4 ms·
One should of course verify its integrity BEFORE installing it and letting it replace spctl. The real question is whether the spctl tool displays "Apple" in ca
by devit 11y ago
One should of course verify its integrity BEFORE installing it and letting it replace spctl.
The real question is whether the spctl tool displays "Apple" in case of a valid (relative to generic CAs) certificate issued to "Apple". Hopefully that's not the case.
Another risk is a specifically designed executable capable of compromising spctl.
- X-Istence 11y agoOn machines with Gatekeeper enabled you won't be able to open the application without it verifying the signature. Devs would have to on purpose remove that protection to run this bad version of Xcode, and after that it is practically game over.
- e28eta 11y agoHow about an "install" script, written in your scripting language of choice? Sufficiently obscure language, obfuscate the code, leave misleading comments and copyright statements to look like its from Apple...
- Sephiroth87 11y agoIt might work, but an "experienced" developer might know that there no install script for Xcode (also, an experienced developer will probably not download from a random server, so i guess that's something...)