion and remote fses upon mounting is going to look
| mighty suspicious and, in the latter case, be cover for
| data exfiltration.
| zibby8 wrote:
| What if the list of known malware changes to include a file
| already on the computer?
| jokethrowaway wrote:
| I spotted this crap in my activity monitor consuming tons of CPU
| and battery for short burst the other day.
|
| Glad to know it's not a malware, but it sucks not having control
| on your system
| culturestate wrote:
| _> it sucks not having control on your system_
|
| I obviously don't recommend this, but if you turn off SIP it'll
| also disable XProtect.
| tjohns wrote:
| There are command line knobs to turn these features off. You
| can disable SIP, or you can disable the system policy (which
| disables Gatekeeper and XProtect).
|
| It's definitely a case of "just because you _can_ , doesn't
| mean you _should_ ".
| user3939382 wrote:
| I don't use AV and I've never gotten a virus on my machine
| regardless of OS, except when I was 12 compiling virus code from
| the ezine 40Hex. I don't run untrusted executables, seems simple
| to me. Then I see my non-technical friends and family with 90
| icons on their desktop and 6 years of files in their Downloads
| folder and you see how it happens.
| TillE wrote:
| There was a really bad Dark Ages of remote exploits which
| peaked around the early Windows XP era. The OS itself and
| Internet Explorer were a horror show.
|
| Other than that, yes, it's been fairly rare to have malware
| infections that don't start with tricking the user into
| executing a binary, though it certainly can happen.
| sealeck wrote:
| What about exploits like bugs in compression algorithms or
| Javascript (with speculative execution)?
| user3939382 wrote:
| It's possible, definitely. I've had some amount of luck. But
| I think if we had good measurements we'd find that getting a
| virus through those means on personal machines is rare.
| olyjohn wrote:
| What about exploits that target the malware scanner itself?
| NonNefarious wrote:
| "system tools for tackling malware were essentially limited to
| XProtect and MRT"
|
| When did those arrive? On what OS versions?
| latexr wrote:
| XProtect has been there since Snow Leopard, released thirteen
| years ago:
| https://www.macworld.com/article/199817/snowleopard_malware....
| ntauthority wrote:
| MRT is the Windows Malicious Software Removal Tool which has
| been distributed via Windows Update since around 2005.
| NateLawson wrote:
| Xprotect is part of GateKeeper, which arrived in Mountain Lion
| (and late versions of Lion).
| kelnos wrote:
| > _XProtect Remediator_
|
| Wow, Apple marketing was really asleep at the wheel when someone
| named this one.
| [deleted]
| SllX wrote:
| They don't market it.
| [deleted]
| saagarjha wrote:
| It's an internal tool. It falls under the umbrella of
| "Gatekeeper".
| dane-pgp wrote:
| Unfortunately the name XDefense was already taken by Nintendo.
|
| https://bulbapedia.bulbagarden.net/wiki/X_Defense
| TedShiller wrote:
| not really
___________________________________________________________________
(page generated 2022-09-01 23:00 UTC)