Yes. And the malware could be polymorphic. Or there could be multiple versions of the same "core" out there. It's not clear to me how sophisticated virus (malware) scanners for OS X are with dealing with that.
> Is there any diagnostic tool out there to determine if you've been infected?
From what I can tell, they posted the SHA256 of the offending binary under the IOCs section of that web page. So you should be able to do this in the root of your home directory to detect if such a file exists:
# find . -type f -print0 | xargs -0 shasum -a 256 | grep 664e0a048f61a76145b55d1f1a5714606953d69edccec5228017eb546049dc8c
Thought experiment: let's say that Apple doesn't know what the suspect in a law enforcement investigation is suspected of. If the request is between revealing the identity of a user from a particular IP address (which is probably easy for them to determine), or giving away (essentially) a master key to decrypt all iPhones, which would it comply with? I think it would have complied with revealing the identity of a user pretty much every time, even if the suspect was a terrorist, but not necessarily to give away the master key for all iPhones even if the suspect was an intellectual property pirate.
Maybe it is a coincidence being posted on HN 7 months after the article was written, but the NY Post article is a great commentary on what is in the news these days:
To quote from the article: “Knockoff chargers sometimes cut corners,” Xiang said. “The quality of the capacitor and circuit protector may not be good, and this may lead to the capacitor breaking down and sending 220 volts of electricity directly into the cell phone battery.”
Apple trying to enforce its quality standards on the charging system seems completely reasonable -- yes, even if it means that the end-user has to pay for the quality. Most Apple customers are actually looking for that quality and willing to pay for it.
There is a great teardown analysis of Apple and knock-off chargers at Ken Shirriff's blog:
1. Apps in the Mac App Store can't ship their own kernel extensions along with the app. With the framework, it may not be necessary for virtualization products to do that -- enabling them to ship in the Mac App Store.
2. Compatibility breaks between OS version updates. Every time the kernel interface changes, someone shipping a kernel extension will need to ship an update as well. With this approach, it's possible to keep compatibility and let the implementation of the framework do all the heavy lifting.
3. If virtualization products are going to be in the kernel in order to run, it would be better for the host OS vendor to supply official supported interfaces instead.
Just as Intel is making it easier to do virtualization on their chips with VT-x and VT-d, Apple is making it easier to implement virtualization with Mac OS X as a host with this framework.
"Federal Reserve Regulation E guarantees that US consumers are made whole when their bank passwords are stolen. The implications lead us to several interesting conclusions. First, emptying accounts is extremely hard: transferring money in a way that is irreversible can generally only be done in a way that cannot later be repudiated. Since password-enabled transfers can always be repudiated this explains the importance of mules, who accept bad transfers and initiate good ones. This suggests that it is the mule accounts rather than those of victims that are pillaged. We argue that passwords are not the bottle-neck, and are but one, and by no means the most important, ingredient in the cybercrime value chain. We show that, in spite of appearances, password-stealing is a bad business proposition."
I don't think this is Apple trying to be difficult: SSD TRIM is buggy between all the different vendors (today even Ubuntu enables it only for Samsung and Intel SSDs by default), they want to guarantee that it works by whitelisting what they ship with, and the mandatory driver signing seems like a security improvement. If some third party wants to ship a signed kernel extension that works with their specific SSD (or generic ones, even) and supports TRIM, that should be possible.
FWIW, there is a third party SSD drive that works with Apple's default drivers for TRIM support; I suspect they're doing some sort of identifier spoof to fool the whitelisting code:
http://www.angelbird.com/en/prod/ssd-wrk-for-mac-929/
I didn't give this article much weight -- Bennett called up Christensen on the telephone and got an emotional, ad-hoc response. This isn't a well thought out, polished, official response from Christensen. Hopefully we'll see one later on.
I had to step back and think of examples that would qualify for what Christensen is talking about. I think I found a few, so I can't take Lepore's piece at face value.
What graphics card does Mac OS X think it's using when running in QEMU/KVM as you describe? Are you able to get different (more than 1200x800) resolutions? One of the major shortcomings of most of the "Mac OS X in a guest" efforts is that 3D hardware acceleration is disabled (unimplemented) in the guest video driver, which the Quartz compositing engine assumes will always be there. This results in weird video behavior, like certain things not showing up or for FLV video to not render in a web browser. Are you able to view web video with this Mac guest?
> he's actively asking people to send money to him in a way that skirts the lien the irs has filed against him. if the irs notices this and gets pissed, it absolutely puts his 'helpers' in harm's way.
I'm not sure that's actually true. Is it? If you donate money[1] or buy something from him, you're giving him property; whether he is properly reporting that property and paying any necessary tax on that is his issue -- he's not asking you to enter into a conspiracy to hide anything.
At the very least, he could use cash donations to pay off whatever lien is against him. And according to [1] below, the recipient of the donation isn't the one paying taxes on the donation amount.
It's breathtaking to see such a blunder: a Forune 100 company telling nearly 20% [1] of its installed user base, it's second largest desktop OS customer base, to stop and make a financial decision about what to do, instead of giving them a low-cost, path of least resistance option to continue in some way similar to the status quo. For many people still on XP, the users are not technical enough to understand how to do an OS upgrade or how to migrate user data to a new machine, let alone understand why they would want to when the current system appears to work fine.
I'm surprised that they're not trying to monetize their current XP user base with some sort of "XP extended support" fee-based subscription so they don't force users to look elsewhere for a desktop OS -- between Windows 8's blunders and a Mac, I suspect many of those XP users will consider a Mac. Or simply by offering a ~$40 upgrader app to get to Windows 7 "lite" for XP users that works on the same hardware and drivers...
I don't see this as a "youth" problem. To reframe the discussion, this is about the ever present cycle of innovators that become incumbents and innovators that disrupt incumbents. If you haven't heard of Clayton Christensen's book, The Innovator's Dilemma, it's a good read.
While some of the people mentioned in the article are young (Bicket and Miswas of Meraki are in their 20s/early 30s), other entrepreneurs in the news today are not: Acton and Koum of WhatsApp (recently bought by Facebook for $19B) are in their late 30s/early 40s.
Google's founders, Larry and Sergey, are 40.
Twitter: Jack Dorsey is 38. Biz Stone is 40. Evan Williams? 42.
Steve Jobs' best work at Apple was when he was in his late 40s/early 50s. Arguably, the success of Apple today is due to Steve's leadership, not due to the company being saved by some young person who breathed new life into the company as this quote from the NYT article suggests: "The most innovative and effective companies are old-guard companies that have managed to reach out to the new guard, like Apple". (If you disagree with this, look at Apple between 1985-1997 and 2011-present, where plenty of young (and old) people worked at Apple)
To simplify the claim here: there are those who know how to adapt to the current situation and those that don't (or can, but don't care). Some of those who know how to adapt are "old guard" and some are "new guard" -- it's not the age that is the determining factor.
As for other items in the article, like the lack of young people "help[ing] cure cancer or fix healthcare.gov", there are plenty of old (older) people who don't want to work on those problems too.
As for the claim that startups are the bastion of youth, that's not true either. I see plenty of 40-something founders and startup employees. While young startup people can easily afford to do a startup because their financial commitments are low (e.g., no mortgage or family to support), the older folks tend to do a startup for a similar reason: they've earned and saved a chunk of money where they're no longer worried about money and they can take on more risk.