5 ms·
Are you implying you (or anybody) can somehow verify the intentions of any macOS app? You should publish.
by mfukar 9y ago
Are you implying you (or anybody) can somehow verify the intentions of any macOS app?
You should publish.
- dpark 9y agoI can verify that running random executables you receive in email is a bad idea, as is downloading apps from untrusted sources. I don't think this is groundbreaking or worthy of publishing in a reputable journal.
- deleted 9y ago[deleted]
- mfukar 9y agoYou've missed the point. "Trusted", signed applications can do the same things this PoC did.
- breakingcups 9y agoRecently CCleaner was hacked to distribute infected versions through it's updating mechanism. It sure would be nice if gaining a foothold on my computer didn't instantly mean gaining complete control over al my credentials.
- CompuHacker 9y agoEncrypt your credentials at rest and aggressively purge them from memory when any are decrypted.
- FabHK 9y agoThe idea (and assumption) was that the macOS Keychain app does encrypt my credentials at rest (and allows access only after express user permission).
- dpark 9y agoFor sure, Apple should fix this bug, and presumably they will. Some basic app hygiene greatly reduces the risk though.
- dangerface 9y agoThats a straw man argument the comment you are replying to specifically said "verify the intentions of any macOS app". If you disagree with his argument perhaps you could give an actual counter argument?
- dpark 9y agoThat comment itself was a straw man. Obviously the answer is no, no one can solve the halting problem and verify the intentions of any arbitrary app.