3 ms·
> In reality it costs the bad guys $299 to bypass this limitation They also had to get verified as a mid-sized or greater corporation (Apple does use real veri
by bfgoodrich 4y ago
> In reality it costs the bad guys $299 to bypass this limitation
They also had to get verified as a mid-sized or greater corporation (Apple does use real verification partners), and further Apple can pull the rug on the certificate in an instant, immediately invaliding that $299 certificate and the considerable effort that went into getting it.
In reality this group likely had to hack an existing Apple Enterprise approved business first, then using that to springboard to the next step.
Casually dismissing that enormous gate is pretty tenuous.
- mike_d 4y agoI don't have any inside details on this case, but I highly suspect the signing certificate was stolen from a legitimate user. Organizations sophisticated enough to build something like this already target organizations like device manufactures to get kernel driver signing certificates on Windows.