Links...
 
Tighten Pro
C/C++/Cocoa tool for codesign security, Developer ID, & Mac App Store Receipt Validation

Tighten Pro - in the Mac App Store

Tighten Pro is now available in the Mac App Store. Simply click on the icon to the left to purchase directly from Apple. Or choose PKCS#7Viewer.app by clicking the image to the right.

5.10.2016
Mac Developer: Second Oracle v. Google trial could lead to huge headaches for developers | Ars Technica

Second Oracle v. Google trial could lead to huge headaches for developers | Ars Technica: "In the EFF's view, the Federal Circuit decision was wrong and conflicts with existing 9th Circuit cases, like Sega v. Accolade (1992) and Sony v. Connectix (2000), which allow for interoperability between systems, whether a copyright owner likes it or not."

Cry, cheer, or neither?

Labels:

By : Tighten Second Oracle v. Google trial could lead to huge headaches for developers | Ars Technica 0 comments

3.27.2016
Mac Developer: Zero Day Exploit Bypasses OS X's SIP Entirely | Digital Trends

Zero Day Exploit Bypasses OS X's SIP Entirely | Digital TrendsThe exploit is unique in that it doesn’t use memory corruption, an common attacker exploit. Instead, the attack exploits a longstanding vulnerability in OS X’s security schemes to gain near-total control over any Mac.
Hmmm.

Labels: ,

By : Tighten Zero Day Exploit Bypasses OS X's SIP Entirely | Digital Trends 0 comments

1.16.2016
Mac Developer: How malware developers could bypass Mac’s Gatekeeper without really trying | Ars Technica

How malware developers could bypass Mac’s Gatekeeper without really trying | Ars Technica

The exploit works with Apple-trusted executable apps that are bundled with, and are programmed to execute, one or more additional apps. The hack works by renaming the Apple-trusted file but otherwise making no other changes to it. Wardle then packages it inside an Apple disk image that contains any executables he wants. Gatekeeper inspects only the first executable file and allows the remaining bundled apps to be executed with no questions asked.
Hmmmmm..

Labels:

By : Tighten How malware developers could bypass Mac’s Gatekeeper without really trying | Ars Technica 0 comments

11.15.2015
Mac Developer: Validating Receipts Locally

Validating Receipts Locally
/* For additional security, you may verify the fingerprint of the root certificate and verify the OIDs of the intermediate certificate and signing certificate. The OID in the certificate policies extension of the intermediate certificate is (1 2 840 113635 100 5 6 1), and the marker OID of the signing certificate is (1 2 840 113635 100 6 11 1). */
I suppose the moral of the story is: don't say I didn't warn ya.

Labels: , ,

By : Tighten Validating Receipts Locally 0 comments

10.08.2015
Mac Developer: Drop-dead simple exploit completely bypasses Mac’s malware Gatekeeper | Ars Technica

Drop-dead simple exploit completely bypasses Mac’s malware Gatekeeper | Ars Technica Since its introduction in 2012, an OS X feature known as Gatekeeper has gone a long way to protecting the Macs of security novices and experts alike. Not only does it help neutralize social engineering attacks that trick less experienced users into installing trojans, code-signing requirements ensure even seasoned users that an installer app hasn't been maliciously modified as it was downloaded over an unencrypted connection.
Extra hoops for legitimate developers that apparently do not retard the activities of elite hackers.

Labels: ,

By : Tighten Drop-dead simple exploit completely bypasses Mac’s malware Gatekeeper | Ars Technica 0 comments

Mac Developer: SHA1 algorithm securing e-commerce and software could break by year’s end | Ars Technica

SHA1 algorithm securing e-commerce and software could break by year’s end | Ars Technica SHA1, one of the Internet's most crucial cryptographic algorithms, is so weak to a newly refined attack that it may be broken by real-world hackers in the next three months, an international team of researchers warned Thursday.
Dang, SHA1, we hardly knew ye.

Labels: , ,

By : Tighten SHA1 algorithm securing e-commerce and software could break by year’s end | Ars Technica 0 comments

9.17.2015
Mac Developer: iOS 9, OS X El Capitan close serious AirDrop vulnerability allowing malware infections

iOS 9, OS X El Capitan close serious AirDrop vulnerability allowing malware infections The technique bypasses Apple's security using a spoofed enterprise certificate, and can potentially be used against anyone within AirDrop range, Azimuth Security's Mark Dowd told Forbes. The attack forces the installation of a provisioning profile, and can alter iOS' Springboard to convince a device that the fake certificate is already trusted.
Kind of a showstopper as far as things like this go.

Labels: ,

By : Tighten iOS 9, OS X El Capitan close serious AirDrop vulnerability allowing malware infections 0 comments

8.11.2015
Mac Developer: Windows 10 Device Guard: Microsoft's effort to keep malware off PCs • The Register

Windows 10 Device Guard: Microsoft's effort to keep malware off PCs • The Register: "If the Windows 10 kernel, which has control over the PC, is compromised, Device Guard will remain fire-walled off, and cannot be subverted into allowing unauthorized code to run. A hypervisor running beneath the kernel and Device Guard enforces this.
Some interesting developments here.

Labels: , ,

By : Tighten Windows 10 Device Guard: Microsoft's effort to keep malware off PCs • The Register 0 comments

6.29.2015
Mac Developer: Stepson of Stuxnet stalked Kaspersky for months, tapped Iran nuke talks | Ars Technica

Stepson of Stuxnet stalked Kaspersky for months, tapped Iran nuke talks | Ars Technica: "in 2011 Duqu 1.0 attackers compromised computers at NetLock, a Hungarian certificate authority. That hack allowed them to sign their wares with digital stamps trusted by Windows machines."
Fascinating tale. Or "How I learned to stop worrying and love the Nation-state sponsored cyberwars."

Labels: , ,

By : Tighten Stepson of Stuxnet stalked Kaspersky for months, tapped Iran nuke talks | Ars Technica 0 comments

5.28.2015
Mac Developer: Bug in iOS Unicode handling crashes iPhones with a simple text

Bug in iOS Unicode handling crashes iPhones with a simple text
A peculiar iOS bug apparently that allows pranksters to crash a victim's iPhone by sending a text message from their own iPhone containing what appears to be a single line of seemingly innocuous Arabic script.


A little troubling to be sure.

Labels: ,

By : Tighten Bug in iOS Unicode handling crashes iPhones with a simple text 0 comments

3.31.2015
Mac Developer: China reportedly defers banking technology regulations, relieves pressure on foreign firms

China reportedly defers banking technology regulations, relieves pressure on foreign firms: "Citing an unnamed U.S. official, Reuters reports U.S. Treasury Secretary Jack Lew met with Chinese officials, including Premier Li Keqiang, in Beijing presumably to discuss concerns over security measures designed to protect state-backed banking institutions from outside threats.
Code security doesn't go any higher than this.

Labels: , ,

By : Tighten China reportedly defers banking technology regulations, relieves pressure on foreign firms 0 comments

3.19.2015
Mac Developer: Hundreds of iOS apps vulnerable to HTTPS-based FREAK attack

Hundreds of iOS apps vulnerable to HTTPS-based FREAK attack
Security researchers at FireEye recently went through thousands of iOS and Android apps and found that while a bulk are not vulnerable to the "FREAK" (Factoring RSA Export Keys) attack, a significant number are, reports Ars Technica.


Internal app security is the next frontier of security.

Labels: ,

By : Tighten Hundreds of iOS apps vulnerable to HTTPS-based FREAK attack 0 comments

1.08.2015
Mac Developer: Quarantino - xattr com.apple.quarantine in an App

Introducing Quarantino.app for Mac OS X (10.6.8 through 10.10.x) - a simple and effective way to view the signing credentials of an app downloaded from the internet, and if so desired, remove the quarantine attribute (xattr -l com.apple.quarantine).

The fact of the matter is, some OS features are not available to properly signed applications if they are in the quarantine. Don't believe me? See if you can spot the differences in operation between Quarantino.app (quarantined) and after you remove it from the quarantine.

Available for download now from this website (DeveloperID credentials) and coming soon to the App Store (fingers crossed - in review)!

Labels: , , , ,

By : Tighten Quarantino - xattr com.apple.quarantine in an App 0 comments

Mac Developer: Mac OS X Security Overview


http://www.giac.org/paper/gsec/28443/mac-security/124082


Nice security overview of Mac OS X. Different features and advantages are covered.

Labels: , , , ,

By : Tighten Mac OS X Security Overview 0 comments

1.01.2015
Mac Developer: Technical notes, my online memory: Gatekeeper, XProtect and the Quarantine attribute

Technical notes, my online memory: Gatekeeper, XProtect and the Quarantine attribute: "Apps can opt-in to Gatekeeper and Xprotect protection by adding LSFileQuarantineEnabled to their Contents/Info.plist. This means that any files created by that app will get tagged with the apple quarantine HFS+ extended attribute.
Everything you wanted to know about quarantine but were afraid to ask.

Labels: , , ,

By : Tighten Technical notes, my online memory: Gatekeeper, XProtect and the Quarantine attribute 0 comments

12.27.2014
Mac Developer: The Cocoa Distillery - How to build on 10.8 and earlier, then sign for...

The Cocoa Distillery - How to build on 10.8 and earlier, then sign for...: "The only way to obtain a v2 signature is by code signing under 10.9, but since Xcode 3 doesn’t run on anything newer than 10.6.8, I’ll have to separate the build process from the signing, packaging and submission process."
For those building under 10.6.8 for the Mac App Store or Gatekeeper.

Labels: , , , ,

By : Tighten The Cocoa Distillery - How to build on 10.8 and earlier, then sign for... 0 comments

9.06.2014
Mac Developer: genkiyooka/MacRuntimeSandboxDetection · GitHub

genkiyooka/MacRuntimeSandboxDetection · GitHub: "For CFPlugIn and AudioUnit developers - how to check Mac App Store sandbox capabilities at runtime."
Apologies for the delay, but just checked in bug fixes for detecting Mac OS X sandbox capabilities at runtime. I'm using this in production code now, and I believe it is stable and working correctly on 10.6-10.9.

This code is quite useful when building solutions that may be DeveloperID or Mac App Store and/or sandboxed. If you discover any cases that are not correctly handled, please let me know.

Labels: ,

By : Tighten genkiyooka/MacRuntimeSandboxDetection · GitHub 0 comments

8.06.2014
Mac Developer: 'Canvas fingerprinting' has a new enemy, and its name is Ghostery | VentureBeat | Security | by Richard Byrne Reilly

'Canvas fingerprinting' has a new enemy, and its name is Ghostery | VentureBeat | Security | by Richard Byrne Reilly: "Critically, canvas fingerprinting cannot be blocked by refusing or deleting browser cookies, which is what most tracking tools use. Although canvas fingerprinting works on both desktop and mobile, it thrives in the former, because the technology is older."
All signs point to the browser as the main security vulnerability.

Labels:

By : Tighten 'Canvas fingerprinting' has a new enemy, and its name is Ghostery | VentureBeat | Security | by Richard Byrne Reilly 0 comments

6.28.2014
Mac Developer: genkiyooka/MacRuntimeSandboxDetection

genkiyooka/MacRuntimeSandboxDetection
For CFPlugIn and AudioUnit developers - how to check Mac App Store sandbox capabilities at runtime.


If you write system components (i.e. CoreAudio AudioUnit), CFPlugIn bundles or loadable Cocoa frameworks which are shared among applications (like haxies), you may wish to detect the capabilities of the sandbox environment into which you've been loaded so you can gracefully disable features and so forth.

Naive implementations of such loadable code often dump huge volumes of system messages into the Console.log - not useful to anyone.

Labels: , , , , , ,

By : Tighten genkiyooka/MacRuntimeSandboxDetection 0 comments

Mac Developer: Secure Coding Guide: Introduction to Secure Coding Guide

Secure Coding Guide: Introduction to Secure Coding Guide
The document begins with “Types of Security Vulnerabilities,” which gives a brief introduction to the nature of each of the types of security vulnerability commonly found in software. This chapter provides background information that you should understand before reading the other chapters in the document. If you’re not sure what a race condition is, for example, or why it poses a security risk, this chapter is the place to start.


A good overview that just popped up on my radar.

Labels: , ,

By : Tighten Secure Coding Guide: Introduction to Secure Coding Guide 0 comments

 

 
 
 

 Tighten    
 Generate    
 Secure    
 Inspect    
 Quarantino    
 QTZ    
 Downloads    
 Support    
 Documentation    
 Tighten App.app    
 Tighten Pro.app    
 PKCS#7Viewer.app    
 Quarzenegger.app    
 About    
 Hire    
 Contact    
 Blogger    
 FaceBook    
 iTunes Direct Link    
 Hollywood CA    
 spctl --assess -vvv    
 spctl --master-enable    
 spctl --master-disable    
 Mac App Store Receipt Validation    
 Apple Code Signing Certificates    
 Gatekeeper Developer ID Apple    
 Xcode codesign tutorial    
 [Site Map]    
 


Copyright © 2005-2020
All Rights Reserved
Tighten Pro