The Mystery of the Phantom App Updates
lapcatsoftware.com
lapcatsoftware.com
So , somebody knows the reason of the phantom updates?
I can't figure out another reason myself… I know it is never a compiler bug, but it could be something less serious.
Hmm. What is the point of notBefore/notAfter constraints if they don't do anything?
To know whether the signature is made within the validity window (or at least, not backdated), a countersignature from a timestamping service is added. If the countersignature or the flag in the cert is missing, an expiring cert will prevent the application from starting (Mumble had that problem), but if both are present, the signature is valid forever.
No idea if OSX handles it the same way, but it would make sense if they did.
Its curious that both of us worked on the apps receiving the phantom update
That said, you could probably get an answer at WWDC, if you find one of the code signing guys at the lab and corner them.
> It turns out that AirPort Utility is code signed with the exact same certificate chain as the old version of Airfoil Satellite. So if there is a problem with the old signing certs, whether expiration or something else, the problem still exists with AirPort Utility. Presumably this fact would also rule out the (highly unlikely) possibility of private key compromise.
If an Apple key was compromised, why would they go through the effort of resigning old third party apps but not one of their own?