[HN Gopher] macOS now scans for malware whenever it gets a chance
       ___________________________________________________________________
        
       macOS now scans for malware whenever it gets a chance
        
       Author : pjmlp
       Score  : 111 points
       Date   : 2022-09-01 19:43 UTC (3 hours ago)
        
 (HTM) web link (eclecticlight.co)
 (TXT) w3m dump (eclecticlight.co)
        
       | kylehotchkiss wrote:
       | Does this mean it's safe to get rid of MalwareBytes for good?
       | Hard to understand if this protection is as comprehensive as
       | MalwareBytes is offering.
        
         | TechBro8615 wrote:
         | I'm pretty happy with a combination of this malware scanning
         | and some Objective See products [0] that can alert me to new
         | network requests or strange behavior like dylib hijacking.
         | Currently I'm running LuLu (firewall) and BlockBlock
         | (persistence monitoring), and I occasionally run the other
         | utilities when I get suspicious of something.
         | 
         | [0] https://objective-see.org/tools.html
        
           | kylehotchkiss wrote:
           | Great idea! Blockblock seems really lightweight. I am a big
           | fan of little snitch for firewall (paid though!)
        
       | sitzkrieg wrote:
       | my only hope is that this makes erm, certain people at least give
       | pause in the future before posting "but windows defender cant be
       | turned off and scans all the time" in any threads about windows
       | 
       | nm instantly too late ;)
        
         | [deleted]
        
       | cpressland wrote:
       | Our business primarily uses macOS but we use Microsoft Defender
       | ATP because we're an Azure and Microsoft 365 house. The
       | performance hit is absolutely insane but I've simply not had
       | enough time to debug it and see if it can be tuned to something
       | more reasonable.
       | 
       | Installing Homebrew is probably the biggest example, without
       | Defender ATP, probably ~3 minutes. With Defender ATP, upwards of
       | 15.
       | 
       | I'd love to convince the powers that be that XProtect is enough,
       | but I'd need some way of measuring and auditing it. Any
       | suggestions?
        
         | encryptluks2 wrote:
         | Homebrew is abysmally slow as is. It is a shame it has the most
         | packages as it is the worst package manager out of Windows,
         | Linux and Mac now that winget is GA.
        
           | saagarjha wrote:
           | MacPorts nominally has several times more packages than
           | Homebrew.
        
           | yamtaddle wrote:
           | I've extensively used: apt/dpkg (Debian and Ubuntu), rpm
           | (Mandrake, Red Hat, Fedora), portage (Gentoo), and MacPorts.
           | I also have some experience with package management on Void,
           | Arch, and FreeBSD. I wanna say I used some unofficial package
           | manager on BeOS back in the day, too, and I'm pretty sure QNX
           | had one though I don't remember much about those.
           | 
           | HomeBrew is my favorite of them, overall. Though Portage is
           | pretty damn great, for what it is.
        
         | oneplane wrote:
         | It's extremely hard because you're essentially trying to use
         | absence of proof as proof of absence. ("There is no malware,
         | therefore the anti malware worked")
         | 
         | Even 'known' detections and preventions won't do it because
         | you'd have to extrapolate if it wasn't detected, if prevention
         | of anything was actually needed. Take a detection of a Excel v4
         | Macro loader, that's great to detect and prevent with ATP, but
         | doesn't do anything on a Mac, and doesn't do anything on most
         | PC's either.
         | 
         | This is similar to comparing Sophos vs. Trend Micro for
         | example. The products do similar things, have similar goals and
         | similar methods.
         | 
         | Ultimately the true protection doesn't lie in what AV you have
         | or what EDR vendor you select, but how you deal with inevitable
         | infections and loss of service. If you can treat the loss of a
         | laptop (be it theft, fire or ransomware) the same way,
         | regardless of the reason of loss, you're good. That also means
         | encryption at rest and DLP at runtime. Neither are going to be
         | in the AV vendor's product.
         | 
         | The same applies to malware ingress. If you have good controls
         | on mail (even if just for attachment and BEC scams), that
         | already saves you a ton of issues. And if you don't use
         | filesystem shares like it's the 90's, that helps a ton as well,
         | because now there is no OS-native spreading method using
         | existing mounts.
         | 
         | The list goes on and on, and ultimately the whole AV vendor
         | thing is just a tiny speck in the grand scheme. The biggest gap
         | would be your audit capabilities, and having any controls vs.
         | having no controls at all.
         | 
         | Something as simple as bare minimum hardening (FDE, MFA,
         | autolock), OSQuery or Kolide for health/security posture
         | checks, non-SMB/NFS file access, and proofpoint or mimecast in
         | your mail flow will have a bigger impact on most corporate
         | setups than any anti malware vendor can do.
         | 
         | Depending on the skill and education level of your users, you
         | might even consider self-selection controls. Personally I use
         | the Objective-see tools, XProtect and on-demand Sophos. The
         | type of work I do doesn't fare well with traditional AV, but
         | because I don't mind binary allowlisting, persistence lockout
         | popups etc. and periodically confirming that I didn't miss
         | anything using Sophos, I can get my work done and be secure
         | enough at the same time. When I work at a regulated company
         | I'll just use their supplied workstations and bill them extra
         | by the hour.
        
         | resfirestar wrote:
         | Defender ATP isn't really comparable to XProtect because it's
         | providing your company with detailed logs of what's going on
         | with the device - file operations, network connections, data
         | about every program executed and the command line, and so on.
         | That's why it slows down Homebrew so much, it's creating a ton
         | of files every time you run it. Setting up exclusions for
         | Homebrew's directories might help with performance, but I'd
         | understand if they say no. Bad guys use Homebrew too.
        
       | pdimitar wrote:
       | I've noticed periodical load on my system for months now, maybe a
       | year.
       | 
       | I'm not okay with it. Cements my decision that my next
       | workstation will be Linux. macOS is getting way too non-user-
       | controllable.
        
         | saagarjha wrote:
         | What is it?
        
         | yreg wrote:
         | You can turn off system integrity protection if you want to...
        
         | olyjohn wrote:
         | Try using MacOS in an enterprise. They locked the fucking power
         | settings on me, even though I use my own power at home. So it
         | goes to sleep after 10 minutes with no mouse movement, drops
         | the VPN and all my SSH sessions, and then forgets my monitor
         | layout.
         | 
         | Computers work pretty damn well most of the time, but as soon
         | as enterprise IT gets their hands on it, they clog it up with
         | poorly written, well marketed security software. We have shit
         | like privilege managers running so that we can install
         | "whitelisted" apps. Still have MS endpoint protection, which is
         | a total piece of shit. All the MDM shit that runs in the
         | background, some password sync manager, a goddamn locally
         | installed proxy that hijacks all your web traffic. JAMF always
         | in there fucking crashing and doing who knows what.
         | 
         | And we migrated our laptops when our company was bought out.
         | And so the entire security suite was completely different. All
         | the old security software was removed, but left cruft, and
         | extensions and shit all over the computer. All our computers
         | run like total dogshit until an OS reload.
         | 
         | All this bullshit that makes our productivity crawl to a halt,
         | just so that they can check some boxes on a security audit.
        
       | mattlondon wrote:
       | This would explain the beach ball I keep getting several times a
       | day now I guess.
        
         | tjohns wrote:
         | I have not seen this behavior on any of my Macs, and what
         | you're describing is not normal.
         | 
         | I'm not saying that you're necessarily wrong, but there are
         | many different things that could also cause this. Some
         | investigation would be in order before making that claim.
         | (Spotlight indexing via mdworker is the usual first culprit for
         | this kind of behavior, in my experience.)
         | 
         | You should be able to see what's causing the extra load by
         | keeping an eye on Activity Monitor.
        
           | yamtaddle wrote:
           | Last couple times I got tons of beachballs system-wide for no
           | clear reason, it was because I was doing Android dev and had
           | the emulator running, or, earlier, because I hadn't yet
           | switched to Safari. Both FF and Chrome did that to me, though
           | Chrome was slightly better about it.
        
           | olyjohn wrote:
           | > I have not seen this behavior on any of my Macs...
           | 
           | > (Spotlight indexing via mdworker is the usual first culprit
           | for this kind of behavior, in my experience.)
           | 
           | So you've seen this behavior enough times that you have a fix
           | for it, but you've never seen this behavior on any of your
           | Macs? What is it?
        
             | happyopossum wrote:
             | "this behavior" presumably being XProtect causing numerous
             | beachballs/day... C'mon - let's be a little less snarky and
             | a little more charitable.
        
           | saagarjha wrote:
           | I'd take a spindump personally.
        
       | upbeat_general wrote:
       | Is there a way to disable the scanning that doesn't involve
       | disabling SIP which prevents you from running iOS apps?
       | 
       | macOS really seems to try to frustrate power-users with these
       | non-optional security features. I even had to make a separate
       | note document with the commands/references to disable the various
       | security features. I don't understand why they choose to
       | frustrate this audience by making it so difficult.
        
         | ubermonkey wrote:
         | What non-optional features are you referring to?
         | 
         | I don't recall having to do anything too onerous to run
         | whatever software I've wanted to run on my M1.
        
         | saagarjha wrote:
         | You can run iOS apps with SIP disabled. You just cannot run
         | encrypted apps.
        
           | Gigachad wrote:
           | Are most apps not encrypted?
        
       | tartoran wrote:
       | Windows defender is scanning every time im building anything in
       | visual studio during which everything on the machine grinds to a
       | halt. I have no idea what's hoping to find but the experience on
       | Windows is execrable. If im listening to some audio it starts
       | stuttering... Very beefy machine too: thinkstation desktop, 64gb
       | ram, 8 cores, etc etc. I stopped caring and started relaxing
       | because it's out of my control. And you guessed it, it's my
       | office machine. At home I banished windows altogether.
        
         | Someone wrote:
         | You can tell Defender to not scan certain directories. See
         | https://support.microsoft.com/en-us/windows/add-an-
         | exclusion...:
        
         | xeromal wrote:
         | Yup. Defender is like "Oh, this game you've played for 600
         | hours? Let me deadlock it just in case it decided to turn into
         | a virus"
        
         | sitzkrieg wrote:
         | if you are able, add your project folder as an exclusion, and
         | maybe msbuild.exe or maybe cl etc. cant hurt
         | 
         | tho i have to say ive never had defender (or any io hits) cause
         | audio to stutter outside of impending bluescreen from garbage
         | device driver tier crashes
        
           | tartoran wrote:
           | Corpo machine that I have no priviledges to. Thats why I gave
           | up and learned to relax instead.
        
             | GordonS wrote:
             | FWIW, I've found Defender to be far less resource hungry
             | that the likes of Mcaffee AV.
        
               | dragonsky wrote:
               | Yah Macffee, worse than most virus in the amount of
               | energy and time it wastes.
        
             | GordonS wrote:
             | Is Hyper-V enabled on your machine? If so, you could
             | install a Windows VM, in which you could do as you needed.
        
             | shultays wrote:
             | Then ask IT?
        
               | rosnd wrote:
               | But why? You get paid either way, what is the point?
        
         | [deleted]
        
       | GekkePrutser wrote:
       | Bringing free antivirus to Mac is a good thing IMO, especially
       | since Microsoft has been doing the same for years.
       | 
       | I'd like to see much more behavioral analysis like the leading AV
       | companies do, rather than just fingerprinting but it's a good
       | start.
       | 
       | One thing I don't like about Apple's approach to security is
       | locking the user out, making the OS like a black box. For me the
       | user should always retain the last word. Until now most of their
       | work has been in this direction (and the direction of iOS) but
       | I'm pleased to see they're looking more into mitigation rather
       | than just prevention now.
        
         | yamtaddle wrote:
         | > One thing I don't like about Apple's approach to security is
         | locking the user out, making the OS like a black box.
         | 
         | You can still turn off _an awful lot_ of the security features
         | in macOS. Some require a reboot, but still, the option 's there
         | for developers and power-users, if they prefer or require
         | riskier operation.
        
           | GekkePrutser wrote:
           | Yes but that's all or nothing then. And you lose out on some
           | functionality.
           | 
           | There is no way for me to put my own configuration in the
           | system and still have it persist. For example I change things
           | in sshd_config (to turn off password auth), and PAM.
           | 
           | This is not OK, there should be a way for me to sign files so
           | they are marked as valid.
           | 
           | I don't think the read-only OS partition or the SIP is a bad
           | idea. The bad part is that Apple is the only one who controls
           | it.
        
             | jen20 wrote:
             | What about editing `/private/etc/ssh/sshd_config` does not
             | persist for you?
        
               | yamtaddle wrote:
               | That file is overwritten on OS updates. At least, it used
               | to be.
        
             | yamtaddle wrote:
             | > There is no way for me to put my own configuration in the
             | system and still have it persist. For example I change
             | things in sshd_config (to turn off password auth), and PAM.
             | 
             | Does putting your custom options in something like:
             | 
             | /etc/ssh/sshd_config.d/disable-passwords.conf
             | 
             | no longer allow custom sshd config to survive updates? It's
             | like if you're configuring daemons on, say, Ubuntu the
             | "right way" so you don't get a ton of those prompts during
             | apt-updates asking you if you want to accept the
             | maintainer's config file or roll the dice and keep your
             | own.
        
             | alwillis wrote:
             | _I don 't think the read-only OS partition or the SIP is a
             | bad idea. The bad part is that Apple is the only one who
             | controls it._
             | 
             | Not true.
             | 
             | Most of Apple's features are for keeping newbies and users
             | who _think_ they know what they 're doing from shooting
             | themselves in the foot.
             | 
             | Apple documents how to disable SIP [1].
             | 
             | [1]: https://developer.apple.com/documentation/security/dis
             | abling...
        
               | saagarjha wrote:
               | You cannot re-enable SIP with a different root of trust,
               | it's Apple or nothing. That's unfortunate.
        
         | bayindirh wrote:
         | > One thing I don't like about Apple's approach to security is
         | locking the user out, making the OS like a black box.
         | 
         | If we're talking about prevention of execution of unknown
         | applications, that's not existent. Right click any application,
         | click open, and it'll show you the same warning with "Open"
         | added. So, you can always override Apple's warning.
         | 
         | I like how macOS makes you read the warning box before making a
         | decision, tbh. Yes, it's no Linux in terms of flexibility, and
         | freedom, but I like the OS nevertheless.
        
           | behnamoh wrote:
           | People have been talking bs about Windows for a long time,
           | but I think Apple will do even worse than what MS did to
           | Windows. As something gets more popular (in this case,
           | macOS), unfortunately it falls victim to corporate greed
           | (telemetry, forced updates, etc.)
        
             | xenospn wrote:
             | to be fair, microsoft has been awful at this from the very
             | beginning and got progressively worse.
        
             | dlivingston wrote:
             | It depends on the profit motivators. Windows fell victim to
             | telemetry and forced updates because Microsoft's business
             | model might not be what you think it is.
             | 
             | Apple has a simple business model for macOS. It exists
             | _solely_ as a vehicle for selling Macs - premium computers
             | with (most importantly) a fat profit margin.
             | 
             | Keeping the customer wanting to buy new Macs (and maybe
             | that new iPhone...and that Apple TV+ subscription...) is
             | what drives their OS to be, generally, much less user-
             | hostile than Windows. The user _is_ the customer; whether
             | through direct hardware sales or through the subscription
             | purchases those hardware sales lead into.
             | 
             | Microsoft, in turn, sells Windows to OEMs and the business
             | world via bulk licensing. You, the consumer, buying a
             | Windows 11 license is not what's funding Satya Nadella's
             | new private island. It's Initech Corp. buying 5,000 PCs
             | with Windows because "no one ever got fired for buying
             | IBM."
             | 
             |  _Disclaimer: this is largely all speculation, and if I am
             | off the mark, do let me know._
        
         | NayamAmarshe wrote:
         | Making tech accessible and safe for people who don't know any
         | better should always be welcomed.
         | 
         | But when you do that yet hide things from people who do know
         | better, you're not making tech accessible, you're making tech
         | worse.
         | 
         | I really don't like how these companies behave sometimes, their
         | utopia involves people with 0% knowledge and 100% obsession.
        
         | m463 wrote:
         | > locking the user out
         | 
         | I wish ios would allow me to firewall my phone, even from
         | apple.
        
           | inopinatus wrote:
           | There are apps performing packet filtering by presenting as a
           | VPN client. Can't stop Apple bypassing that when it wants to,
           | however.
        
           | kylehotchkiss wrote:
           | Me too, little snitch for iOS would be fantastic at
           | preventing so many apps from phoning home to analytics
        
             | behnamoh wrote:
             | I tried Mullvad VPN and chose "Block Ad URLS", but then
             | iCloud sync stopped working!
        
             | blacksmith_tb wrote:
             | For that can't you use Private DNS / Encrypted DNS pointing
             | to a PiHole or nextdns etc? My memory is that iOS you have
             | to change the DNS settings for each network which is sort
             | of a headache, but one-time at least.
        
               | clairity wrote:
               | that only works for network requests that use dns. some
               | (including a number of apple & google services) go
               | directly to an ip address, which is why a firewall like
               | little snitch is still valuable beyond dns-based blockers
               | like pihole, nextdns, and adguard (this is what i use on
               | ios). you used to be able to install an application
               | firewall on jailbroken iphones, but i don't think that's
               | an option any more.
               | 
               | on macos, i used to use hands off! from one periodic (and
               | before that, metakine), but they've since disappeared. i
               | now use lulu with pf firewall via murus lite as a backup,
               | but may switch to little snitch again (used to have a
               | license but was unable to upgrade it so switched to hands
               | off! via a promo) for the better UX.
        
         | green_on_black wrote:
         | The issue is most users would be better served with a black
         | box. If there's a way in, malice will get there, regardless of
         | user and developer intent.
        
           | noasaservice wrote:
           | And this arrogant "we know better than you, plebes" is why I
           | don't buy apple shit.
           | 
           | My money, my hardware, my control. Not negotiable.
           | 
           | (Edit: this applies to all their offerings. Iphone is already
           | anti-user and effectively a rented device. Mac laptops are
           | heading that way. Do not want.)
        
             | _ph_ wrote:
             | They give you pretty much all control of the hardware. The
             | ultimate sign of that is, that you can install Linux on the
             | ARM macs now. Apple even made some steps to make this
             | reasonable. You do have full control of the hardware.
             | 
             | On the other side, a booted macOS has certain limitations
             | in place. Not even root is able to write to certain
             | partitions and such stuff. This is not because "we know
             | better", but because these limits provide some fundamental
             | security. A partition which cannot be written to, cannot be
             | modified by malware.
             | 
             | You can boot into a mode where this protection does not
             | exist, but for productive usage, it is a good idea to have
             | that protection in place.
        
             | gffrd wrote:
             | ... and that's your choice!
             | 
             | In their defense--both Apple's, and the public's--the
             | general populace is, like, 99.99% OK with outsourcing those
             | choices to a company that's way more
             | interested/invested/capable in knowing better than they
             | would be on their own.
             | 
             | Is it arrogant if the public continues to reward/reaffirm
             | it?
        
               | oarsinsync wrote:
               | > In their defense--both Apple's, and the public's--the
               | general populace is, like, 99.99% OK
               | 
               | Majority of customers purchase one of two options in a
               | duopoly isn't really an endorsement of the options, but
               | rather a critique on the lack of options.
        
               | mhh__ wrote:
               | I agree it's mostly between the customer and apple but
               | just remember that most people don't know anything about
               | computers at all.
               | 
               | Even people who have _heard_ of Linux for example 's
               | opinions will have mostly been set by people shilling for
               | Windows and so on
        
               | noasaservice wrote:
               | This is a textbook example of
               | https://en.m.wikipedia.org/wiki/Argumentum_ad_populum
               | 
               | Or bandwagon fallacy.
               | 
               | To use that as evidence is absurd and wrong at best.
        
               | kriops wrote:
               | Is it, though? Or is it evidence that Apple's products
               | wins out on usability for the majority of use cases that
               | are relevant to their customers? That is compared to
               | Linux, where you have to make an active effort to acheive
               | the same level of usability.
        
             | _gabe_ wrote:
             | Same here. I just finished reading Raymond Chen's _The Old
             | New Thing_ , and it was really reassuring to read about the
             | choices the Windows developers would make to always give
             | the _user_ the final choice over the _programs_. Hopefully
             | Microsoft still has devs like these working their on the OS
             | now.
        
             | rosnd wrote:
        
               | BLKNSLVR wrote:
               | Sad nerd here thinking that if your comment were true
               | then it's also only sad nerds aren't turning into dull-
               | eyed mindless drones tiktok'ing themselves into the bliss
               | of ignorant oblivion of the total lack of agency in ones
               | own life.
        
               | rosnd wrote:
               | There's also the option of doing better things with your
               | life and not worrying about what software your phone
               | runs, in reality your life has to be really fucking
               | boring for it to make any difference whatsoever.
        
             | yamtaddle wrote:
             | You can turn off most of the stuff that's keeping it out of
             | "your control". I write "most" only to hedge--I'm not aware
             | of any that you can't (though there may be some).
        
       | Sirened wrote:
       | this might be dumb, but why do we even use scanning in this day
       | and age? Why not use kernel callbacks which notify when
       | executables and files load for, say, the first time after being
       | modified? Surely that'd be less race-y and waste less battery?
        
         | SmellyPotato22 wrote:
         | Totally that's why Apple made endpoint security for security
         | vendors. You can even pipe the events from the kernel with
         | "sudo eslogger exec | jq" on the new macOS
         | 
         | https://developer.apple.com/documentation/endpointsecurity
        
         | jokethrowaway wrote:
         | They already do it, that's all the notifications when you first
         | run an executable.
        
           | kube-system wrote:
           | I just 'executed' an eicar test file in a terminal and
           | nothing stepped in.
        
             | simonh wrote:
             | If you have XProtect active, it should step in if you try
             | and open the EICAR file in a text editor. It may not if you
             | try and "run" the file because it's not an executable
             | binary. Have you disabled Gatekeeper?
        
           | Sirened wrote:
           | Right, which is why I'm baffled as to why they'd introduce
           | scanning in 2022
        
             | NateLawson wrote:
             | A semi-legit app can later drop malicious code and run it.
             | Think of a repackaged OSS project or pirated software that
             | has an auto-updater built in.
        
               | lalopalota wrote:
               | which would be a new file, or one that has been modified
               | since it was last run. which would be handled by the
               | first run protection.
        
             | melony wrote:
             | In case of zero days, the AV can block the file before it
             | exploits the kernel (or whatever other vector)
        
               | GekkePrutser wrote:
               | But this doesn't scan for zero-days, only for several
               | major known malwares.
               | 
               | If you want to catch real zero-days, you have to approach
               | things very differently. Do behavioral analytics, seeing
               | what a process is up to and if it's poking into things it
               | shouldn't.
               | 
               | Many leading AV suppliers like SentinelOne, Cylance,
               | Crowdstrike do this and are very successful at it.
               | However Apple is just starting in the antimalware market
               | so I forgive them that they're just scanning for some
               | known-bads for now.
        
               | radicaldreamer wrote:
               | I'm sure it works a lot better when alerts result in a
               | human looking at the issue.
        
             | simonh wrote:
             | It will catch an infected file that simply passes through
             | the computer without being opened or executed.
        
               | robryk wrote:
               | What do you mean by "passes"? Unless it's a file on a
               | removable medium or a remote fs, it has to be created,
               | which requires opening it. Scanning removable media upon
               | insertion and remote fses upon mounting is going to look
               | mighty suspicious and, in the latter case, be cover for
               | data exfiltration.
        
         | zibby8 wrote:
         | What if the list of known malware changes to include a file
         | already on the computer?
        
       | jokethrowaway wrote:
       | I spotted this crap in my activity monitor consuming tons of CPU
       | and battery for short burst the other day.
       | 
       | Glad to know it's not a malware, but it sucks not having control
       | on your system
        
         | culturestate wrote:
         | _> it sucks not having control on your system_
         | 
         | I obviously don't recommend this, but if you turn off SIP it'll
         | also disable XProtect.
        
         | tjohns wrote:
         | There are command line knobs to turn these features off. You
         | can disable SIP, or you can disable the system policy (which
         | disables Gatekeeper and XProtect).
         | 
         | It's definitely a case of "just because you _can_ , doesn't
         | mean you _should_ ".
        
       | user3939382 wrote:
       | I don't use AV and I've never gotten a virus on my machine
       | regardless of OS, except when I was 12 compiling virus code from
       | the ezine 40Hex. I don't run untrusted executables, seems simple
       | to me. Then I see my non-technical friends and family with 90
       | icons on their desktop and 6 years of files in their Downloads
       | folder and you see how it happens.
        
         | TillE wrote:
         | There was a really bad Dark Ages of remote exploits which
         | peaked around the early Windows XP era. The OS itself and
         | Internet Explorer were a horror show.
         | 
         | Other than that, yes, it's been fairly rare to have malware
         | infections that don't start with tricking the user into
         | executing a binary, though it certainly can happen.
        
         | sealeck wrote:
         | What about exploits like bugs in compression algorithms or
         | Javascript (with speculative execution)?
        
           | user3939382 wrote:
           | It's possible, definitely. I've had some amount of luck. But
           | I think if we had good measurements we'd find that getting a
           | virus through those means on personal machines is rare.
        
           | olyjohn wrote:
           | What about exploits that target the malware scanner itself?
        
       | NonNefarious wrote:
       | "system tools for tackling malware were essentially limited to
       | XProtect and MRT"
       | 
       | When did those arrive? On what OS versions?
        
         | latexr wrote:
         | XProtect has been there since Snow Leopard, released thirteen
         | years ago:
         | https://www.macworld.com/article/199817/snowleopard_malware....
        
         | ntauthority wrote:
         | MRT is the Windows Malicious Software Removal Tool which has
         | been distributed via Windows Update since around 2005.
        
         | NateLawson wrote:
         | Xprotect is part of GateKeeper, which arrived in Mountain Lion
         | (and late versions of Lion).
        
       | kelnos wrote:
       | > _XProtect Remediator_
       | 
       | Wow, Apple marketing was really asleep at the wheel when someone
       | named this one.
        
         | [deleted]
        
         | SllX wrote:
         | They don't market it.
        
         | [deleted]
        
         | saagarjha wrote:
         | It's an internal tool. It falls under the umbrella of
         | "Gatekeeper".
        
         | dane-pgp wrote:
         | Unfortunately the name XDefense was already taken by Nintendo.
         | 
         | https://bulbapedia.bulbagarden.net/wiki/X_Defense
        
         | TedShiller wrote:
         | not really
        
       ___________________________________________________________________
       (page generated 2022-09-01 23:00 UTC)