Links...
 
Tighten Pro
C/C++/Cocoa tool for codesign security, Developer ID, & Mac App Store Receipt Validation

Tighten Pro - in the Mac App Store

Tighten Pro is now available in the Mac App Store. Simply click on the icon to the left to purchase directly from Apple. Or choose PKCS#7Viewer.app by clicking the image to the right.

1.06.2016
Mac Developer: Android N switches to OpenJDK, Google tells Oracle it is protected by the GPL | Ars Technica

Android N switches to OpenJDK, Google tells Oracle it is protected by the GPL | Ars Technica Google told VentureBeat that it in "Android N," the next major version of Android, it is swapping Android's Java libraries from its own Apache Harmony-based implementation to one based on Oracle's OpenJDK—yes that Oracle, the same company suing Google.
Not sure what Oracle is upset about since Android is a major boon to the Java ecosystem. Under the Kleenex marketing principle they're crazy to upset the balance. What would be bad for Oracle is for Android to move to some other technology base. Like C# and the managed runtime, for example.

This is a sad legacy for SUN because Scott McNealy stood on his soapbox for years criticizing closed systems in favor of the open system model that SUN was all about.

Labels:

By : Tighten Android N switches to OpenJDK, Google tells Oracle it is protected by the GPL | Ars Technica 0 comments

4.02.2015
Mac Developer: A Look Inside the Ask Toolbar Installed with Java for Mac | The Mac Security Blog

A Look Inside the Ask Toolbar Installed with Java for Mac | The Mac Security Blog: "Java and Ask Toolbar Installation Process At the beginning of the installation process, the Java installer creates a temporary helper, com.oracle.JavaInstallHelper, in /Library/PrivilegedHelperTools/"
The battle for your desktop from a language technology nobody wants on the desktop (except Android devs).

Labels: , , ,

By : Tighten A Look Inside the Ask Toolbar Installed with Java for Mac | The Mac Security Blog 0 comments

7.29.2014
Mac Developer: BBC News - Android Fake ID bug exposes smartphones and tablets

BBC News - Android Fake ID bug exposes smartphones and tablets
BlueBox Labs said it was particularly concerning as phone and tablet owners did not need to grant the malware special permissions for it to act.


If this is true, then essentially Android devices do not have codesigning protection. Sounds like any app can use a self-signed certificate chain to spoof the identifier of a well-known manufacturer. I guess the good news is they are fixing the bug.

Labels: , , , ,

By : Tighten BBC News - Android Fake ID bug exposes smartphones and tablets 0 comments

11.11.2013
Mac Developer: Mobile devs: Google will officially translate your Android apps | VentureBeat

Mobile devs: Google will officially translate your Android apps | VentureBeat - Google announced that it would be opening up a translation service at Google I/O and officially released it.


What's good for global revenue is good for both publisher and distributer.

Labels:

By : Tighten Mobile devs: Google will officially translate your Android apps | VentureBeat 0 comments

11.06.2013
Mac Developer: Is a Nexus 5 Phone Running on KitKat Any Sweeter? - Walt Mossberg - Personal Technology - AllThingsD

Is a Nexus 5 Phone Running on KitKat Any Sweeter? - Walt Mossberg - Personal Technology - AllThingsD - KitKat is also somewhat smoother and faster than its predecessor, Jelly Bean, at least on the Nexus 5. All of these KitKat features worked fine, but none was a huge deal to me.


Sometimes less is more.

Labels: ,

By : Tighten Is a Nexus 5 Phone Running on KitKat Any Sweeter? - Walt Mossberg - Personal Technology - AllThingsD 0 comments

7.25.2013
Mac Developer: First malware in the wild found exploiting Bluebox's Android app signing flaw

First malware in the wild found exploiting Bluebox's Android app signing flaw: "Earlier this month, the popular Facebook app was caught harvesting users' entire phone books for upload into the social network's vast graph, without notice, and subsequently 'sharing' information with other users 'having some connection to them' on the site. "


They're getting into the American spirit popularized by the NSA! This is an important read because it highlights the reasons that an application bundle needs both external (system verified) and internal (application self-verified) code signatures.

At least, that's my opinion.

Labels: , ,

By : Tighten First malware in the wild found exploiting Bluebox's Android app signing flaw 0 comments

 

 
 
 

 Tighten    
 Generate    
 Secure    
 Inspect    
 Quarantino    
 QTZ    
 Downloads    
 Support    
 Documentation    
 Tighten App.app    
 Tighten Pro.app    
 PKCS#7Viewer.app    
 Quarzenegger.app    
 About    
 Hire    
 Contact    
 Blogger    
 FaceBook    
 iTunes Direct Link    
 Hollywood CA    
 spctl --assess -vvv    
 spctl --master-enable    
 spctl --master-disable    
 Mac App Store Receipt Validation    
 Apple Code Signing Certificates    
 Gatekeeper Developer ID Apple    
 Xcode codesign tutorial    
 [Site Map]    
 


Copyright © 2005-2020
All Rights Reserved
Tighten Pro