said by StopandGo:said by bjf123:but where in the AP article did it mention the user provided the admin password? The article certainly implied that the user did nothing but click on links.
The media droids are ignoring that one detail. The user got infected with the Leap.A worm. It requires an admin password to propagate. Perhaps if the user is silly enough to be clicking on links as an admin user it might get thru. I guess the lesson here is Mac users need to use common sense and stop running as root. The "threat" here is from willful ignorance, not a flaw in the OS. (yet)
I find a few things wrong with this. First of all, the vast majority of OS X users only have one acct on their computer. They are unconcerned with having to create a 2nd acct. I don't blame them.
Second, even if you run as admin, in order to run any system functions, you are prompted to put in your password. Inherent admin validation is the biggest hole for a virus to exploit, and one of the reasons why Windows is so easy to code viruses for.