Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
I can be Apple, and so can you – Bypassing some macOS signature checks (okta.com)
3 points by eps on June 12, 2018 | hide | past | favorite | 1 comment


From the ArsTechnica article [1]:

According to the researchers, the mechanism many macOS security tools have used since 2007 to check digital signatures has been trivial to bypass. As a result, it has been possible for anyone to pass off malicious code as an app that was signed with the key Apple uses to sign its apps.

...

"To be clear, this is not a vulnerability or bug in Apple’s code... basically just unclear/confusing documentation that led to people using their API incorrectly," Wardle told Ars. "Apple updated [its] documents to be more clear, and third-party developers just have to invoke the API with a more comprehensive flag (that was always available)."

[1] https://arstechnica.com/information-technology/2018/06/simpl...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: