3 ms·
This looks extremely scary to me, they say you can avoid having to noterize your apps with apple and microsoft because their installers are already approved. Wh
by greatjack613 5y ago
This looks extremely scary to me, they say you can avoid having to noterize your apps with apple and microsoft because their installers are already approved. What happens when someone publishes some malware application using their wrapped and noterized installer? Apple and microsoft will then flag all other applications that used jdeploy as malware as well since they are all relying on the same noterized installer application.
Super risky and definitely not a good approach from a security perspective.
- jeroenhd 5y agoIt definitely bypasses signature checks on macOS and Windows. I don't know if that's actually a bad thing for security, though. Notarization and code signing has hardly posed a problem for malware on either platform so far.
- ryan29 5y ago> Notarization and code signing has hardly posed a problem for malware on either platform so far. It's big business. They buy EV certs from what I've seen and no one in the industry cares about anything but the money.
- shannah78 5y agoI considered that. The approach I'm taking was inspired by the way that Chrome creates app bundles for PWAs. > What happens when someone publishes some malware application using their wrapped and noterized installer The installer application simply installs the app. It doesn't in itself run any of the app's code. The installed app doesn't need to be codesigned and notarized like it would if you had just downloaded it from in your web browser. This works fine for many cases. A limitation is that apps built in this way can't be submitted to the app store. For that you would use jpackage or similar. But in most cases, this strategy is fine - and even better since it includes things like auto-updates.
- unclebucknasty 5y ago>The installer application simply installs the app. It doesn't in itself run any of the app's code. The installed app doesn't need to be codesigned and notarized Wait, then doesn't that mean Apple's intent there is broken? I mean if you can bypass its controls on installing unsigned apps by merely wrapping an unsigned (possibly malicious) app in a signed installer, then what's the point?
- absove 5y agoVery naive question but is it different from what npm, pip, etc. let you do already? Does the app installed this way get more permissions coming from a signed installer? I'm not familiar with OSX security model.
- shannah78 5y ago> Very naive question but is it different from what npm, pip, etc. let you do already? npm, pip, etc.. are CLI install tools. jDeploy supports CLI app distribution using npm also. But the key difference is that jDeploy provides double-clickable installers for the apps. If you're distributing a desktop app, it should be installable in the desktop (IMO). Making users go to the command-line to install the app is actually prohibitive for the average user. Even when your userbase is programmers, I find that making them go into the command-line loses them. > Does the app installed this way get more permissions coming from a signed installer? I'm not familiar with OSX security model. Since Catalina, you can't download and run a Mac app in any form unless it is signed and notarized. Using the signed and notarized installer allows you to get around this limitation.
- invalidname 5y agoIn addition Java is signed. So the app is running within a signed/trusted VM that has the right permissions. The OS includes guards in place (at least in Mac) so permissions should be granted if you do something outside of what you're supposed to do.