Live data from Hacker News

Yet another macOS privacy protections bypass

lapcatsoftware.com

41–50 of 94 posts

Re: Yet another macOS privacy protections bypass

#41
post #35

Earlier quoted context omitted.

No, not any random app. You knowingly chose to install the app. It either came from the App Store or it was notarized by Apple. There are just so many reasons why software needs to access your hard drive. My app, for example, needs to write files in ~/Library/Application Support/Chrome in order to add native messaging permissions for my extension. Can you imagine the number of "Karens" that are going to email me beca…

> Apple did the right thing by only adding warnings for more sensitive areas like your Downloads or Documents folder, but any more than that and I think it'll cause more harm than good. Browsing history is not sensitive‽

Sorry, I didn't mean to argue for apps to be able to read your browsing history.

The main point I was trying to make was that apps having network access without warning is more of a security/privacy issue than apps being able to read local files without warning. It's probably why Little Snitch became so popular and why I think Apple is in the process of shoving them out of the market by building it into the OS (I'm guessing!).

Re: Yet another macOS privacy protections bypass

#42
post #17

Earlier quoted context omitted.

You did use the word serious enough to make it compelling. But the author’s biography doesn’t mean that his comment wasn’t flippant. He’s proved that an well-behaved, codesigned app can list file metadata about files in restricted directories. He hasn’t proven the sandbox compromised. You claim he has so much serious evidence, link us there. Don’t just string adjectives together. I have great respect for Jeff, but he…

A well behaved, codesigned app being able to list metadata about files in restricted directories is a sandbox compromise. In what viewpoint is it not?

As pointed out by the most voted top level comment it's a kernel issue.

Re: Yet another macOS privacy protections bypass

#43
post #12

Quick note: The report makes it sound like /bin/ls is being given special privileges. That would be reminiscent of many past macOS security issues: processes are treated differently based on their code signature and entitlements, and sometimes that has unexpected consequences. But that's not the case here. /bin/ls has no entitlements. And if I modify the sample project to just call stat() directly rather than invokin…

> That would be reminiscent of many past macOS security issues: processes are treated differently based on their code signature and entitlements, and sometimes that has unexpected consequences. Hmm, I wonder if this is the root cause of something my friend group found in high school. We had macs that were locked down and I think it was something the system did vs third-party software but I could be mistaken. Pretty m…

Hahaha this is great. Reminds me of my first suspension from school when I used MS Word hyperlinks to get to all the drives "hidden" by the network admins. This included the homework mailbox drives, so naturally I found my least favourite teacher's inbox, hid the folder with the work in it and then created a pair of links pointing to one another. Good times. I wouldn't have been found out if I hadn't removed the graphic for the login screen and replaced it with the Christmas version in May... and then bragged about it when everyone in my class noticed.

Re: Yet another macOS privacy protections bypass

#44
post #42

Earlier quoted context omitted.

A well behaved, codesigned app being able to list metadata about files in restricted directories is a sandbox compromise. In what viewpoint is it not?

As pointed out by the most voted top level comment it's a kernel issue.

That doesn't mean it's not an issue.

I would like Apple to not roll out BS prompts that make my life more difficult until those prompts are actually capable of protecting some of the most sensitive data on my machine.

Re: Yet another macOS privacy protections bypass

#45
post #43

Earlier quoted context omitted.

> That would be reminiscent of many past macOS security issues: processes are treated differently based on their code signature and entitlements, and sometimes that has unexpected consequences. Hmm, I wonder if this is the root cause of something my friend group found in high school. We had macs that were locked down and I think it was something the system did vs third-party software but I could be mistaken. Pretty m…

Hahaha this is great. Reminds me of my first suspension from school when I used MS Word hyperlinks to get to all the drives "hidden" by the network admins. This included the homework mailbox drives, so naturally I found my least favourite teacher's inbox, hid the folder with the work in it and then created a pair of links pointing to one another. Good times. I wouldn't have been found out if I hadn't removed the grap…

It's funny how changing grades is a pretty common trope but surprisingly not that hard to do back in the old days. I remember reporting an issue where the school district had their reporting tool just open to the internet.

I don't know how I didn't get in trouble for all the snooping around I did.

Re: Yet another macOS privacy protections bypass

#46
post #12

Quick note: The report makes it sound like /bin/ls is being given special privileges. That would be reminiscent of many past macOS security issues: processes are treated differently based on their code signature and entitlements, and sometimes that has unexpected consequences. But that's not the case here. /bin/ls has no entitlements. And if I modify the sample project to just call stat() directly rather than invokin…

> That would be reminiscent of many past macOS security issues: processes are treated differently based on their code signature and entitlements, and sometimes that has unexpected consequences. Hmm, I wonder if this is the root cause of something my friend group found in high school. We had macs that were locked down and I think it was something the system did vs third-party software but I could be mistaken. Pretty m…

Oh man, this reminds me of my own experience with early computers in the classroom. Back in these days there were two computers in each classroom. One for the teacher and one for the students to share. Generally, students never used the single computer because what is the point, there's only one. My AP Calc teacher's "student" computer was broken. The school IT department couldn't be fussed to fix it, so we asked if we could and we did. As a reward for fixing the computer, we were allowed to use it. We played GTA (original) every day. One person was back there at a time during lecture. Your goal was to find a flame thrower and a chain of joggers, we called them the school children. If you killed all the joggers in the chain you got a big bonus. You can see where this is headed. Once you got the flame thrower and the school children on the screen you announced it to the class, lecture would stop, you'd flame thrower the school children while everyone watched, and then you traded off to the next person and the lecture continued. All but one person passed the AP exam that year.

Re: Yet another macOS privacy protections bypass

#47
post #43

Earlier quoted context omitted.

> That would be reminiscent of many past macOS security issues: processes are treated differently based on their code signature and entitlements, and sometimes that has unexpected consequences. Hmm, I wonder if this is the root cause of something my friend group found in high school. We had macs that were locked down and I think it was something the system did vs third-party software but I could be mistaken. Pretty m…

Hahaha this is great. Reminds me of my first suspension from school when I used MS Word hyperlinks to get to all the drives "hidden" by the network admins. This included the homework mailbox drives, so naturally I found my least favourite teacher's inbox, hid the folder with the work in it and then created a pair of links pointing to one another. Good times. I wouldn't have been found out if I hadn't removed the grap…

Bragging, a very similar thing was my downfall back when I was much younger.

In middle school I had this weird idea to collect everyone's ID number. It, coupled with your name, would log you into everything on the computers. To this day I don't know why I wanted this info other than to have it. I never once used it for any purpose, I think I tested 1 or 2 but never touched any files. I had a HyperStudio stack (saved to my network drive) that had hidden buttons and a certain sequence you had to press them to get to the "database" (just text entry field that I saved 1 name and 1 ID number per line). It was painfully easy to collect the numbers as most kids had their class schedule on the outside or inside of their binder they carried around. The ID number was only 6 or 8 digits so it was easy to memorize, write down, and store in HyperStudio later.

But alas, stupid younger me thought it would be a good comeback to rattle off someone's ID number when they were picking on me one time which led to a 3 day in-school suspension and loss of computer privileges till the end of the year. They made me show the IT guy where I had stored the numbers (how to navigate my HyperStudio project) and phrases like "hacking" and "hacker" were thrown around even though this was literally equivalent to writing the numbers in a notebook but since I had used a computer to store the data it became a way bigger thing in their minds. Even "funnier" (not to me at the time) I had a friend that helped me collect the numbers (again, this was stupid easy, felt like a fun game to figure out how to get it, and who could collect more the fastest) who got a lighter punishment and didn't lose computer access.

Fast forward to high school and I ended up writing 2 different PHP-based apps for the school. A library attendance program that teachers used to mark that they were sending kids to the library that the library could see (so they didn't just skip school I guess? Or goof off in the halls) and to keep track of who was in the library and how long they had been there. I also wrote an online voting platform for the school that they could re-use for things like Homecoming court/Prom court/Senior superlatives/etc. The reason I bring up both of these? The high school gave me a massive CSV of all the students in the school.... and their ID number to be used for login to the platforms. I still get a good chuckle out of that.

Re: Yet another macOS privacy protections bypass

#48
post #12

Quick note: The report makes it sound like /bin/ls is being given special privileges. That would be reminiscent of many past macOS security issues: processes are treated differently based on their code signature and entitlements, and sometimes that has unexpected consequences. But that's not the case here. /bin/ls has no entitlements. And if I modify the sample project to just call stat() directly rather than invokin…

> That would be reminiscent of many past macOS security issues: processes are treated differently based on their code signature and entitlements, and sometimes that has unexpected consequences. Hmm, I wonder if this is the root cause of something my friend group found in high school. We had macs that were locked down and I think it was something the system did vs third-party software but I could be mistaken. Pretty m…

How long ago was this?

Re: Yet another macOS privacy protections bypass

#49
post #45
post #43

Earlier quoted context omitted.

Hahaha this is great. Reminds me of my first suspension from school when I used MS Word hyperlinks to get to all the drives "hidden" by the network admins. This included the homework mailbox drives, so naturally I found my least favourite teacher's inbox, hid the folder with the work in it and then created a pair of links pointing to one another. Good times. I wouldn't have been found out if I hadn't removed the grap…

It's funny how changing grades is a pretty common trope but surprisingly not that hard to do back in the old days. I remember reporting an issue where the school district had their reporting tool just open to the internet. I don't know how I didn't get in trouble for all the snooping around I did.

https://xkcd.com/2385/

Re: Yet another macOS privacy protections bypass

#50

Earlier quoted context omitted.

> That would be reminiscent of many past macOS security issues: processes are treated differently based on their code signature and entitlements, and sometimes that has unexpected consequences. Hmm, I wonder if this is the root cause of something my friend group found in high school. We had macs that were locked down and I think it was something the system did vs third-party software but I could be mistaken. Pretty m…

Oh man, this reminds me of my own experience with early computers in the classroom. Back in these days there were two computers in each classroom. One for the teacher and one for the students to share. Generally, students never used the single computer because what is the point, there's only one. My AP Calc teacher's "student" computer was broken. The school IT department couldn't be fussed to fix it, so we asked if…

Ahh yes, I helped fix computers throughout my time in primary education to the point I'd get pulled from classes to help sometimes. I had cemented my "status" back in elementary school when I was a "computer genius" because I knew how to mount the network drive then open and save files to it (which led to me being tasked with helping everyone else of course lol). I used to take every single chance to put my hands on a computer and it paid off in present day when I get paid to do it.
Post reply on HN