The British security firm Intego has published a security memo that provides a clear and detailed view of Apple’s new XProtect anti-virus system in Snow Leopard.
There are several interesting tidbits: Apple’s new XProtect system cannot recognize all the variants of the Trojans it is supposed to protect against, for example.
Also, the XProtect system does not spot Trojans hidden inside .mpkg files downloaded from the internet, a major weakness, according to Intego. (Apple’s installer recognizes two types of files — .pkg files for simple packages, and .mpkg files that contain multiple packages to be installed.)
The memo is patently self-serving — Intego sells several anti-virus and privacy packages for the Mac — but nonetheless provides a clear and detailed view of what Apple’s new XProtect system does — and doesn’t do.
The full memo after the jump.