BeyondTrust

Security In Context

Bringing you news and commentary on solutions and strategies for protecting your critical IT infrastructure.

Macs Need Least Privilege Too

Post by Peter McCalister June 17, 2011

Turns out that Macs aren’t as virus and hacker proof as originally perceived. Just check out a recent posting on MacRumors.com to read all the details.
In this blog post it appears that a new malware threat is appearing when users perform Google searches.
I’ve actually seen this malware pop up on a Mac recently, and the recommendation to mitigate this threat was to run as least privileged user (“of course”). Running as a standard user can blunt the attack and generally enhance security on any operating system. Interestingly, a post was made in the comments section below the article that got me thinking.

The commenter said, “nothing can defend against user stupidity.” If the organization allows users to run with administrator privileges on any operating system, is it really a surprise that bad things can and do happen? Is it realistic to think that users will do the right thing when faced with a security decision?

As IT professionals, it is easy to point the finger at the user and call them “stupid,” but that is because we have learned (in some cases, the hard way) to spot security threats that come from suspicious downloads and phishing scams. Further, users simply want to get their job done. If IT security is not part of their job description, it shouldn’t really come as any surprise that users ignore these security threats, which are obvious to IT professionals.

It could be argued that everyone has a responsibility when it comes to security, but that doesn’t mean that we should simply ignore recommendations to remove administrator privileges from users and call them stupid.

Leave a Reply

Additional articles

insider-threat-fed

Mitigating Inside Threats to U.S. Federal IT Environments

Recent high-profile cases have increased the perceived risks that go along with disclosure and usage of confidential information. One of the most difficult security threats to mitigate is an attack from the inside. When an over-privileged user, such as an unhappy current or former employee, contractor, or consultant, begins navigating your network, how will you…

Post by BeyondTrust Software April 17, 2014
Tags:
, , , , ,

Are you a Target? Investigating Security Breaches with Kevin Johnson

Last week, over 1,000 IT security professionals watched as Kevin Johnson, CEO of Secure Ideas, presented his expert opinion on lessons learned from recent, high-profile retail breaches. Here’s a summary of key takeaways from the webcast plus an on-demand recording of the full, 60-minute presentation. Understanding the “why” behind attacks According to Kevin, the primary…

Post by Chris Burd April 17, 2014
Tags:
, , , , ,

Vulnerability Expert Forum Highlights: April 2014

We had a great turnout for last week’s April 2014 Vulnerability Expert Forum (VEF) webcast. BeyondTrust Research experts, Carter and DJ, provided in-depth knowledge about the latest vulnerabilities and their potential impacts on network environments. Below are highlights from the Forum, plus an on-demand video of the presentation. Latest critical vulnerabilities, vendor patches, and zero-day…

Post by Chris Burd April 16, 2014
Tags:
, , , , ,