5 ms·
I thought only apps signed by "identified developers" are run by default on Macs with Gatekeeper now. Shouldn't code-signing have prevented this? Unless they in
by sd8f9iu 11y ago
I thought only apps signed by "identified developers" are run by default on Macs with Gatekeeper now. Shouldn't code-signing have prevented this? Unless they inserted the malware before the signing process.
- msh 11y agoHold down control, right click and choose run. Then once will run unsigned binaries (after a warning).
- __david__ 11y agoA small nit: just plain right click, or hold down control and left click, which is the same as right click.
- coldtea 11y ago>I thought only apps signed by "identified developers" are run by default on Macs with Gatekeeper now. Shouldn't code-signing have prevented this? "By default". Most developers don't bother to register, and lots of people change the default (and after that, they can right click to open the app and bypass the warning).
- jakobegger 11y agoAnyone can sign up for the Apple Developer Program to become an "identified developer", so there's nothing that stops an attacker from signing their malware.
- thesimon 11y agoAnd according to the analysis [0], this is exactly what they did. They used a different cert to sign their malware. I have to admit that Windows' UAC is better in that regard, as it shows the signees name. But of course this is only useful if you know the "right" name. [0] http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-ransomware-keranger-infected-transmission-bittorrent-client-installer/ http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-...
- jakobegger 11y agoYeah, I think this is a major issue on OS X. For the average user it is impossible to tell who signed an app, if it is sandboxed, and what permissions it has. Hell, using the codesign command to extract entitlements from all binaries in a package is hard even for advanced users... (There is third party tool named RB App Checker which does make these tasks a bit easier, though)
- arm 11y agoWell, I guess that’s at least one advantage for apps that use Installer.app¹ to install; Installer.app makes it really easy to see the certificate². ―――――― ¹ — https://en.wikipedia.org/wiki/Installer_(OS_X) https://en.wikipedia.org/wiki/Installer_(OS_X) ² — http://f.cl.ly/items/1s1E3n19273M1l3i3S2X/developer_id_installer.png http://f.cl.ly/items/1s1E3n19273M1l3i3S2X/developer_id_insta...
- zyxley 11y agoThe malware version was signed with the Transmission developer key.
- arm 11y agoNo, it wasn’t: “The two KeRanger infected Transmission installers were signed with a legitimate certificate issued by Apple. The developer ID in this certificate is “POLISAN BOYA SANAYI VE TICARET ANONIM SIRKETI (Z7276PX673)”, which was different from the developer ID used to sign previous versions of the Transmission installer. In the code signing information, we found that these installers were generated and signed on the morning of March 4.” From: http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-ransomware-keranger-infected-transmission-bittorrent-client-installer/ http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-...
- lottin 11y ago> which was different from the developer ID used to sign previous versions of the Transmission installer and that didn't ring any alarm bells?
- arm 11y agoFor the end user? No, it wouldn’t. As thesimon and jakobegger, respectively, said: “And according to the analysis, this is exactly what they did. They used a different cert to sign their malware. I have to admit that Windows' UAC is better in that regard, as it shows the signees name. But of course this is only useful if you know the "right" name.” “Yeah, I think this is a major issue on OS X. For the average user it is impossible to tell who signed an app, if it is sandboxed, and what permissions it has. Hell, using the codesign command to extract entitlements from all binaries in a package is hard even for advanced users... (There is third party tool named RB App Checker which does make these tasks a bit easier, though)” …in this comment thread: https://news.ycombinator.com/item?id=11234966 https://news.ycombinator.com/item?id=11234966
- ololoev 11y agoIt did actually, but only for in-app updates [0]. [0]: https://forum.transmissionbt.com/viewtopic.php?f=4&t=17835 https://forum.transmissionbt.com/viewtopic.php?f=4&t=17835