That's unbelievably stupid dev behavior, if true.
That's unbelievably stupid dev behavior, if true.
Developers as a group are at least as stupid about security as everyone else.
Is the "right-click and open" trick that disables Gatekeeper for that app generally unknown? Or do people value not being assed to do it more than (potential) security upsides?
Is it possible that the malware version of Xcode had its signature removed?
Don't open it if the signature is invalid.
This is generally known as hubris. We think we're smart and that the rules don't apply to us, because we know better than the other people. Turns out they can protect us too. Who knew?
In this instance, I'd give the Chinese developers the benefit of the doubt, having recently had first hand experience myself of just how obstructive and irritating the great firewall can be (I was struggling to download small files my entire visit, like a 10MB pdf; I can't imagine trying to download a multi-gigabyte file). So perhaps this was the only way they could get work done–in which case it's on Apple to improve their CDN within China.
More broadly, it seems like though there's a careful line to be walked between locking down a computer (e.g. gatekeeper, system integrity protection) and keeping it 'open', I'm personally much more in favour of the former by default provided that the end user can disable it if necessary. It seems like the only realistic option going forward. Perhaps Xcode should be included under the SIP umbrella too?
:-(
I'm not quite sure why it's up to anyone outside of China, Apple included, to bear the cost of China's firewall dickery.
This is on China to turn off their firewall or bear the costs, commercial and otherwise, of this stupidity. Perhaps Chinese developers shouldn't be allowed to submit apps to the non-Chinese app store?
Not necessarily - they might have disabled GateKeeper a long time ago and never re-enabled it. I have the same complain with Android's "allow software from third parties" checkbox - it's a little useless because you uncheck it for one specific app you downloaded, but probably leave it unchecked forever more.
Downloading Xcode from a third party, now that's stupid.
EDIT: I should mention that I work as an iOS engineer. Gatekeeper has not once impeded my work.
Without those local caches the xcode download can sometimes take days or never finish at all.
Downloading from a 3rd party is fine IMO (after all the internet is just a big game of whisper-down-the-lane), but verifying checksums and signatures is incredibly important.
$ spctl --assess --verbose /Applications/Sublime\ Text.app
/Applications/Sublime Text.app: accepted
source=Developer ID
Or have you downloaded a special version from a Chinese file sharing website? :)No.
Every unsigned app you download needs to be whitelisted. Right click the app, click open. It will remember your choice and whitelist the app forever more.
Solving the unsigned app problem by silently ignoring clearly invalid signatures is like solving an ant problem by burning down your house.
(but I also don't download Xcode from random places)
I suppose you can argue that, if that's the case, what's the point? Well, if you think that a piece of software should be signed but it is in fact not signed properly, then that's a clue that it's been tampered with. If the software isn't signed at all, then at least I can decide whether I trust the source enough to install it.
Baidu isn't a very effective search engine and there are tons of people trying to get their mitts on user data including the government themselves.
That said, I have no idea why anybody would download XCode from a third party...
Easily explainable really. Went to [their favorite search engine], searched for "Xcode download" and clicked the first result which may not be from Apple (or an advertising).
If it were just unsigned apps I wouldn't mind so much, but it's the stupid, "This application came from the internet..." dialog box that drives me nuts most of the time.
Well it would have stopped this actual piece of malware! How often are you installing unsigned applications that a single right click to add to a whitelist is too much effort?
And I'm not infected by this piece of malware, so I still trust myself over Gatekeeper.
> How often are you installing unsigned applications that a single right click to add to a whitelist is too much effort?
Far more often than I install things from the app store. I don't find it to be a useful feature, so I disable it.
That's idiotic.