Recommended Posts

This is the very definition of anecdotal evidence.  I haven't had malware on my Windows machine in over 10 years, therefore it doesn't exist.  I don't know anyone who owns an iPhone, therefore they don't exist.  I don't know anyone who owns a PS4 either, so obviously nobody has one.  See how this works? 

 

Note that Sonne is shifting the goalpost. Originally the claim was that there wasn't any viruses for Mac in the wild. It was then pointing out to him that most Malware infections aren't actually viruses and further shown that Malware does exist for Mac (by you, goretsky, and me). Since we've shown him that Malware does exist for Mac, the only logical course is for him to move the goalpost and show that he, himself, doesn't need anti-malware software and to try to make a hasty generalization out of his specific case.

 

I'm not saying that it means you need full time running protection.  I don't use a resident AV suite on my Windows machines either, I use other means to keep my systems secure.   (I agree with wasted resources.. if you're relying on an AV suite to tell you that you got malware, you probably already messed up.)  But it doesn't mean you're immune to malware and you can just do whatever you please with anything you do or download either.  Malware does exist for other operating systems.  OSX has had it's attacks, even Linux has had some.  (Kernel.org and a few other high profile sites being taking down due to a rootkit anyone?)   There is no such thing as an operating system that's immune to malware or exploitation.  User error, gullibility, vulnerabilities in software, or just plain carelessness, all sorts of ways to do damage to somebody's system.  The only reason Windows machines get targeted the most is due to the sheer number of users, most current malware is money or data theft oriented, they tend to go where the most people are.

 

Well said. I still think Sonne is doing a disservice to Mac users by making it seem as if one doesn't have to bother to do anything and is simply immune to attacks. Anti-malware software is no substitute to being smart about what you install/etc. but many folk simply don't have the background to know how to keep safe in the first place.

 

Apple itself offers suggestions on how to be safe from Malware for this reason: http://support.apple.com/kb/PH11432. And even disabled installing applications from unknown sources per default in Mountain Lion.

Hello,

 

No properly-written anti-malware software for OS X interferes with the continuity, integrity or reliability of the Apple Mac on which it is installed, nor does it consume excessive system resources such as processor utilization, memory capacity, disk I/O or network bandwidth.

 

I can provide some external proof of this:  If you visit Apple's web store, you will find some security programs for sale in it.  Apple will not and does not allow programs which cause problems with its computers to be sold through its store.  I know this because about four years ago, one of my employer's programs was removed by Apple from its webstore for this reason.  As you might imagine, our developers worked very dilligently to fix the issue.  This is not limited to anti-malware software, of course; I'm sure other kinds of programs have been pulled by Apple from its web store when they caused issues with Apple products.

 

Now that we have gotten the specter of compatibility issues out of the way, let's look at some of the reasons a person might run anti-malware software on their Mac:

 

  • They work with proprietary or confidential data, and have concerns it might be altered, deleted or stolen.
  • They frequently download and run pirated software.
    (If you take a look at the last five or so Microsoft Security Intelligence Reports, you can see that the greater a country's piracy rate, the more likely they are to experience malware.)
  • They were affected by malware once and as a result run anti-malware software on all their devices (smartphone, tablet, PC, etc.)
    (The "once-bitten, twice shy" approach.)
  • It is a requirement mandated by school, employer or other source.
  • They work with, or otherwise exchange data with, computers that run more heavily-targeted operating systems, such as Microsoft Windows.

I am sure you there are plenty of additional reasons, but those are just a few off the top of my head.

 

One thing that I think is important to keep in mind, which is an issue we have kind of side-stepped so far, is why exactly is there a need for anti-malware software on OS X?  Well, the obvious answer to that is because there is malicious software for OS X.  And that, in turn, leads to the real crux of the question:  Why exactly (e.g., for what purposes) is malicious software being written for OS X?  Outside of PoCs, the answer seems to largely fall into two camps: 

 

The first is for criminal reasons, which is to say, somehow illegally making money off the computer.  Examples of this might include things like DNS redirection to certain search engines, stealing account credentials, using the Mac as zombie in a botnet or some other higher-level tiered function such as a drop zone or a C&C server, and so forth.

 

The second reason is for surveillance or espionage.  This can be both by governments and corporations, and, as for reasons, well, whatever reasons those sorts of folks like to spy on other folks.  Between the links I provided earlier and all the news involving Edward Snowden, I don't really think there's anything additional which needs to be said here.

 

If you go to any of the conferences which specialize in discussions of malicious software (CARO, EICAR, ISOI, VB and so forth) you will see a lot of security professionals running Apple MacBooks of various kinds (even I have one), and they are all running anti-malware software on them.  I think that would be a much better venue for determining whether or not a given operating system needs security software, because those are the folks who see the threats day and day out.  There are a lot of Mac-centric forums with some very security-savvy people on them, but the overall focus of such venues is usually the Mac ecosystem, not system security, information integrity, continuity of operations or all the other things which go on under the umbrella of information security.

 

Before I conclude this message thread, there are a couple of things I wanted to mention:

 

Firstly, you seem to be under the assumption that I am advocating anti-malware as the primary and sole means of securing Apple Macs.  That is incorrect.  A layered-approach is necessary to defend any computing resource, and that includes user education, staying up-to-date with OS and application patches, performing backups, testing your disaster recovery plans and so forth.  These are just as important as anti-malware software, it not more so.  Anti-malware may be an important tool in your information security arsenal, but its only one tool out of many.

 

The second thing is, you keep saying "antivirus" or "A/V" when discussing anti-malware software.  I realize the reasons for doing so (public literacy levels, familiarity with computer viruses versus other kinds of threats, marketing, etc.), and am often guilty of doing it myself in casual conversation.  However, in this particular conversation, it makes your writing less persuasive.  It would be as if we were having a discussion about cars and you kept talking about them as horseless carriages.  The criminal world has largely moved on from computer viruses because they have better types of malware to use for stealing and their other criminal enterprises.

 

Regards,

 

Aryeh Goretsky

 

 

 

  • Like 2
  • 5 months later...
  • 1 month later...
  • 3 weeks later...
  • 4 weeks later...
  • 11 months later...
  • 3 weeks later...
  • 1 year later...

Not to bump this or anything but I've always been a fan of Malwarebytes for several years now and haven't really used much else. Even on Windows, I didn't use anything else and it did the best job from the ones I've tried (Norton, Avira, Avast, AVG, etc.). Would find trojans that other programs would not.

  • 1 year later...
58 minutes ago, d5aqoëp said:

Do we still need antivirus for macOS?

You tell me. Exploits found have increased over the years and so has malicious software. Does that mean you need it less now? Doubt it ;)

Hello,


Some recent reports of Mac (macOS) malware from the last couple of weeks:

 

OSX.HiddenLotus.A - https://securityboulevard.com/2017/12/interesting-disguise-employed-by-new-mac-malware-hiddenlotus/

OSX.Pirrit - https://www.scmagazineuk.com/new-macos-malware-steals-bank-log-in-details-and-intellectual-property/article/718542/

Proton RAT - https://www.macworld.com/article/3237678/macs/sophisticated-mac-os-malware-uses-trust-and-developer-certificates.html

 

Even if a Mac isn't performing any high-risk activities, it is probably still a good idea protect it. 

 

 

Regards,

 

Aryeh Goretsky

  • 6 months later...
  • 2 weeks later...

To be very frank and on a serious note, using mac is quite safe from viruses itself because Apple has made that mark from a long time and will do everything to keep its head above all. Till the time you don't do some deep random websites surfing getting you to catch some sort of virus, it's altogether safe to use it without antivirus. Still, to go with an option, Sophos is best till date.

  • 4 months later...
  • 1 year later...
9 minutes ago, Katastrofe said:

I've never installed antivirus software on my Macbook Pro.
 

That’s fine as long as you aren’t under the misconception that there are no Mac viruses/malware. 

  • Like 2
  • 11 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Posts

    • Wow, Microsoft IS cooking lately... This only shows that they COULD improve, they just chose not to for whatever reasons. That obsession with AI was destroying them from the inside out.
    • BATorrent 4.1.0 by Razvan Serea BATorrent is a lightweight, open-source BitTorrent client built with modern C++ and Qt 6, offering a clean, fast, and privacy-focused alternative to traditional torrent apps. It supports magnet links, .torrent files, resume data, sequential downloading, per-file priorities, and even imports from qBittorrent. Power users benefit from integrated RSS auto-download with regex filtering, duplicate detection, and automatic tracker lists from Stremio. Streaming is seamless thanks to auto-detected players like VLC and IINA. BATorrent includes robust VPN tools—interface binding, auto-detection for WireGuard-based services like Mullvad and NordLynx, kill switch, proxy support, and IP filtering. A full WebUI enables remote control, while integrations with Plex, Jellyfin, and Emby automate library updates. With themes, speed scheduling, system-tray alerts, and cross-platform support for Windows, Linux, and macOS, BATorrent delivers a polished, high-performance torrenting experience. BATorrent features: Core .torrent file and magnet link support Resume data — picks up where you left off after restart Import torrents from qBittorrent Create .torrent files from any file or folder Sequential download mode Per-file priority control (skip, low, normal, high) Seed ratio limits with auto-pause DHT, PEX, UPnP, NAT-PMP RSS Auto-Download Subscribe to RSS feeds — automatically download new torrents as they appear Regex filters — match only what you want (e.g. 1080p|720p, S01E\d+) Per-feed settings — custom save path, check interval (5–1440 min), enable/disable Auto-download — matched items are downloaded automatically in the background Supports magnet links, .torrent URLs, and tags Tray notifications when items are auto-downloaded Duplicate detection — never downloads the same item twice Stremio Stremio Addon System pre-installed — works out of the box Auto tracker list from ngosang/trackerslist Streaming Play while downloading — stream video files before the download is complete Supports mp4, mkv, avi, mov, wmv, flv, webm, m4v, ts Auto-detects installed players (VLC, IINA, system default) VPN & Privacy Interface binding — lock torrent traffic to a specific network interface (e.g. tun0) Auto VPN detection — identifies VPN interfaces (tun, tap, WireGuard, Mullvad, NordLynx, ProtonVPN) Kill switch — automatically pauses all torrents if the VPN interface drops Auto-resume — resumes only the torrents paused by the kill switch when VPN reconnects Proxy support — SOCKS5 and HTTP proxy with optional authentication IP filtering — load P2P blocklists to block unwanted IP ranges Protocol encryption (enabled / forced / disabled) WebUI Remote management — control torrents from any browser at http://localhost:8080 REST API with JSON responses Add torrents via magnet link or .torrent upload Pause, resume, remove torrents remotely View peers and files per torrent Dark theme matching the desktop app HTTP Basic Auth with SHA-256 password hashing Configurable port and remote access (localhost vs 0.0.0.0) Interface 3 themes: Dark, Light, Midnight (bat/vampire aesthetic) Real-time speed graph Detailed panel with tabs: General, Peers, Files, Trackers Filter bar: search by name, filter by state (Active, Downloading, Seeding, Paused, Finished) Drag & drop .torrent files and magnet links Drag & drop reorder in torrent list System tray with notifications (download complete, kill switch events, RSS auto-downloads) Splash screen with bat animation Bilingual: English and Portuguese (BR), auto-detected from system locale Bandwidth Scheduler Alternative speed limits — set different download/upload limits on a schedule Time range — configure active hours (e.g. 01:00 to 07:00), supports overnight ranges Per-day control — choose which days of the week the schedule applies Automatically switches between normal and alternative speeds Media Server Integration Plex — automatically trigger library scan when a download completes Jellyfin / Emby — same automatic library refresh via API Configure server URL and authentication token/key in Settings System Cross-platform: Windows, Linux, macOS Auto-shutdown — automatically shut down PC when all downloads complete (60s cancellable countdown) Auto-update system (AppImage on Linux, installer on Windows, DMG on macOS) CLI arguments: pass .torrent files or magnet: URIs directly Keyboard shortcuts: Space to toggle pause, Ctrl+A to select all, Ctrl+O to open BATorrent 4.1.0 release notes: A community-driven release: everything here came straight from your reports and requests. It closes the remaining gaps with qBittorrent and fixes the Windows settings/tray/splash issues several of you hit. Fixed Settings now actually save. A whole class of preferences — speed limits (and the alternative limits), max active downloads, seed ratio, listen port, max connections, DHT/uTP/encryption, VPN interface, kill switch and proxy — weren't being persisted and reset to defaults on every launch. They now round-trip correctly. (Thanks to everyone who reported "the upload limit always goes back to 0".) Splash and tray toggles stick on Windows. Turning off the startup animation (or "close to tray") no longer reverts — the Windows registry stored these booleans as integers and the UI was misreading them. Close-to-tray hint. The first time the window hides to the tray you get a one-time notification, so the app doesn't look like it vanished (Windows 11 tucks new tray icons into the overflow). macOS Dock icon size. The icon filled its canvas edge-to-edge and rendered larger than neighbouring apps; it now uses the standard safe-area padding. Native file picker language. The "Torrent file / All files" filter in the open dialog follows the app language instead of being hard-coded. Added — qBittorrent parity Alternative speed limits toggle — a turtle button in the toolbar flips your throttled limits on/off instantly, independent of the scheduler. Follow system theme — switch light/dark automatically with the OS (Settings → Appearance). Pre-allocate disk space — reserve the full file size up front to reduce fragmentation (Settings → Downloads). Recheck data on add — optionally force a hash check when adding a torrent, so existing or partial files on disk are detected. Port status indicator — a 🔴 dot in the status bar shows whether your listen port looks reachable (UPnP/NAT-PMP + listen state; fully local, no external check). Add torrent from URL — File → Add torrent from URL (Ctrl+U) fetches a remote .torrent and routes it through the normal add dialog. Export .torrent — right-click a torrent → Export .torrent to save its metadata file. Already there (in case you missed it) Watch folder — auto-add .torrent files dropped into a monitored directory (Settings → Files). This release just surfaces it. Incomplete files already carry a .!bt suffix until they finish. Under the hood Regression tests for the settings-persistence and Windows boolean bugs. A new Qt Quick Test harness covering the startup splash and the design-system widgets. Download: BATorrent 4.1.0 | 37.5 MB (Open Source) Download: BATorrent Portable | 51.7 MB Links: BATorrent Website | Screenshot | Changelog Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Disabling open on hover, great! That was so stupid! They need to do a fix, where if a network share is disconnected, it doesn't hang when opening "This PC" for 20 seconds.
    • Microsoft releases major feature updates for stock Windows 11 apps by Taras Buria In addition to releasing new Windows 11 preview builds, Microsoft announced that inbox Windows apps now have dedicated release notes in the official documentation. At long last, users have access to all the release notes for each app, with changes listed in chronological order. Microsoft used to announce feature updates for stock apps with each build. Now, with Windows Insider release notes hosted on the Microsoft Learn website, each app has a dedicated space for its changelog, which is very useful for those who want to track new features and improvements. Alongside that, Microsoft dropped massive feature updates for six stock apps: Clock, Media Player, Calculator, Voice Recorder, Photos, and Paint. Each app packs quite a lot of changes and new capabilities, so here are the release notes. Here are quick notes so that you can jump to the app you are interested in the most: Calculator Camera Clock Media Player Paint Photos Sound Recorder Here is what is new for the Calculator in version 11.2605.9.0: More accurate square-root results — Fixed rare cases where a calculation that should equal zero (like sqrt(2.25) - 1.5) returned a tiny leftover value instead. Readable text in High Contrast themes — Settings text now shows the correct colors in the High Contrast Aquatic and Desert themes. Fixed layout for right-to-left languages — For languages like Arabic and Hebrew, the graph, number pad, equation fields, and scroll buttons now appear correctly oriented. Reliable launch after upgrading — Fixed an issue where upgrading from much older versions could leave outdated settings that stopped the app from opening. Here is what is new for the Camera app (version 2026.2605.7.0): Zoom slider works on more cameras — The zoom slider now works on the latest cameras, respects your system zoom settings, and updates instantly when you change those settings. Full range of zoom levels — Fixed an issue where the zoom slider only showed three steps on some devices that zoom in finer increments. Front camera works on more devices — Resolved a problem that blocked the front-facing camera on certain wide-angle devices. More video resolution choices — You can now pick video resolutions that were previously hidden; the app shows a heads-up warning instead of removing them. QR links you can still use — When a scanned QR code points to something with no matching app, the link is now copied to your clipboard (with a notification) while still offering a Store search. Smarter default settings — When you haven't set a preference, the app now follows your system settings by default. The Clock app has a massive changelog with the following improvements in version 11.2605.9.0: Timers keep counting after they hit zero — When a timer runs out, it now keeps counting up (for example, -00:27:31) so you can see how far past the time you've gone. You can turn off the daily goal — Focus Sessions now include an "Off" option so you can skip setting a daily goal entirely. New 15-minute snooze option — Alarms now offer a 15-minute snooze interval. Run up to 3 countdowns at once — The Countdown Widget now supports three simultaneous countdowns, up from two. Timer Widget notifications now appear — Fixed an issue where the "timer finished" notification didn't show when the timer was started from the widget. Less clutter in Focus Sessions — Tasks you've already completed no longer show up in the Focus Session task list. More accurate focus progress — Fixed a rounding issue that could show your daily focus progress as a minute short (for example, 49 minutes instead of 50). Smoother World Clock comparisons — The World Clock compare page now loads dates as you scroll, so it feels more responsive. Up-to-date World Clock locations — Refreshed country and city names to match their current names. Correct sun and moon icons during midnight sun — Fixed an icon that wrongly showed a moon during all-day daylight in polar regions. Fixed back-button behavior in clock comparisons — Pressing back once now takes you back as expected, instead of jumping the date to 1926. Corrected the Newfoundland time zone — Newfoundland now uses the right time zone (St. John's). Disabled alarms stay looking disabled — Editing a turned-off alarm no longer makes it appear turned on. Cleaner timer cards — The expand button is now turned off on timer cards that have no time set, preventing actions that wouldn't do anything. Clearer theme setting — Updated the wording to "Choose your preferred app theme." Smoother Settings links — The "About" links in Settings no longer trigger an unexpected "switch apps" prompt. Fixed spacing in Spotify settings — Corrected uneven spacing in the Spotify settings card. Better focus visibility in High Contrast — The focus highlight in World Clock is now clearly visible in the High Contrast Aquatic and Desert themes. No more double announcements — Screen readers no longer read the timer value twice. Countdown names read correctly — Screen readers now properly announce the name of each countdown. Keyboard focus stays put — Focus no longer disappears after you press the Timer Reset button. Clearer alarm toggle for screen readers — Tidied up how the alarm on/off switch is announced. The Media Player app received plenty of changes as well (version 11.2605.14.0): Custom captions — You can now personalize how closed captions appear, with caption styling tied to your Windows caption settings, plus a quick link to open those settings directly. "Indexing" banner in the play queue — When your media library is still being scanned, a banner now explains why some items may not appear yet. Fixed the look of selected items — Corrected a layout glitch with selected items in lists. Fewer playback failures — Improved how the app recognizes supported file types, so more files play without issues. Playlists need a name — You can no longer accidentally save a playlist with a blank name. Cleaner look for empty playlists — Improved how a playlist appears when it has no items yet. More stable play queue edits — Fixed a crash that could happen when changing the play queue while the app was switching between sessions. Clearer "missing codec" message — Improved the dialog that appears when a file needs a codec you don't have, with clearer guidance on what to do. A big update is also available for Paint in version 11.2605.61.0: Adjustable eraser transparency — You can now control how transparent the eraser is. Cleaner stamp brush strokes — Fixed visible color shifts and artifacts when using stamp-style brushes. JPEG photos save in place — Opening a rotated JPEG and pressing Save now overwrites the original instead of unexpectedly prompting "Save As." No more crash on bad image files — Opening a damaged or invalid image, from within the app, by double click, or commandline, now shows a clear error message instead of closing the app. Classic selection behavior restored — The selection outline now hides while you move, resize, or rotate a selection, just like in classic Paint. Tidier AI image panel — Fixed missing spacing at the bottom of the AI image generation panel for a cleaner layout. Visible button hover in light theme — Toolbar split buttons now show a clear hover highlight in the light theme. Snappier toolbar — Streamlined how the ribbon lays out, giving a small speed boost at startup. Fewer background crashes — Fixed a crash that could happen while background tasks were finishing up. Stable app shutdown — Prevented rare crashes when closing the app. Fixed layer removal glitch — Deleting the active layer no longer leaves the layers list in an inconsistent state. Here is what is new in the Photos app (version 2026.11060.2004.0): AI watermarking — AI-generated or edited images can now carry a visible Copilot watermark. You choose Never, Always, or Ask Every Time in Settings, with a confirmation when saving. The watermarking is off by default in settings. Better viewing of small images and pixel art — Tiny images (like 16×16 pixel art) now zoom in far more to fill the screen and stay crisp instead of looking blurry. Select scanned text with the keyboard — When text is detected in an image, you can now navigate and select it using the arrow keys, Shift+Arrow, Home/End, and Ctrl+A, with a clear focus highlight. Fixed a crash in text recognition — Resolved a crash that could close Photos while detecting text in images; the app now recovers gracefully. Easier keyboard navigation — Tabbing through the navigation bar no longer stops on hidden controls, so it takes a single Tab to move past it instead of three. And finally, here is the Sound Recorder (version 11.2605.1.0): Waveform shows with Bluetooth mics — The live waveform now displays correctly when you record using a Bluetooth audio device. No more stray scrollbar — A non-working horizontal scrollbar no longer appears at the bottom of the waveform unless you've zoomed in. Mark button ready right away — The Mark button no longer looks grayed out until you hover over it after opening the app. Markers hidden for WAV files — Markers are now turned off for WAV recordings, since that format can't store them — so they're no longer lost silently. Smoother deleting — Quickly pressing Delete and Enter to remove several recordings in a row no longer triggers a "file doesn't exist" error. Fixed a memory issue — Resolved a memory leak that occurred each time a recording started. You can find all these changelogs in the official documentation here.
  • Recent Achievements

    • Very Popular
      AndrewSteel earned a badge
      Very Popular
    • Veteran
      Taliseian went up a rank
      Veteran
    • One Month Later
      Clizby earned a badge
      One Month Later
    • One Month Later
      Timaximus earned a badge
      One Month Later
    • Week One Done
      Timaximus earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      517
    2. 2
      PsYcHoKiLLa
      170
    3. 3
      +Edouard
      162
    4. 4
      Steven P.
      84
    5. 5
      ATLien_0
      78
  • Tell a friend

    Love Neowin? Tell a friend!