⬅ Back to Security Stuff

Are Macs Really More Secure?

by robert terrin

There's a belief among many folks that Mac operating system is more secure than the Windows operating system. It's even quite prevalent among security experts:

I'm not specifically picking on Thomas here, I happened to agree with him. But then I thought some more about it and the logic behind my belief didn't sit right with me, so I tried to write it out in a systematic way. For now, I'll leave the most provocative part of the statement (about antivirus) to the side and limit my discussion to OS security. It's hard to say where the view that Macs are more secure comes from, but there are a number of reasons, some better than others.

The Good

So what are some good reasons for believing in the security of Macs? One common assertion is that Apple simply maintains higher standards, has better engineers and exacts more control. Another claim is that the Mac was designed more thoughtfully with security in mind from the beginning. A third claim is that because Apple is highly attentive to user experience, they encourage better security.

It is well known that the Apple ecosystem is closely guarded. Because of the philosophy behind macOS, it is in some ways easier to defend a closed system where you can exert more control, making developers adhere to stricter standards. Sometimes people in cybersecurity refer to this as "security through obscurity," but Apple often publishes their architectures and white papers while hiding manuals, schematics and diagrams of their systems to preserve a business advantage, not stymie hackers. They have, in fact, developed a reporting platform and bounty program.

On top of Apple's philosophy, macOS has some architectural security benefits, because of its shared history with Unix systems. This shared underlying structure allowed Apple to take advantage of government research into security for their own Unix systems. By building on the Federally funded work, Apple has leveraged a community of developers and security experts even broader than Microsoft's. This and the walled garden approach allowed Apple to maintain backward compatibility without sacrificing security. It wasn't until Windows Vista that Microsoft implemented equivalent security features.

Finally, much is made of the list of Apple's security features. They make headlines for their moral stand on encryption (Microsoft has supported their legal position). Iphones were the first mass adoption phone to popularize biometric authentication. Apple's attention to security is laudable, and it is aligned with their business model. What is less clear is how that business model translates the value to consumers, and what value people are getting from it.

The Bad

OK, so I've piled on enough compliments and arguments for why macOS is the technical person's preferred secure OS. In theory, all of the above is true, but where is the evidence? Does Apple even want you to see the evidence? No, they want you to see this:

Of course it is in their interest to market their security. They are, after all, spending millions of dollars on this stuff. The problem is that Apple has a history of doing this sort of thing.

What is more, Apple often takes the position that they build perfectly secure systems and if only users would keep them hermetically sealed in their neat plastic wrap, they wouldn't need all that additional security! They host answers on their community forum defending the view that macs come with everything they need built in. Unfortunately, computers are meant to be used by unsophisticated people, connected to networks, and yes, even jail broken sometimes. This, of course, is not without risk.

The rising tide of mac malware is finally washing up on our shores. What are these emerging threats? Mostly adware. A recent Kaspersky report pointed out the prevelence of a particular strain of Trojan. While these are worrying, they are clearly not up to the level of threats faced by Windows machines.

The Ugly

Two big issues outside of any one organization's control are driving this debate. The first is the prevalence of the Windows OS, particularly in the business world. The second is user behavior.

It is well known in the cybersecurity world that the efficacy and professionalism of cyber criminals are on the rise. As business requirements and return on investment drive hacking behavior, and macs continue to enter the workplace, expect to see more mac targeted malware. It is already a known fact that digital marketers price discriminate based on what operating system you are running. Today, it is just good business sense for hackers to target Windows machines. They are less likely to be kept up-to-date. They have more legacy compatibility issues, and they are 90%+ of the business ecosystem. As workforce demographic trends (in the U.S. at least) turn over, expect to see more mac's in the c-suite, and as the CEO does, so will middle management. To some degree, Apple may become a victim of its own success.

The other reason it may be less productive for cyber criminals to target mac users has to do with how the users interact with their devices. I alluded to this above when talking about Apple's attention to design and user experience. It is true the devices appear harder to mess up. One is less likely to download malware in the process of trying to install some dependency. Other factors may be tech savvy, age and education. One informal survey found that mac users are younger, perceive themselves as more technically inclined, and have more years of education. While it is debatable whether these factors are positively associated with better cyber hygiene, or whether they matter at all, there is evidence that routine activities from years of downloading unknown files can increase one's risk.

Operating System in a System

After exploring all of these justifications, biases and arguments for and against inherent macOS security, I am left with a mixed sense of relief and dread. The relief comes from the fact that there is some basis, even if it is mostly theoretical, for my initial reaction. I was also relieved to find that Apple does genuinely seem to care about and spend resources on security. That is not all they spend resources on, however. As I dug into the research, I was shocked at how powerful a subliminal marketing message Apple has crafted. They are indeed master marketers. The dread comes from the emerging body of evidence that the security advantage macOS has enjoyed will not always be the case. Ultimately, security is a property of a system, and no matter what OS you use, how you use it will always matter more than what its defaults are.



Tweet this article