Is macOS’s new XProtect behavioural security preparing to go live?
eclecticlight.co
eclecticlight.co
Windows Defender (or whatever it’s called) looked like it might help similarly on Windows, but I haven’t seen it being used that way. It looks to me like the third parties keep looking for new features they can advertise, knowing that corporate InfoSec will mandate support for them quickly, and that an OS-provided solution isn’t sold in the same way, so will be deemed unsuitable.
Anyone feel more optimistic?
Good call. There has been too many awful products in that space.
Scenario 2: corp keeps third party software, which bangs its head against Apple's protection which prevents such god processes to access information, thus corp disables Apple's protection and keeps using third party software.
(Compare/contrast: Hypervisor.framework)
E.g. https://www.bloomberg.com/news/features/2023-05-11/the-plot-...
We used to write image processing pipelines.
This is code that really needs to run fast.
We spent a huge amount of time tuning, analyzing, and re-tuning the software.
Our IT group was completely focused on office workers, and would force us to install their spyware on our test machines.
It was not a good fit.
It is more and more, but you need the expensive Microsoft 365 license to use the web portal for it for, key word, MANAGEMENT.
You want to be able to scan computers, lock them out of all network access besides the AV management, block usb/peripherals etc etc when an attack happens.
You DONT want to just let it run headless.
XProCheck, which allows for easier viewing of XProtect log details: https://eclecticlight.co/consolation-t2m2-and-log-utilities/
As well as SilentKnight + LockRattler for checking the status of XProtect updates and other security configuration: https://eclecticlight.co/lockrattler-systhist/
But since iOS they've been slowly pushing this model to Mac. It pushed me away from the Mac platform, I only use it for work now.
https://objective-see.org/products/ransomwhere.html
For a deep dive into this line of thinking, his post:
Towards Generic Ransomware Detection (04/20/2016) — https://objective-see.org/blog/blog_0x0F.html
Malwarebytes purchased an activity detecting product and claimed to offer this type of protection, though that marketing has become more generic now:
https://www.malwarebytes.com/cybersecurity/business/what-is-...
Given AV firms change hands and veer into dark patterns, forum posts like this one shouldn't recommend anything in particular as the ownership and policies can change overnight.
The development process could have been much worse, but some aspects of swift development in XCode were frustratingly rough with a range of extremely well document to barely documented APIs.
Can I do X with SwiftUI? Who knows. Does it support Y pattern well? Absolutely, and here are a dozen examples. Such a pain in the ass.
I also have no idea when my app will be approved. It just generates air quality forecasts from multiple sources, provides alerts, shows active wildfire perimeters, and doesn’t allow any access to anything else. Just uses location, optionally. It’s been weeks now.
Overall I’d rather not develop for apple’s devices again, but mostly because so little is in my control. The rest was fine. I strongly dislike having so little agency around being accepted into the platform and then publishing on it. Not having a say over my tool chain is also pretty frustrating when theirs is so buggy, slow, and unintuitive.
Exactly this. Don't even get me started if you are writing a Mac Catalyst app too.
Can I use this NSEvent? No? I gotta create a bundle that's built for OSX and then load that dynamically and pass stuff as AnyObject from my AppDelegate.
Oh I'm getting .rotation and .magnify events. Is there any API I can call to ask the OS the positions of the fingers on the trackpad? No? I need to go through the GestureRecogizer? But that is returning 0 touches for a .magnify event.
All I wanted was to get the current location of the fingers so that I can decide on which axis to zoom more on. Oh there is a plist for Application Supports Indirect Events. Downstream effects not documented, well, that's how it is developing for an Apple platform.
I don't understand why Apple has decided this is okay, or why they don't direct more resources and attention to ensuring this sort of thing doesn't become reality.
I’d be fine with their process if there was an alternative way to get my app into my customers hands. But there isn’t, and they’re vehemently against it.
When Apple launched unlisted apps I was really excited. But these apps inexplicably seem to go through the same review process. If it’s unlisted, why do they care about anything other than security?
Apple truly makes life painful for developers. Can’t wait for alternative app stores.
SwiftUI is still very green, especially on Mac where it hasn't gotten as much attention as it has on iOS. There are some things I'm starting to use it for over UIKit on iOS, but on macOS I wouldn't bother — AppKit might be a little rough around the edges compared to UIKit, mainly due to its age, but it's a great deal more suitable for production work on macOS than SwiftUI is.
Thanks for that, though. I’ll likely give that a shot soon, because my current client loves the idea of MacOS apps. I like the idea of common code to rub on multiple platforms, but it seems like it’s too green.
It's somewhat true on mobile, too, though to a lesser extent because mobile UI widgets don't need to be as functional, which makes it easier for new things to compete — for instance a table view with sortable, rearrangable columns and column headers is practically unheard of on mobile whereas it's a cornerstone widget on desktop. For user-facing platforms the web is the odd exception where it's somewhat the norm to jump for the latest trendy shiny thing on new projects.
And on the other end, window's UX is going down the drain year over year.
It's designed so regular users don't / can't bother to do so, tho
It's certainly either something I'm doing wrong, or a big in the software I'm using to automate signing, notification and stapling.
Here's the issue I opened on the software I'm using to automate: https://github.com/electron-userland/electron-builder/issues... that issue kinks to the PR that adds the automation.
It's a non-trivial thing to test, since it involves so many secrets and the notarization step can take over an hour, so I don't expect anyone here to actually want to look into it.
My original comment really was just venting my frustration, not a cry for help (but I might be crying soon if I cant get to the bottom of this!).
Conveyor can package Electron apps and also do all the Mac specific stuff from any platform including Linux. So it can sign, notarize and staple the app itself, also bundling Sparkle updates as it goes. We're listed on the Electron website these days. You may have more luck with it. There's a Discord channel for help too if you get stuck.
[1] https://hydraulic.dev/ (disclosure: my company)
/Applications/Ganache.app: rejected (invalid destination for symbolic link in bundle) origin=Developer ID Application: ConsenSys AG (48XVW22RCG)
I see you're also migrating to Github Actions for this particular release and that the notarization process was working correctly on your previous CI/CD? I guess there has to be an issue with the new environment here or the way you're building it now.
I've manually tested on Monterey.
I’d recommend you check out Apparency [1], which can inspect .app bundles and show you what’s up with the signing on your bundle. It looks like you include a few frameworks (which also need to be signed), so maybe you have components missing signatures/with mismatched signatures.
Preventing an app from accessing browser data feels like an approach to make people feel safe while providing no meaningful protections from most malware behavior.
Depends on the threat model. Yes, protecting browser data does not help if the attacker gained entry into the system by exploiting a vulnerability in the browser. But it helps against all other entry points: USB sticks laced with malware (common threat against companies), malware that came as part of an email attachment or by dodgy warez, an attacker that's already in the network (either because they're laterally moving or because the victim is in a scenario like a public wifi) and exploits some vulnerability in network-enabled software...
Classic defense in depth here, it massively raises the bar for attackers because to steal Chrome user sessions or passwords, you now need a code execution avenue but also a kernel-level or at least sandbox exploit to bypass Bastion.
Sure, but this is a very arbitrary threat model to prioritize that doesn't seem to affect people. What about ads? Tracking? Apps sending fingerprinting home? That seems like a more obvious place to start.
Credential stealer malware is abundant, it's often enough how attackers gain initial access to a company's internal network - grab the credentials off of Chrome, Firefox or one of the other popular password manager apps, and you're bound to find a set of credentials there. Now all you need is some piece of software that's reachable from the Internet and lacks 2FA (which applies to a shocking lot of legacy software), and you got some sort of persistent access to the network.
And in ye early days of cryptocurrencies, before hardware vaults became the norm among crypto enthusiasts, a fair amount of people got their wallets drained by targeted cookie (=session) stealers.
> What about ads? Tracking? Apps sending fingerprinting home?
That is bad, but not "someone can drain your bank account or take over your social media accounts to spam" bad.
Malware exfiltrating users' browser sessions and passwords is a "very arbitrary threat model" that "doesn't seem to affect people"???
This tells me that either people rarely need to do this, or that it’s very hard to do in userland.
Or you can just develop for vulnerable-as-all-getout Linux or Windows systems. Your choice.
But thanks for reminding me I have a choice, which I actually do not.
- I can't prevent the police from pegasusing my device.
- I haven't have anyone infected by a malware in years, no matter the brand of device.
- Most thief won't be able to do anything with any of my devices, no matter the brand. They are not very smart, and can't deal with a bios password, an encrypted disk or even simply a locked smartphones. They steal it anyway, and throw it away when it fails.
But in the end, I don't optimize my life for the rare occasion of being stolen.
I optimize it for my day to day problems, like being able to use my machine to do what I want to do every day, without having to hope I'm allowed to do it by corporations.
I'm much more worried about the state of society that losing a phone once to a thief.
"resistant" is a pretty low bar to pass. Do we get to include the Nintendo Switch for having eFuses?
macOS @ M1 boot process looks similar to that of iOS devices: https://support.apple.com/en-gb/guide/security/secac71d5623/...
Under the assumption that SIP is not disabled, and computer doesn't have any 3rd party kernel extensions installed (both of which are safe to assume for most people), it's close to impossible to inject something in the boot chain.
---
I think the best possible option might be to replace the keyboard with the one with a hardware keylogger, and record the actual password.
The threat model the general populace faces ranges from something as mundane as your ex wanting to extract something from your device to basically being the know-all key to every important document, photo and data you might have. I think I can safely say that under this circumstances not even physical access poses a real threat to the device's security -- it is tamper-proof to replacing most critical parts and the boot-sequence is cryptographically secured. Biometric data is not stored in software, so not even that can be spoofed.
If you exclude themselves from the threat model of course, which I don't see why you would
If you don’t understand why this isn’t true, I would respectfully start reading about what the platform does. It’s not like it was around the turn of the century where PCs and Macs were roughly equivalent.
Sure you can find some problems that have been solved but for each of those, there's a brand new problem created and not necessarily any better than the previous one.