Apple Accidentally Approved Malware to Run on macOS
1–10 of 134 posts
Re: Apple Accidentally Approved Malware to Run on macOS
#2Otherwise Apple would have to scan every single binary submitted for notarization, which then puts a pretty large onus on them should anything slip through.
Re: Apple Accidentally Approved Malware to Run on macOS
#3Re: Apple Accidentally Approved Malware to Run on macOS
#4Since the whole point of notarization is to give Apple the power to revoke malicious binaries on its system after-the-fact, this seems like it works by design, no? Apple quickly revoked the notarization once they were alerted of the malware. Otherwise Apple would have to scan every single binary submitted for notarization, which then puts a pretty large onus on them should anything slip through.
Re: Apple Accidentally Approved Malware to Run on macOS
#5It would be news if it was on the App Store, which has a review.
Re: Apple Accidentally Approved Malware to Run on macOS
#6It should be possible to verify developers and distribute open source apps without a cost on macOS.
Re: Apple Accidentally Approved Malware to Run on macOS
#7Since the whole point of notarization is to give Apple the power to revoke malicious binaries on its system after-the-fact, this seems like it works by design, no? Apple quickly revoked the notarization once they were alerted of the malware. Otherwise Apple would have to scan every single binary submitted for notarization, which then puts a pretty large onus on them should anything slip through.
1: https://developer.apple.com/documentation/xcode/notarizing_m...
Re: Apple Accidentally Approved Malware to Run on macOS
#8Since the whole point of notarization is to give Apple the power to revoke malicious binaries on its system after-the-fact, this seems like it works by design, no? Apple quickly revoked the notarization once they were alerted of the malware. Otherwise Apple would have to scan every single binary submitted for notarization, which then puts a pretty large onus on them should anything slip through.
If Apple didn't want scan every binary submitted for notarization then they didn't need to introduce the notarization. They already had the means to revoke malicious binaries after-the-fact by revoking the corresponding developer certificate. The main difference with notarization is that it forces binaries to be submitted to Apple early for inspection in comparison with signing using developer certificate which happe…
Re: Apple Accidentally Approved Malware to Run on macOS
#9I'm confused, when did Apple "approve" anything? The notarisation software isn't a review process.
Re: Apple Accidentally Approved Malware to Run on macOS
#10Those news about Apple approving malware are so wrong: the notarization is not an approval, it's more like a registration. It would be news if it was on the App Store, which has a review.
Apple seem to be saying that it is more than a registration process. Not passing a human review would be bigger, but it is a review of a kind.
[0] https://developer.apple.com/documentation/xcode/notarizing_m...