Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nmgycombinator
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
nmgycombinator
1y ago
That's an interesting idea. I do think it would be nice to have some way of knowing "is this prompt coming from the operating system or some third-party app?". However, I don't think it would have helped in the case of m
32.
▲
by
nmgycombinator
1y ago
Yeah. I think the key thing in my vulnerability is that it abused a legitimate OS prompt and had the consequences of that prompt be applied to something separate from what the prompt text itself said it would.
33.
▲
by
nmgycombinator
1y ago
No word from them on the payout, yet. They only start deciding on if and how much to pay after the patch. I know for a fact it doesn't fall under the $1,000,000 reward tier as that is for their Private Cloud Compute platform. But it ma
34.
▲
by
nmgycombinator
1y ago
Honestly, I think you have a fair point there. I personally don't believe that any system could be 100% secure. But I do think there is a point to be made on the efficacy of securing the runtime compared to individual app inspection.
35.
▲
by
nmgycombinator
1y ago
I agree that it's weird that Apple TV comes pre-installed. The others I have less experience with so I can't really comment on them.
36.
▲
by
nmgycombinator
1y ago
The local network popup thing is too overdone in my opinion. However, I do think it is a good choice (in some respects) for Apple to have the "this is a program downloaded from the Internet", even if it can be annoying. It might a
37.
▲
by
nmgycombinator
1y ago
Out of curiosity, what do you find annoying about it?
38.
▲
by
nmgycombinator
1y ago
I bet threat actors are just salivating at the thought of giving you a fake password prompt.
39.
▲
by
nmgycombinator
1y ago
> The day Apple prevents users from giving sudo access to a third-app app is when the Mac fully becomes a walled garden, and you can expect pages of HN complaints. I can see this happening, but it probably won't anytime soon. macOS
40.
▲
by
nmgycombinator
1y ago
I guess that's a fair point. It cuts both ways, but given that so many people use Slack as opposed to talking, the exact words people used and when are could be open to view. Whereas, before all of this, you may only just have the minu
41.
▲
by
nmgycombinator
1y ago
Yeah. I'm guessing there must be some legitimate (internal?) use cases for the behavior I found and they spent all that time working out the kinks to allow those edge cases while also not allowing malicious ones. Or perhaps it wasn
42.
▲
by
nmgycombinator
1y ago
I mean, at that point and app could just put up a fake prompt using the UI framework. And I think users would be more hesitant to type a full password than just click a button. But if you're talking about a bug similar to mine where an
43.
▲
by
nmgycombinator
1y ago
This is Apple-specific, though. So there aren't really any other vendors that are relevant to this specific scenario. I will say, they have been quicker with my other reports; taking just a few months as opposed to a full year.
44.
▲
by
nmgycombinator
1y ago
I honestly think this is a good skepticism to have. I generally don't hit "Accept" (or "Allow" or whatever) on any permission pop-up unless I know exactly what it's doing and what I need it for.
45.
▲
by
nmgycombinator
1y ago
Thank you very much! Although I'm not a guy, just fyi! I'm just a person :)
46.
▲
by
nmgycombinator
1y ago
I don't either. But it's still a bit creepy regardless.
47.
▲
by
nmgycombinator
1y ago
> which was patched in today's releases of macOS Sequoia 15.5 et al. Correct.
48.
▲
by
nmgycombinator
1y ago
Damn. As someone who has dabbled in OS history research Usenix's archives were a God-send. I hope they continue to maintain them, and that other groups can take up the mantle of hosting cutting-edge computer science research (at least
49.
▲
by
nmgycombinator
1y ago
Damn. That sounds pretty dystopian. But typical for American corporate life.
50.
▲
by
nmgycombinator
1y ago
A software updater was going to be my best guess at what this was. I guess I understand the flexibility it brings, but it definitely does have some security trade-offs.
51.
▲
by
nmgycombinator
1y ago
I'm not aware of the "helper tool" popup, but I would definitely be skeptical of it. Even if it is Slack, Slack is just a messaging application. I don't know what legitimate need it would have for a helper tool. I would
52.
▲
Can you trust that permission pop-up on macOS?
(wts.dev)
377 points
by
nmgycombinator
1y ago
|
251 comments
53.
▲
by
nmgycombinator
2y ago
Fascinating perspective. I understand your point, and agree with it generally. I will point out though that this doesn't really have anything to do with Continuity or any "feature" per-se. It doesn't really have anything
54.
▲
by
nmgycombinator
2y ago
I've seen Apple do this with Chrome tabs for some reason. It's weird.
55.
▲
CVE-2025-24259: Leaking Bookmarks on macOS
(wts.dev)
17 points
by
nmgycombinator
2y ago
|
4 comments
56.
▲
by
nmgycombinator
2y ago
Thanks for the feedback! I was burying the lede a bit on purpose to entice the reader to read more, but I also completely understand your perspective as well.
57.
▲
by
nmgycombinator
2y ago
> A capability-based design should be able to systematically prevent this kind of problems. I think Entitlements could be considered a type of capability? And if so, then you're right on your this point, as the solution was to requi
58.
▲
by
nmgycombinator
2y ago
Yeah I got confused there for a second based on your original message, but I'm glad to know my understanding initially was correct.
59.
▲
by
nmgycombinator
2y ago
Oh nice! Do you have a GitHub or something for the kernel?
60.
▲
by
nmgycombinator
2y ago
Well, it took 8 hours, but this post is now no longer top 5 on the front page (it's #27 now for me, so still front page, just the bottom). Thank you everyone for your comments!
More ›