Apple is the new hacker bulls-eye





NEW YORK (CNNMoney.com) -- When Apple was just a niche maker of Mac computers and only truly popular among college students and graphic designers, hackers paid little attention to the company. Instead, they focused on Microsoft, which had more than a 90% share of the PC operating system market.

Those days are over. Recent iPad security scares are a sign that Apple's devices are a growing target for hackers, spammers and malicious coders.

"Market share is a pretty good indicator of who hackers are going after," said Kevin Haley, director at Symantec Security Response. "Hackers are motivated by money, so they want to get access to the most amount of people."

Hacker group Goatse Security was able to obtain 114,000 iPad 3G users' e-mail addresses and iPad SIM card ID numbers from AT&T's (T, Fortune 500) website last week. The vulnerability was on AT&T's site, but any hit against the iPad dings Apple as well.

And in a blog post, Goatse Security said Monday that a "skilled attacker" could take advantage of a weakness in the iPad's Safari Internet browser to launch a spam attack from a compromised iPad.

"This is a wake-up call for Apple, and it cannot afford to hit the snooze button," said Hemanshu Nigam, founder of SSP Blue, a cybersecurity consulting firm. "The hacker community focuses on companies that are on the top of their games. Apple has gained enough market share that it has caught hackers' attention."

It's not surprising that Apple is becoming a growing target -- it's simply a matter of scale. Cybercriminals try to hack the software that most people use to access the Internet, and increasingly, that software is made by Apple. While Apple's PC market share is still in the single digits, Apple is now the second largest smart phone maker in the United States, behind only BlackBerry maker Research in Motion (RIMM). It has also sold more than 2 million iPads in just two months.

"Any company's device or platform on which lots and lots of people are exchanging or storing data is going to be susceptible to an attack," said Fred Rica, principal security analyst at PricewaterhouseCoopers. "Hackers are beginning to change over to other platforms that hadn't been traditional targets, particularly to mobile."

Response is critical

As Apple (AAPL, Fortune 500) products become higher-profile targets, its response is going to be tested. The company's stance on security has long been "don't worry about it." For instance, on its website Apple says simply, "Mac OS X doesn't get PC viruses." The iPhone and iPad websites don't even mention security.

Apple claims that the Unix framework that its Mac operating system is built on is inherently safer than Windows. The truth is that Mac OS has as many vulnerabilities as Windows, according to Nigam -- Apple patches its products just often as Microsoft (MSFT, Fortune 500) does.

In the past, Apple has responded quietly when vulnerabilities are exposed, patching products through automatic updates with no announcement. The company's famous "Get a Mac" ads say Microsoft's constant security updates and alerts interfere with users' ability to do work on their computers. Ironically, Apple's Safari browser's lack of security alerts is one of the factors contributing to the security hole in the iPad, according to Goatse Security.

Apple did not respond to requests for comment.

"Suggesting Apple doesn't get viruses gives its users a completely false sense of security," Nigam said. "It's essentially taunting hackers. They'll take it as a challenge, and just start exploiting Apple's user base."

As a result, Nigam suggested it's time for Apple to change it's attitude. Right now, Apple prioritizes the user experience ahead of security. That can backfire.

"Apple has the capability to take charge of this situation now," he said. "If it doesn't, it's risking damage to its reputation for the long haul, a la Microsoft."