15 ms·
Can you trust that permission pop-up on macOS?
- sefrost 1y agoMy work Mac regularly pops up an alert box claiming that Slack is “trying to install a new helper tool”. I have no idea why or what it means. I asked IT how I could verify it was legit and they didn’t know. I often wonder if this could also be exploited because it asks for a password and it keeps popping back up every time I click cancel.
- nmgycombinator 1y agoI'm not aware of the "helper tool" popup, but I would definitely be skeptical of it. Even if it is Slack, Slack is just a messaging application. I don't know what legitimate need it would have for a helper tool. I would ask Slack support, though (and hopefully you can get a real answer and explanation).
- 1oooqooq 1y ago> Slack is just a messaging application its sold more as a way to store and all conversations than the ability to be a messaging application. the original pitch was to make all information, even private conversation of previous employees, searchable.
- nmgycombinator 1y agoDamn. That sounds pretty dystopian. But typical for American corporate life.
- frollogaston 1y agoI don't really expect my 1:1 conversations on the company chat to be invisible to the company.
- nmgycombinator 1y agoI don't either. But it's still a bit creepy regardless.
- trollbridge 1y agoIn environments like this, my trusted colleagues and I communicated using Signal (and before that, WhatsApp). One somewhat paranoid department that was convinced they were being spied on (they weren’t; I saw the Slack admin dashboard and management was too cheap to pay for the retention and spying features) maintained the use of an ancient Jabber based group chat for their own internal communications.
- 1oooqooq 1y agoif signal is on company hardware, they have crowdstrike for that.
- trollbridge 1y agoThis was around 8 years ago, but there was no MDM installed on our cell phones, regardless of if BYOB or company paid for device. The only restriction was if you went to China, you took a burner phone (one of the old company phones, usually) and weren’t supposed to ever use it again once you left. I think they just sold them to a liquidator.
- cyberax 1y agoWhy? Companies already have to retain the data (in case of lawsuits, etc.). Slack is also used because it allows to create persistent channels that are searchable. So they often end up being a knowledge base for the company.
- nmgycombinator 1y agoI guess that's a fair point. It cuts both ways, but given that so many people use Slack as opposed to talking, the exact words people used and when are could be open to view. Whereas, before all of this, you may only just have the minutes of any official meetings. Any side chatter not in the meeting room and/or exact phrasings would be lost to time.
- frollogaston 1y agoIt doesn't need special permissions on your Mac to do that.
- makeitdouble 1y ago> Slack is just a messaging application. I kinda like this angle. While Slack makes an effort to work basically everywhere with low effort, I wonder what would follow if it wasn't the case. For instance if for some stupid legal reason Slack was banned from macos, how many people would just switch to another OS ? I'd bet it would be a non trivial amount of users at this point.
- dylan604 1y agoor you know, just use the web app
- makeitdouble 1y agoIf it was a legal ban I'd assume Apple would go pretty far to make it happen, app or not.
- JadeNB 1y ago> I kinda like this angle. While Slack makes an effort to work basically everywhere with low effort, I wonder what would follow if it wasn't the case. This idea of respecting user preference is not the way, though. For example, back when Skype existed, you couldn't remove its icon from the macOS menu bar, because (1) Microsoft didn't believe you had the right to choose to remove that item, and (2) macOS believes an app developer should have more control over what goes in my menu bar than I do.
- dcrazy 1y agoThis dialog comes from the System Management framework [1]. Slack is probably installing a privileged helper tool (conceptually similar to a setuid root binary) so that it can update itself regardless of where it is installed or which user originally installed it. [1]: https://developer.apple.com/documentation/servicemanagement/smappservice?language=objc https://developer.apple.com/documentation/servicemanagement/...
- QuercusMax 1y agoSeems like it should only need to do this once. I get this with almost every Slack and VSCode update. The correct solution for me is to quit Slack.app and let my company's management software do the update for me.
- closeparen 1y agoMaybe it's smart enough to require re-authorization when the binary changes?
- ubercow13 1y agoWhy would the helper binary change that much? A setuid-ish binary should be ultra simple and not constantly changing I'd assume.
- QuercusMax 1y ago...and it should be able to replace itself.
- socalgal2 1y agoI don't use slack except in the browser. I never get a prompt for VSCode. It must be one of your extensions.
- QuercusMax 1y agoI've got them both installed through a corp-managed "software center". Don't have any exciting extensions that I've installed.
- 1shooner 1y agoI get this from every Electron-based app that I have run as multiple OS users.
- kccqzy 1y agoThat does sound like it could be exploited, but with only as much exploitability as some random app that requires your password (for analogy consider a Linux binary that refuses to run unless being run as root). Ultimately it's a matter of deciding whether you trust the developer of the app and whether you trust this app is really from that developer. The day Apple prevents users from giving root access to a third-app app is when the Mac fully becomes a walled garden, and you can expect pages of HN complaints. Overall I think it's good paranoia to not grant root permissions to apps that do not clearly need them such as Slack.
- aziaziazi 1y agoBeing paranoid, would it be possible that another app already installed (but not trusted enough to give privilege, let’s say a shady mouse driver or screenshot app) detect when slack (more trustfully) does launch to open a dialog at that precise time and deceive the user? Let’s say the shady app is named « SIack » or something close enough to be missed - but brand itself as innocents « screenshotPro4000 » in the app itself graphics so you’re not suspicious.
- nmgycombinator 1y ago> The day Apple prevents users from giving sudo access to a third-app app is when the Mac fully becomes a walled garden, and you can expect pages of HN complaints. I can see this happening, but it probably won't anytime soon. macOS is still open enough, and with the assumption that sometimes processes need root (see third-party Launch Daemons). It would probably break quite a lot. But I wouldn't be surprised if they eventually gradually move macOS in that direction.
- haiku2077 1y agoI get this popup all the time. It contains no information that I can reasonably use to match a decision on whether or not to allow it, so I always click cancel on it.
- jonplackett 1y agoThese types of ‘security’ blockers are so dumb because they train people to act dumb. Even if they’re real, the next time they may not be. It’s like how my bank often calls and wants me to give them my personal info for ‘data protection’ before we can speak. These are legit bank calls, training people to give out personal info to strangers.
- hbn 1y agoAs of the latest macOS update, every app is now asking every few days if it can have access to devices on your local network, or something to that tune. My theory right now is it's something in chromium that automatically asking for this and Electron apps will do this out of the box, but I can't remember which apps exactly have been doing this. Regardless, yes it causes the exact issue you're talking about. I don't even read what the popups say anymore, I'm just blindly hitting an accept button.
- jonplackett 1y agoI’m surprised Apple have let this happen. When you make an iOS app and requested permission for something - photo library or location etc. you MUST write out a sentence of what you’ll use it for which is shown to the user. Why not the same for Mac apps?
- reaperducer 1y agoWhy not the same for Mac apps? How would Apple enforce that? iOS apps go through the App Store, so proper behavior can be enforced. The apps people are complaining about here are downloaded from the vendor. Apple is not involved.
- Kwpolska 1y agoApple controls the OS and permission system. They could just automatically reject all permission requests with an empty/short reason.
- 1y ago
- jq-r 1y agoAnd it so annoying because it steals focus so as you're writting a message it suddenly stops taking your input and "helpfully" continues typing your text into the password box.
- floatrock 1y agoNot an os-x developer, but I've always wondered are there any OS guardrails against any (malicious) application showing a window styled the same way as that popup box and just stealing your password?
- nmgycombinator 1y agoI mean, I don't know how there would be? Unless they were scanning the text of every pop-up for words convincing the user to enter their computer password. There would be no way to determine intention without some sort of language analysis.
- rplnt 1y agoAnd they somehow stack in time. So after a weekend it's popping up over and over until I give up and quit Slack. It's been like this for a year I'd say. There's no way to stop them and they always get focus, which is extremely annoying. How can I revoke this permission from Slack? Seems pretty abusive.
- diebeforei485 1y agoI use Slack as a web app, but not in the browser: https://support.apple.com/en-us/104996 https://support.apple.com/en-us/104996 Discord can be installed this way as well. It's (imo) a better usage experience than their Electron apps. Nearly every Electron app is better this way.
- gorfian_robot 1y agosame but nordVPN
- nyarlathotep_ 1y agoVSCode does this too on work-issued Mac. I've been ignoring both for literally years.
- e40 1y ago> The patch is released I assume that is with 15.5...
- nmgycombinator 1y ago> which was patched in today's releases of macOS Sequoia 15.5 et al. Correct.
- nmgycombinator 1y agoCorrection (longer explanation elsewhere): only 15.5. Apple didn't patch it in the other two releases.
- commandersaki 1y agoLove this guy's research, such good presentation!
- nmgycombinator 1y agoThank you very much! Although I'm not a guy, just fyi! I'm just a person :)
- JohnFen 1y agoHonestly, I don't really trust any permissions popups on anything anymore. They are often porous enough to count as "security theater".
- nmgycombinator 1y agoI honestly think this is a good skepticism to have. I generally don't hit "Accept" (or "Allow" or whatever) on any permission pop-up unless I know exactly what it's doing and what I need it for.
- coolcase 1y agoAnd at $Corp I get constant popups to enter my password or confirm an action. Like 50-100 a day.
- nmgycombinator 1y agoI bet threat actors are just salivating at the thought of giving you a fake password prompt.
- coolcase 1y agoYeah. I am very hygienic at work in terms of what sites I visit but you can never be too careful. To me the main threat vector is my dev curiosity!
- nmgycombinator 1y agoLol, I know that curiosity feeling.
- silvestrov 1y agoIt took Apple a full year to release the fix. That is a very long time. 2024-05-04 I leave several additional update messages as I continue testing my PoC 2025-05-12 The patch is released
- nmgycombinator 1y agoYeah. I'm guessing there must be some legitimate (internal?) use cases for the behavior I found and they spent all that time working out the kinks to allow those edge cases while also not allowing malicious ones. Or perhaps it wasn't as high on their priority list as it required a higher level of user interaction (the user had to click "Allow"). In any case, though, I do believe that a year is a shockingly long time for them to take.
- zoomTo125 1y agoAlmost a year to release a patch. If Apple takes that long, there is no hope for other vendors.
- nmgycombinator 1y agoThis is Apple-specific, though. So there aren't really any other vendors that are relevant to this specific scenario. I will say, they have been quicker with my other reports; taking just a few months as opposed to a full year.
- kllrnohj 1y agoWhy is there no hope for other vendors?
- EGreg 1y agoI once sent an email to Steve Jobs back in 2009 or so I told him that the MacOS permissions dialog could easily be spoofed, and that Macs should have a secret phrase or icon that you choose that they’d display inside these dialogs, and prevent their screen capture like what they had been doing with their recent DRM features. Never heard back from him And it never got implemented. Any program can still continue to spoof it and grab your system password.
- nmgycombinator 1y agoI mean, at that point and app could just put up a fake prompt using the UI framework. And I think users would be more hesitant to type a full password than just click a button. But if you're talking about a bug similar to mine where an attacker could use the OS's own code against it and make it show a prompt with misleading content, you might be able to report it to Apple Product Security and maybe get a bounty.
- trollbridge 1y agoI mean, a website could display a crafty popup-appearing box and try to get you to type in your username and password. Not really sure how you can prevent that. Vista used the “the background dims quite a bit” to try to deal with that.
- nmgycombinator 1y agoYeah. I think the key thing in my vulnerability is that it abused a legitimate OS prompt and had the consequences of that prompt be applied to something separate from what the prompt text itself said it would.
- EGreg 1y agoI just told you how… it would show your special icon or phrase inside so you’d confirm it before you typed anything. The phrase would be managed through a system screen, like a login screen
- muppetman 1y agoI remember the I'm a Mac and I'm a PC ads that mocked this on Vista. And now my Mac is worse than Vista. It's so annoying.
- nmgycombinator 1y agoOut of curiosity, what do you find annoying about it?
- muppetman 1y agoEvery time I update an app I have to be told I downloaded it from the Internet and do I trust it. Can this app look on the local network? Constantly being nagged to the point I don't even check/care anymore. Exactly what Vista used to do.
- nmgycombinator 1y agoThe local network popup thing is too overdone in my opinion. However, I do think it is a good choice (in some respects) for Apple to have the "this is a program downloaded from the Internet", even if it can be annoying. It might also be a push to get developers to publish on the App Store (where Apple can be more sure (hopefully) that the apps are safe). It's a double-edged sword in my opinion. I think it's good that the OS is looking out for the user in a lot of cases. I also understand how it can give the users pop-up fatigue.
- bigyabai 1y ago> It might also be a push to get developers to publish on the App Store (where Apple can be more sure (hopefully) that the apps are safe). This is exploitation of developers, plain and simple. Apple should secure their runtime, not roleplay as a software rent-a-cop that manually (and fallibly) inspects submissions. The App Store is a blatant moneymaking racket, on mobile and desktop alike. "Security" is a fig leaf for the perverse incentive Apple has to corral developers under their thumb.
- yieldcrv 1y ago> Apple confirms that I will be credited congratulations on the credit and they also paid you $1,000,000 or whatever their top bug bounty payout is right?
- nmgycombinator 1y agoNo word from them on the payout, yet. They only start deciding on if and how much to pay after the patch. I know for a fact it doesn't fall under the $1,000,000 reward tier as that is for their Private Cloud Compute platform. But it may fall under some of their other categories.
- cypherpunks01 1y agoJust recently learned I should be installing mac apps into my home directory Applications, not the system Applications (as every single app installer suggests). Of course, only makes sense for a single-user machine. If I downgrade myself to a non-admin user, and install apps into my home Applications, then I'm not bothered by permissions requests from apps to update themselves. Almost all of them can just do it, on their own, with non-admin permissions. The only exceptions I've found are Tailscale and other stuff that needs higher level OS integration. Edit since upvotes: Non-admin user operation was recommended by the Pareto Security app, see info on this specific item: https://paretosecurity.com/mac/checks/not-using-admin https://paretosecurity.com/mac/checks/not-using-admin All Pareto security checks: https://paretosecurity.com/mac/checks https://paretosecurity.com/mac/checks App: https://paretosecurity.com/mac https://paretosecurity.com/mac and https://github.com/paretoSecurity/pareto-mac https://github.com/paretoSecurity/pareto-mac
- Etheryte 1y agoUnfortunately many (most?) application developers don't know this either, and many of them go so far as to explicitly require their apps to be installed in /Applications, they simply won't work otherwise.
- xp84 1y agoNo comment on the overall topic, but I have long made a practice of installing into $HOME/Applications instead[1], and it's rare for me to encounter software that cares. A few apps have added popups to explain to beginners "Hey, you're running me from the Downloads folder, uhh, want me to properly move myself to /Applications/?" but that's about it. The only apps I run from /Applications that aren't part of the OS are the ones that still use "Installers" like Adobe apps, because I assume they spew crap all over anyway. I haven't tried moving those, but I wouldn't be surprised if they deeply cared. [1] The idea being that I could then migrate more easily by copying the whole home directory, and thus all my apps that didn't require "installation" would come over.
- nmgycombinator 1y ago
- pier25 1y agoAdobe Creative Cloud will keep multiple processes running in the background even when you explicitly configure it to not do that in the OS settings.
- MiddleEndian 1y agoCreative Cloud is malware IMO.
- xp84 1y agoOn the off-chance someone at Apple reads this, I'll repeat my perennial beg that Apple stops popping up 'Give me your (local admin) password right now' dialogs randomly throughout the day because the computer has a hankering to install updates or something. Anyone with basic skills can whip up a convincing replica of that popup on the Web, and the "bottom 80%" (at least) of users in technical savvy would not think to try dragging it out of the browser viewport or switching tabs to see if it is fake or real. The only protection against this kind of stuff is to NOT teach users that legitimate software pops up random "enter your password" dialogs in front of your work without any prompting. That's what these dialogs are doing. Display a colorful flashing icon in the menu bar. Use an interstitial secure screen like Windows does. Whatever. But the modern macOS 'security' UI is wildly bad.
- ssd646 1y agoWhen logging into iCloud, they show a pop-up asking for the local password to the computer. And then they upload that password to the iCloud servers.
- DowsingSpoon 1y agoPlease provide evidence for a claim that logging into iCloud necessarily sends your plaintext local password to the server.
- ssd646 1y agoI never said it sends your plaintext password. It says it 'encrypts' your password, because it needs to access your Keychain. The dialog says this, but there is no way to opt out. You are 100% wrong. EDIT: https://apple.stackexchange.com/questions/467137/are-keychain-passwords-stored-in-icloud-by-default https://apple.stackexchange.com/questions/467137/are-keychai...
- nmgycombinator 1y agoAs someone who dove deep into keychain items for a previous write-up, I believe you are misunderstanding this situation. As far as I understand it, many keychain items can be stored in your iCloud keychain. However, your local machine can have its own keychain that's different than the iCloud keychain, with items that are not sent to iCloud. And besides all that, to my knowledge your local machine password (the password you use to login) isn't stored in a keychain item, so there's no way it could make itself into the iCloud keychain, or your local keychain. You may be mistaking some explanations. Your computer password is used to unlock your local keychain, but it itself is not stored in your keychain. Your local keychain is also not your iCloud keychain, it's not stored in iCloud. Again, I'm not an Apple developer, so there may be stuff I don't know, but I am a developer in general and I have researched this. The above is my current understanding.
- pkkkzip 1y agoman, i think this really is the last time im buying Apple products, the string of CVEs, the many issues with hardware, iPhone as well....im over the hype and switching to Android and Windows I miss being able to play games. I miss having a phone without lock-ins and security vulnerabilities that do not get patched.
- muppetman 1y agoOh you're going to _hate_ Windows - I say this as someone who switched in the last 2 years. MacOS can be very annoying, Windows is just one big advertisement these days in a badly skinned window manager.
- trealira 1y agoYeah, I basically keep Windows just for Word and Excel and Windows-exclusive video games, and use Linux most of the time because of this. There's no perfect system out there.
- seeknotfind 1y agoTrust nothing.
- lapcat 1y agoFrom the beginning, TCC has been a house of cards. It only impedes legitimate developers and tortures users with permission prompts that Apple ridiculed back in the day, while malicious apps can easily bypass the "security" (theater) in countless ways that researchers continue to uncover and report. I'm not a professional security researcher, just a Mac developer, but I've discovered a number of bypasses myself. It's almost as if Apple engineers don't even understand the technology they're using. And maybe they don't! How many remain from the pre-iPhone era?
- mrtesthah 1y agoThe continuous incorporation of basic system features into TCC has drastically increased the friction of deploying enterprise management software on Macs (especially for education), to the point where I would question the overall value proposition. I say this as a dedicated macOS (Cocoa) developer since 2003.
- Jerry2 1y agoAuthor didn't disclose if got a reward for his work. Hope he did!
- nmgycombinator 1y agoThank you for your kind words. To respond: 1. I'm not a "he", I would prefer "they". 2. As I mentioned in another comment, I have not received word back yet on any reward.
- sexy_seedbox 1y agoMaybe they'll put you into their "Hall of Fame"
- nmgycombinator 1y agoI think their "Hall of Fame" (or at least whatever people colloquially refer to as that) is their credits for people who found bugs in their web servers, so I don't think that counts here. I did get credited, so I'm happy about that. Now I just have to wait and see if they determine it's worth a reward (and, if so, how much).
- amazingman 1y agoIt is absolutely worthy of a reward, and it should be worth a few months of your time. This is a nasty security issue, and you showed a ton of restraint not losing patience with Apple. Honestly, it's bullshit that you don't already know whether or not you're going to get a bounty.
- nmgycombinator 1y agoI will definitely admit, it can be a bit of a pain point that Apple sometimes takes a lot of time to determine a bounty. I'm just waiting patiently now to see what they say. I appreciate your kind words and encouragement.
- nmgycombinator 1y agoAn important correction, so hopefully this bubbles to the top (this will be appearing on the post as well): A previous version of this article mentioned below that this CVE was patched in macOS Sequoia 15.5 et al., but I was a bit mistaken in that. Despite being released today as well, it appears that macOS Ventura 13.7.6 and macOS Sonoma 14.7.6 are not patched against this vulnerability. I wrote that sentence assuming that Apple would have included a patch in all of the releases. It was only later, when I checked the security release notes, that I saw I was not credited under the other two releases. I reached out to Apple to clarify if these releases were patched. As of writing, I have not heard back. I chose to do my own testing and spun up a virtual machine. After some difficulties I got it updated to macOS Sonoma 14.7.6 and was able to compile and run my proof of concept. It still worked. I would assume the same is true for macOS Ventura 13.7.6. I'm not sure why Apple didn't include the patch in these two releases. I will update the post when I have more information and/or context.
- nmgycombinator 1y agoEdit made: Ventura and Sonoma will remain vulnerable. Apple made the decision to only patch this in Sequoia.
- gitroom 1y agotbh i just don't trust any of these permission dialogs at this point - makes me wonder if good security even starts with the ui or it's all just kinda broken underneath?
- Alex_001 1y ago[dead]
- nmgycombinator 1y agoI mean, as others have mentioned, actually true capabilities would be nice. But as long as we're going to have a database, it would have to end up in user space or in the kernel. And I'm not sure how much I like either option.
- nottorp 1y agoWell, today Mac OS told me Chrome wants to access bluetooth, which of course I denied. So I guess sometimes the permission system works.
- kristel100 1y agoAt this point, “permission fatigue” is real. You almost get trained to click ‘Allow’ just to get work done—which defeats the whole point. Would love a tiered trust model, not binary prompts.
- freddie_mercury 1y ago> You almost get trained to click ‘Allow’ just to get work done I had an interesting experience of this with a normal/non-technical user when my wife asked for help setting up some money remittance app. Early in the install it popped up some dialog, something about whether you wanted to transfer money via credit card or...except she clicked the "OK" button before I could read more than that. As in, she clicked it literally as fast as she could process there was a pop-up and move her finger there. I asked her why she clicked the pop-up away without reading it, it might have been important...and she literally began to argue with me that there hadn't been a pop-up and what was I talking about. Just like how our brain has learned to edit out blinking, it seems like (at least in some circumstances) her brain has learned to edit out pop-ups and essentially muscle memory is clicking "Okay" as fast as possible to get back to whatever she was doing.
- deleted 1y ago[deleted]
- geekraver 1y agoThis is one of those places where having a selected “security image” makes sense. That popup should not just be easily spoofed text.
- nmgycombinator 1y agoI agree with you. However, in this case, I was abusing a legitimate OS prompt (not just making my own), so I don't know if a security image would be a barrier there. It would definitely be one for instances where malicious apps make their own pop-ups.
- Lucyj001 1y ago[dead]
- Juliusthomas 1y ago[dead]
- Juliusthomas 1y ago[dead]
- Theodoremelissa 1y ago[dead]