4 ms·
This attitude from users is a very real problem, but I'd argue it's platform agnostic. For instance there were headlines around the internet not too long ago s
by 2cb 6y ago
This attitude from users is a very real problem, but I'd argue it's platform agnostic.
For instance there were headlines around the internet not too long ago stating Android is more secure than iOS based on claims made by Zerodium.
Any Android user who read that may well have the same attitude you've described from iOS users. And it's potentially far more dangerous on Android because it allows you to sideload apps.
You can even extend it to Windows. Your average user will buy a laptop preinstalled with McAfee [1] and think "no need to worry about viruses now because I've got an antivirus."
Don't get me wrong I agree it's perfectly reasonable to be critical of Apple when it's warranted, but we don't yet know if it is in this case. It's entirely possible (and fairly likely) this malware was delivered as a trojan using pop ups the user had to interact with. If that's the case you can't blame Apple for user error, especially when trojans exist for every single OS that allow the user to install software from the internet.
> most users perform two types of installs: relatively safe ones through the App Store, or venturing out into the wild west of the internet and bringing home a random binary that hopefully does what it says.
This seems to imply any software installed from the App Store is safe while anything from outside the App Store is dangerous.
Isn't the implication that App Store downloads must automatically be safe falling into the same trap you're criticising here?
Quotes from the article:
> Developer ID Saotia Seay (5834W6MYX3) – v1 bystander binary signature revoked by Apple
> Developer ID Julie Willey (MSZ3ZH74RK) – v2 bystander binary signature revoked by Apple
So both of these malware packages were signed by Apple.
Seems like relying on Apple's review processes to determine how safe a particular binary is only provides the same false sense of security you're describing.
[1] https://www.youtube.com/watch?v=bKgf5PaBzyg https://www.youtube.com/watch?v=bKgf5PaBzyg (sorry, couldn't resist)
- codezero 6y agoI’m curious if more will come out of this but it sounds like the attackers probably already attacked Julie or her employer (she appears to have worked for Tile, Oculus and others) and just signed the app with her ID. I bet they have a ton of these credentials in their pocket from previous infections. Since this didn’t go through the App Store it probably wasn’t reviewed but the developer’s certificate would be checked when it’s run - hence the revocation now.
- codezero 6y agoEdit: I'm also pretty sure this means they breached her iCloud account entirely - as I am pretty sure you need to sign in to your account to sign applications. That's pretty scary, and I hope if it's possible that is the case, someone is looking into it!