Some security experts worry that Mac customers who opt to run the Windows operating system will need reminding to keep up with all the various viruses and other threats.
Users installing Windows XP on Intel-based Macs face some special security issues, a security expert said Thursday.
By applying Apple Computer's just-released Boot Camp, Mac owners can now create a dual-boot system that runs either Mac OS X or Windows XP. It's the latter that worries Ken Dunham, the director of the rapid response team at security intelligence firm iDefense.
"When a Mac is booted into Windows, it can be attacked by the same [exploits] that threaten any Windows PC," said Dunham. "If you're running an unpatched version of Windows XP on any box, it'll be hacked pretty quickly."
Of the two operating systems, "naturally with Windows you're more at risk," said Dunham. Neither Mac OS X or Windows are invulnerable to attack -- the former was the subject earlier this year of its first zero-day bug -- but the latter is, by far, the one that draws most attacker attention.
But it's not the vulnerability of Windows that concerns Dunham; it's the fact that the Mac will have multiple operating systems on its hard drive.
"It's the best of both worlds [having Mac OS X and Windows] on one machine, but the user also has to manage two OSes."
Typically, argued Dunham, people are less diligent about updating their secondary system, whether that's an at-home machine (when the primary is at the office) or a second computer used by children. The same applies here.
"This dual-boot may create another set of Windows installs that are secondary systems, ones that might not be patched as often as they should be," Dunham said.
On the bright side, an attack on the Windows XP part of the Mac probably wouldn't have an effect on the Mac OS X partition. "It actually appears to be a pretty good design," said Dunham, who noted that while the Mac OS can read (and depending on the formatting of the Windows partition, also write to) the Windows volume, the opposite's not true.
5 Top Federal Initiatives For 2015As InformationWeek Government readers were busy firming up their fiscal year 2015 budgets, we asked them to rate more than 30 IT initiatives in terms of importance and current leadership focus. No surprise, among more than 30 options, security is No. 1. After that, things get less predictable.