Banner
donkdown

Who Is Chatting

Chatroom is empty

Chat Now

Account Login

MANDATORY: Former NeverWinPoker users, please click HERE to reset your password



Poker Blog

02/03/2012
Glimmer of Hope
Comments: 5
by chinamaniac
01/31/2012
They Just Grab it Part 2
Comments: 1
by chinamaniac
01/12/2012
Little Comeback
Comments: 3
by chinamaniac

Micon's Hot Tweets

BryanMicon: Some @tom_mcevoy teaser pix from the awesome interview to be up on @DonkDown soon --> @AnnieDuke old school magazine http://t.co/mojF8qSD
BryanMicon: RT @WagerMinds: Safety Dance: Bettor wins $50,000 on $1,000 Safety Bet http://t.co/sku9VoKa
BryanMicon: RT @tw1tt3rart: ☆░░#PATRIOTS░V░#GIANTS░░☆ ☆╔╗╗╗╦╗╦╗╦╗░╦╗╔╗╗╗╗╦░☆ ☆╚╗║║╠╝╠░╠╩╗╠╣║║║║║║░☆ ☆╚╝╚╝╩░╩╝╩░╩╩╝╚╝╩╩╝╩╝☆ ☆░░░░#SUPERBOWL░46░░░░☆ #TwitterArt
BryanMicon: It amazes me that at 3:30am ish the day of the super bowl most sports books in Vegas are closed. if I owned a casino mine would be 24/7
BryanMicon: RT @qsdaddy1: @BryanMicon @GoldfarbLOL @painlesswon @BrandonGerson I'm on team "cute little schmeckle" FTW
Banner
Banner
Banner


Search This Topic:
Jump to:  


Post new topic Reply to topic  [ 4 posts ] 
Mac Security 
Author Message
DD Fish
User avatar

Profile
Degen Index: 2
Joined: 04 Jul 2008
Posts: 223
Sonatine....

Mac security Vs. windows based PC. GO!

Can a hacker infect a mac? (not just the Steve Blow-Jobs answer please)

Can someone install a keylogger without my password?

Can they control my webcam?

Is Internet poker safer when playing on a mac?

Does sharig a wireless connection with an unprotective PC user endanger me in any form or lower my safely level?

Give me the 411 please


Wed Jan 27, 2010 12:02 am
DD InfoSec Oyabun
User avatar

Profile
Degen Index: 59
Joined: 04 Feb 2007
Posts: 8011
3cents wrote:
Sonatine....

Mac security Vs. windows based PC. GO!

Can a hacker infect a mac? (not just the Steve Blow-Jobs answer please)

Can someone install a keylogger without my password?

Can they control my webcam?

Is Internet poker safer when playing on a mac?

Does sharig a wireless connection with an unprotective PC user endanger me in any form or lower my safely level?

Give me the 411 please



OK lets see here:

Overview. A Mac is no more secure than a PC, in fact right now the argument can be made that a Mac is less secure than a PC because there is such a long term focus on Windows security that many of the solutions implemented have yet to be ported to Macs..

PCs do have certain intrinsic weaknesses that tie into the role Explorer has with regards to interfacing with the operating system, and those weaknesses are legion mind you, but again its kind of an oranges v apples thing. Macs are softer (imo) but there is less knowledge floating around regarding how to take advantage of their weaknesses, so PCs can be considered the lower hanging fruit.

Now. If Mac actually comes through with a PC-buster, eg a laptop or desktop for half the current price with twice the hardware value, then I think what we will see is an inversion of sorts, where browser-based OSX exploits become far more serious/pervasive... but even now, major zero day browser based exploits will often determine what browser / operating system youre running and then direct you to an appropriate malicious payload. Thats kinda new. It used to be that people would just make their hostile malware PC specific and say fuck it re: the 5% of apple boxes that it doesnt affect. That 5% (or whatever it currently is) is no longer being ignored.


So:


Can a hacker infect a mac? (not just the Steve Blow-Jobs answer please)

Yes, 100%. OSX is a BSD based UNIX variant that can be subverted. Fairly easily in truth, once the equivilent of "administrator" access is attained (root, we call it). And there are a lot of ways to get root on OSX if you understand how to audit code/binaries and are so inclined.

Can someone install a keylogger without my password?

Yes, 100%. Once you have root access to an OSX computer, you have the literal keys to the kingdom. Your keystrokes can be logged, screen captured, webcam enabled. If it can be done on a PC it can be done on a Mac, basically. But again; for every 1 person who knows how to actually do this to a Mac there are probably 10,000 who know how to do it to a PC.



Can they control my webcam?

See above.


Is Internet poker safer when playing on a mac?

Its safer, sure. But you have to look at it like this; someone pops your PC while putting together a botnet for spam and DDoS and sees you are a regular 2/4 NL player, for example. Cool, its showtime, because they earn something like $80 US a month on the average and now they can take a years salary off you in one session.

Now lets imagine they get access to your Mac. Again, same villains. They are roaming around putting together a botnet, and they get into your Mac. Again, same thing, they see you playing 2/4 NL holdem.

Im going to put myself in their shoes; I can find someone in a few hours through networking who can put together a OSX rootkit, throw them a months wages for their efforts, and then grift you for 3 hours for a small fortune.

Why wouldnt I do that?

So you see, there is a hurdle presented by running a non-standard OS but at the end of the day, the grey market has a contingency plan for that hurdle, and most others as well.

Does sharig a wireless connection with an unprotective PC user endanger me in any form or lower my safely level?

Good question.. if you were a government employee or working with highly sensitive data (financial, medical, so on), then the answer is unequivocally yes.

If you want to play on FTP or Stars while your roomates girlfriend installs 50,000 trojaned freeware games on his PC, youre safe. FTP, Stars, pretty much all the big sites encrypt traffic between their servers and the client application.

Those data streams are secure. To compromise the integrity of the encryption or otherwise hijack the data would require aa quantity of talent and effort that would almost certainly be better spent elsewhere, so you would likely be a poor candidate for a random assault based off a rogue PC on the same network.

Caveat: if you are running a poker client that does not encrypt traffic (FYI I dont know of one) then you may have a problem, and if your Mac is running applications that can be easily exploited by the PC, you may also have issues if the PC-hijacker cares enough to go for it.

You have to remember; 99.99999% of all infected computers are automated attacks. Botnets today contain literally hundreds of thousands of nodes. You dont get that many computers by scanning and trying to penetrate computers one at a time. So really when discussing pragmatic security, you have to differentiate between the average threat (automated scans) and exotic threat (people aggressively trying to compromise your computer).

One of the reasons Im glad this forum exists is because I think the latter becomes far more realistic for internet poker players, as the sums of money at risk are extremely tempting and can justify large amounts of effort.

_________________
Wiz' Fruity Pebbles Poetry Contest Runner-Up, probably.
<Ripptyde64> anyway I just wanted to give you some props for your posts....you really have a unique way with words and as a fellow writer I am humbled
<Ripptyde64> lol I just like your style. there are so many useless and moronic poster on these forums and you are vastly superior in quality, form and content.

╭∩╮(︶︿︶)╭∩╮


Mon Feb 01, 2010 1:16 pm
DD Mushroom Stamping Mod
User avatar

Profile
Degen Index: 37
Joined: 23 Feb 2005
Posts: 13448
http://www.f-secure.com/weblog/archives/00001896.html

The two time reigning Pwn2Own internet security challenge winner agrees.


Mon Mar 08, 2010 12:20 am
DD John Anthony
DD John Anthony


Profile
Degen Index: 8
Joined: 10 May 2005
Posts: 3313
The short answer is that right now this second, you are 10000x less likely to become infected with a mac. As sonatine said, this will change drastically as Apple gains more market exposure... which will happen. Right now though, if you are concerned... buy a mac.

Another thing that I would highly advise is to segregate the machine that your poker is played on with the one that your IM, Web, Email is accessed from. You can do this on the same computer via virtual machines, which is what I do. I believe my setup is one of the most secure setups you can have in 2010. I run Mac OSX as my primary OS (which by the way I feel is a better OS unless you have specific windows only apps to access), and run a virtual machine via Parallels for my poker clients. This completely separates poker from everything else you do that could be compromised.

I have actually set this up for several high limit poker players that were unaware of how close they were to losing hundreds of thousands of dollars in unsecured poker accounts.


Mon Mar 08, 2010 5:14 am
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 


Users browsing this topic: No registered users and 1 guest


Similar Topics

 Topics  Forum  Author  Replies
Wireless network security Anti-Hacker Information Warfare Forum tomfmason
Wed Jan 18, 2012 6:55 pm
3
HOF Baseball fan escapes security Shooting Off muck ficon
Sat Nov 05, 2011 6:28 am
4
TSA Employee Takes Bribe to Move Passengers to Front of Airport Security Line Shooting Off Anonymous
Wed Sep 14, 2011 4:23 pm
6
Weed in Vegas or getting it through the new airport security Shooting Off Stugots
Sat Sep 03, 2011 5:18 pm
20
Cool Project... Running Security At the WSOP Shooting Off vegas1369
Wed Apr 13, 2011 5:22 pm
38

Search for:
Jump to:  

Poker Blog | Poker Forum | Contact Us | Advertise | Sitemap
Copyright © 2009-2011 Donkdown.com