4 ms·
> It makes life hard in companies where binary whitelisting is used. The application would still have to be audited, signed or not, prior to whitelisting.
by korzun 9y ago
> It makes life hard in companies where binary whitelisting is used.
The application would still have to be audited, signed or not, prior to whitelisting.
- sslalready 9y agoIn practise it's much easier to just trust well-known developers by whitelisting their code-signing certificates. You could still get owned, of course, but the benefit here is that you're excluding everything not explicitly whitelisted, including drive-by downloads, crap on portable devices or random programs downloaded off the internet that someone thinks will solve their problem of the day. When people do not code-sign their software every software update is painful. At work, where we run https://github.com/google/santa https://github.com/google/santa, it frequently happens that companies with code-signed software forget to code-sign their auto-updater, or random binaries that run during installation. Most of the time the application crashes/hang during the update (because some piece weren't allowed to run), only to remind to you update the software again when you restart the application.
- aoeuasdf1 9y agoDoes santa work with brew? If not, how do you even function?
- sslalready 9y agoPersonally I've managaged to avoid using it so far. But yes, you can whitelist individual binaries or even directories. The lack of code-signing doesn't prevent whitelisting, it just makes your life harder than necessary.