dkp said:
Windows viruses will have read/write access to your entire Mac hard drive, and all remote mounts you have have attached to your Mac. These viruses can delete your entire home directory there, or copy parts of it or any readable part of your hard drive to a remote location on the internet. They can quietly steal your VM's and you won't know it has happened. They will run just fine at their new home. The viruses can read and exploit your email, read all your documents and share them with the world. None of this is terribly hard to do once the virus has invaded your Windows system. It is as bad as if you'd gotten a Mac virus. All you need to know is your Mac is not well protected from Windows viruses that allow running arbitrary code in Windows.
Not everyone knows this is possible.
Actually, windows viruses would only have read/write access to directories my account has read/write access. That is far from my entire Mac hard drive and remote mounts I have attached to my Mac. Many of the remote mounts are read only mounts - especially many of the remote windows mounts.
Yes, the viruses can delete my entire home directory. This involves two critical components however. One is that I am stupid enough to not realize in this day and age how much security software must be loaded on a windows system that has a network connection. The second would be that I would allow the windows system access to the internet to get infected. The second is sometimes true, since within BootCamp, I do allow internet access. That still means I would have to get infected first. There are more than enough IPS devices, both network and host based that protect against 0-day attacks. Network based ones operate through anomalies in network and/or protocol traffic, while the host based systems operate through anomalies to standard system operation.
The reason their are so many zombies and spambots out there are people still don't even have enough of a basic clue to realize they need to run security software on their system, and/or they trust in windows security.
Granted, I've been in infosec for about 12 years now, but i've been using AV products for almost 20 years now. Between stores, magazines, and preloaded software, anybody not running protection on their machines deserve what they get. I do believe that application and OS vendors should do everything within their power to prevent memory leaks and buffer overflows, I don't however believe they should cripple a product to just to benefit a few ignorant people.
People gain a basic understanding of the threats while driving before they connect their car to the world through roads, why should it be any different before connecting their computer to the world? Or should we just put a governer on each car for speed that users have to take off the car in order to use it to it's full potential. I'd rather a system that is maxed for performance with the capabilities for security.
Realistically, even someone in pure Windows, using BootCamp to boot into Windows is still vulnerable to their Mac side being attacked. That partition still exists. Heck, i imagine it would be quite easy to configure a worm to zero out a partition so it is fully unrecoverable.
Yes, I agree that the implication should be known of a setting, but I think it absurd that fear should win out over functionality.