Live data from Hacker News

Apple Accidentally Approved Malware to Run on macOS

wired.com

111–120 of 134 posts

Re: Apple Accidentally Approved Malware to Run on macOS

#111
post #4
post #2

Since the whole point of notarization is to give Apple the power to revoke malicious binaries on its system after-the-fact, this seems like it works by design, no? Apple quickly revoked the notarization once they were alerted of the malware. Otherwise Apple would have to scan every single binary submitted for notarization, which then puts a pretty large onus on them should anything slip through.

If Apple didn't want scan every binary submitted for notarization then they didn't need to introduce the notarization. They already had the means to revoke malicious binaries after-the-fact by revoking the corresponding developer certificate. The main difference with notarization is that it forces binaries to be submitted to Apple early for inspection in comparison with signing using developer certificate which happe…

> They already had the means to revoke malicious binaries after-the-fact by revoking the corresponding developer certificate

That's a big hammer because it breaks everything that was ever signed with the certificate.

Re: Apple Accidentally Approved Malware to Run on macOS

#112
post #109

Earlier quoted context omitted.

Nope, you can only generate 5 Developer ID Application certificates for the lifetime of your Developer account. It's a real pain to get another one, I had lost all of mine (didn't have a real Mac, so was using various temporary Hackintosh and KVM installs) and it took 2 months of emails to both Developer support and the Security team to get another one issued [and backed up].

It took you five times before you learned to make backups? Woah.

That's a bit condescending. The signing stack is very complicated and folks often make mistakes when attempting to back up (export) the correct private key and certificate pair.

Re: Apple Accidentally Approved Malware to Run on macOS

#113
post #4

Earlier quoted context omitted.

If Apple didn't want scan every binary submitted for notarization then they didn't need to introduce the notarization. They already had the means to revoke malicious binaries after-the-fact by revoking the corresponding developer certificate. The main difference with notarization is that it forces binaries to be submitted to Apple early for inspection in comparison with signing using developer certificate which happe…

> They already had the means to revoke malicious binaries after-the-fact by revoking the corresponding developer certificate That's a big hammer because it breaks everything that was ever signed with the certificate.

That's fine with me - if the developer was caught with one malware-infected app, I would worry about the other malware they shipped that wasn't caught.

Re: Apple Accidentally Approved Malware to Run on macOS

#114
post #95

Earlier quoted context omitted.

The thing to remember is that, under all the chrome and Apple styling, macOS is rooted in BSD. So the power users who enjoy the *nix-y bits of macOS and are looking for a replacement will look for something that gives them more of that.

Is this a real thing? Like there are people that don't VM/SSH into Linux but use shell? What demographic is this? College kids and Apple employees? It seems like minor benefit in an otherwise atrocious platform.

Over the years I haven't found very many unix tools I couldn't install with homebrew. I'm also a big fan of the move from Bash to ZSH. Why start up a VM or SSH into another machine if I can just use Terminal or Iterm.

Re: Apple Accidentally Approved Malware to Run on macOS

#115
post #99

Earlier quoted context omitted.

This is clearly anecdotal, but nearly every dev/engineer from every company I have ever worked for has had an MBP as their work laptop.

I'm the other way, I've never seen a Macbook in an (Engineering) office setting, four fortune 500, two small businesses. I've seen them at University and some non STEM students homes. That said, I see iPhones at work, but probably because they are not critical to doing anything other than email.

I worked at SAP for seven years in their cloud business and about half the engineering staff had MBP laptops. Some engineering teams used only Macs. Operations was the same way. Engineering computer usage in India was mostly Windows, China was ~50% Macs, US/Canada was ~80% Macs, and Europe was ~50% Macs.

Re: Apple Accidentally Approved Malware to Run on macOS

#116
post #67

Earlier quoted context omitted.

I think open source licenses are ripe for an update with the following clauses to deal with FAANG companies: This software shall not be used on platforms that hinder users in their free choice of software. This software shall not be used to create or in conjunction with adware, spyware, or other malicious software. (Perhaps after a lawyer has reworded it properly so people can't pretend to not understand what is mean…

> This software is free for personal use, and for commercial use by companies with an annual revenue less than $1B. I've been advocating for something similar: > This software is free for any entity that does not contain material stakeholders (bond holders, debt holders, etc) that are billionaires. A yearly licence fee of $1m waives this requirement. Something like that. I'm sick of wealth centralization. If a startu…

"My core beef with billionaires is that they do not pay their fair share in taxes."

Mine is pretending they're not freeloading. A close second is the performant persecution complex. Third might be the rationalist rhetoric about slippery slopes (eg anything less than Freedom Markets™ is socialism).

Re: Apple Accidentally Approved Malware to Run on macOS

#117
post #109

Earlier quoted context omitted.

Nope, you can only generate 5 Developer ID Application certificates for the lifetime of your Developer account. It's a real pain to get another one, I had lost all of mine (didn't have a real Mac, so was using various temporary Hackintosh and KVM installs) and it took 2 months of emails to both Developer support and the Security team to get another one issued [and backed up].

It took you five times before you learned to make backups? Woah.

I admit it was foolish, but this was over 3 years and I didn't know there was a limit on the number of certificates you could generate.

Re: Apple Accidentally Approved Malware to Run on macOS

#118
post #62

Earlier quoted context omitted.

> There’s no attempt by Apple to claim that the application is safe or does what it says on the tin. So that isn't part of the notarization process. It still was approved by Apple and thus was notarised. > It’s like claiming that the outcome of toasting a sandwich is approval or rejection, no the outcome of toasting a sandwich is you have a sandwich that is toasted, aka “toasted sandwich.” That's disingenuous. If I s…

If I set up a toasting service and you sent me a ham and cheese sandwich spread with Nutella, you're going to get it back toasted. That doesn't mean that I approve of that nasty sandwich filling though.

Then you should not toast it.

Re: Apple Accidentally Approved Malware to Run on macOS

#119
post #4

Earlier quoted context omitted.

If Apple didn't want scan every binary submitted for notarization then they didn't need to introduce the notarization. They already had the means to revoke malicious binaries after-the-fact by revoking the corresponding developer certificate. The main difference with notarization is that it forces binaries to be submitted to Apple early for inspection in comparison with signing using developer certificate which happe…

> They already had the means to revoke malicious binaries after-the-fact by revoking the corresponding developer certificate That's a big hammer because it breaks everything that was ever signed with the certificate.

Not true. They can make the certificate invalid after a certain date, while still allowing software signed before that date. This happened when Panic lost their signing certificate.

Re: Apple Accidentally Approved Malware to Run on macOS

#120
post #67

Earlier quoted context omitted.

I think open source licenses are ripe for an update with the following clauses to deal with FAANG companies: This software shall not be used on platforms that hinder users in their free choice of software. This software shall not be used to create or in conjunction with adware, spyware, or other malicious software. (Perhaps after a lawyer has reworded it properly so people can't pretend to not understand what is mean…

I appreciate your eagerness and positivity but I fear it's not a solution. After all, who defines 'hinder', 'adware' or 'spyware'? (I'm reminded of the phrase "one man's terrorist is another man's freedom fighter".) Any company willing to make adware/spyware probably isn't above ignoring a plea in a license agreement. There are laws against burglary, assault, embezzlement, murder, too, and even with very harsh penalt…

The developer account is much cheaper than lawyers and process required to set up a 500M subsidiary, so I don't think we even need to think of this edge case.
Post reply on HN