6 ms·
This is a good illustration of why you should not install apps as administrator. Specifically, you should not install Mac OS packages, which allow for arbitrary
by diebir 11y ago
This is a good illustration of why you should not install apps as administrator. Specifically, you should not install Mac OS packages, which allow for arbitrary pre- and post- install scripts to be executed as root.
Same is true for Windows and Linux.
There are privilege escalation bugs in any OS, but it is usually not a given. Throw the application into ~/Applications as a Mac bundle, worst that will happen is your account will be compromised. Much easier to detect and clean. Most trojans won't even succeed.
We are going to have these problems until the developer community realizes that executing a randomly downloaded package installer as a privileged user is giving away the keys to the kingdom.
Application stores is one solution, but really is not an open one. I'd rather see the apps distributed in a form similar to Apple app bundles, where a non-privileged user can just install the app into their home.
- NN88 11y agoso how do I get around this if most apps I want require this?
- diebir 11y ago1. Petition vendors to stop distributing .pkg's 2. Most packages can be extracted with pkgutil and then just copied into ~/Applications. It is infrequent that somebody needs to modify your OS and if they do, then they better explain why.
- Nullabillity 11y ago> Throw the application into ~/Applications as a Mac bundle, worst that will happen is your account will be compromised. On a typical single-user setup, there's not much difference between an account compromise and a machine compromise anyway.
- woodman 11y agoThat is only true if you have no interest in recovery post compromise. A user level account shouldn't be able to put the system in such a state that online recovery is impossible, whereas a system level account easily can - think loadable kernel modules. Only offline recovery works once you lose trust in the kernel. That is the difference between "Alright grandma, lemme remote in" and "Sorry old lady, better start looking for the factory install CDs". Lets not even get into how screwed we are with UEFI...
- kentonv 11y agoIf you have to wipe the user account anyway, then wiping the system at the same time hardly adds any more effort -- in fact it's probably easier. Your system files are the easiest part of your system to recover, because the originals are readily accessible from the vendor.
- woodman 11y agoI guess it depends. In the grandma scenario it adds a lot more effort. A corporate laptop in a standard AD environment, no problem. In a situation where you've customized the system (custom packages, sshd.conf tuning, flags in rc/csh/sysctl/resolv/loader/randomsbinutilityinstalled2yearsago.conf) it would be a lot more work than just reinstalling the OS. Use backups you say? What if I told you that you could use the very same backups to rollback changes to the user's home directory, in 5 minutes, and not have to reimage the entire machine? I'm just saying: even on a single user setup - there is a world of difference in what options you have open to you, depending upon whether you let the malware hit ring 0 or not.
- theinternetman 11y agoNot sure why anyone with a compromised machine would rather have the risk of a lingering backdoor just to save 1-2 hours clean formatting and reinstalling
- bartvk 11y agoMe neither, but there's a whole industry of software for Windows users that promises to remove malware.
- woodman 11y agoBecause unless an unknown method of privilege elevation was used, it doesn't make sense. Do you throw a pinch of table salt over your shoulder as well? It also has a very strong Microsoft smell to it, where instead of doing root cause analysis on why Windows is misbehaving - you just reboot and cross your fingers.
- 0x0 11y agoI think it's a poor illustration. You could install and run this app as a regular user (and never escalate to administrator) and the app's bundled malware would still absolutely destroy anything of value on your computer. It's the stuff inside $HOME (and $HOME/Documents) that's valuable. Not system binaries in {/bin,/sbin,/Applications} that can be re-downloaded in a second. The problem is that any non-sandboxed app runs with the same uid and full read/write permissions to all of $HOME as well as all the other running processes, even if it only needs read/write access to $HOME/Documents/Appname/ and none of the other pids.
- diebir 11y agoFirst, obviously you can make an account for running the untrusted software, like Bittorrent clients (which are known to carry malware frequently). Second, most malware requires and counts on having admin privileges on target machine. The task of auditing, cleaning and finding out that malware is present is significantly easier if malware is limited to a non-privileged account. With malware running as a non-privileged user you still have to clean up and recover, but you can easily switch an account, compare, audit and trace. The anti-malware tools also still have a chance when OS is not compromised, otherwise it's all lost the moment you ran a malicious post-install script. The more common problem, however, is a regular app install. The goal of the application packager is to make their application work first, and preserve your environment second. So, in many cases even not malware does bad things to your OS. The scripts are usually written by devs that are fairly clueless, which leads to some pretty awful stuff in them. Almost 100% of the time the install/uninstall action is not idempotent, although it should be. What really needs to happen is a shift in a mentality that accepts the idea that apps need to be installed as an administrator (unless the apps are a part of the main OS distro).
- ricardobeat 11y agoHis comment went right past you. What you care about the most on your computer is your personal data, and all of it sits under $HOME. Any script running as $USER can steal sensitive data, wipe out personal and work files, maybe even cloud storage services. None of that requires admin rights. The only solution is sandboxing everything.