3 ms·
This is odd, my proxy doesn't seem to show this. I will try to load my root cert into Wireshark and check. Edit: Checked and double checked: When I run a new s
by usmannk 6y ago
This is odd, my proxy doesn't seem to show this. I will try to load my root cert into Wireshark and check.
Edit: Checked and double checked: When I run a new shell script, syspolicyd just makes a connection with no application data
- _qulr 6y agoI'd recommend trying this: Download a notarized Mac app, delete any stapled notarization ticket (.app/Contents/CodeResources), and then trace the launch. What do you see, and does the system let you open the app? Does it say it checked for malware?
- usmannk 6y agoAh I see, looks like we're not running quite the same experiment. I suspect that anything including an app bundle ID is going to see some more interesting traffic.
- _qulr 6y agoDon't suspect, test. ;-) I'm running both experiments. I've tested and compared script notarization to app notarization. You're getting apparently unusual results with script notarization. So the natural next step would be to compare against app notarization.
- usmannk 6y agoAgh, I think it was cert pinning. Looks like the connection is terminated if you're snooping. I see the same results as you now. Thanks!
- deleted 6y ago[deleted]