|
Tighten Pro C/C++/Cocoa tool for codesign security, Developer ID, & Mac App Store Receipt Validation
  Tighten Pro - in the Mac App Store
Tighten Pro is now available in the Mac App Store.
Simply click on the icon to the left to purchase directly from Apple.
Or choose PKCS#7Viewer.app by clicking the image to the right.
|
Mac Developer: Second Oracle v. Google trial could lead to huge headaches for developers | Ars Technica
Second Oracle v. Google trial could lead to huge headaches for developers | Ars Technica: "In the EFF's view, the Federal Circuit decision was wrong and conflicts with existing 9th Circuit cases, like Sega v. Accolade (1992) and Sony v. Connectix (2000), which allow for interoperability between systems, whether a copyright owner likes it or not."
Cry, cheer, or neither? Labels: secure coding mac
Mac Developer: Zero Day Exploit Bypasses OS X's SIP Entirely | Digital Trends
Zero Day Exploit Bypasses OS X's SIP Entirely | Digital TrendsThe exploit is unique in that it doesn’t use memory corruption, an common attacker exploit. Instead, the attack exploits a longstanding vulnerability in OS X’s security schemes to gain near-total control over any Mac. Hmmm.
Labels: secure coding mac, security flaw
Mac Developer: How malware developers could bypass Mac’s Gatekeeper without really trying | Ars Technica
The exploit works with Apple-trusted executable apps that are bundled with, and are programmed to execute, one or more additional apps. The hack works by renaming the Apple-trusted file but otherwise making no other changes to it. Wardle then packages it inside an Apple disk image that contains any executables he wants. Gatekeeper inspects only the first executable file and allows the remaining bundled apps to be executed with no questions asked.
Hmmmmm.. Labels: secure coding mac
Mac Developer: Validating Receipts Locally
Validating Receipts Locally
/* For additional security, you may verify the fingerprint of the root certificate and verify the OIDs of the intermediate certificate and signing certificate. The OID in the certificate policies extension of the intermediate certificate is (1 2 840 113635 100 5 6 1), and the marker OID of the signing certificate is (1 2 840 113635 100 6 11 1). */
I suppose the moral of the story is: don't say I didn't warn ya.
Labels: secure coding mac, security, security fix
Mac Developer: Drop-dead simple exploit completely bypasses Mac’s malware Gatekeeper | Ars Technica
Drop-dead simple exploit completely bypasses Mac’s malware Gatekeeper | Ars Technica Since its introduction in 2012, an OS X feature known as Gatekeeper has gone a long way to protecting the Macs of security novices and experts alike. Not only does it help neutralize social engineering attacks that trick less experienced users into installing trojans, code-signing requirements ensure even seasoned users that an installer app hasn't been maliciously modified as it was downloaded over an unencrypted connection.
Extra hoops for legitimate developers that apparently do not retard the activities of elite hackers.
Labels: secure coding mac, security policy
Mac Developer: SHA1 algorithm securing e-commerce and software could break by year’s end | Ars Technica
SHA1 algorithm securing e-commerce and software could break by year’s end | Ars Technica SHA1, one of the Internet's most crucial cryptographic algorithms, is so weak to a newly refined attack that it may be broken by real-world hackers in the next three months, an international team of researchers warned Thursday.
Dang, SHA1, we hardly knew ye.
Labels: secure coding mac, security, SHA1
Mac Developer: iOS 9, OS X El Capitan close serious AirDrop vulnerability allowing malware infections
iOS 9, OS X El Capitan close serious AirDrop vulnerability allowing malware infections The technique bypasses Apple's security using a spoofed enterprise certificate, and can potentially be used against anyone within AirDrop range, Azimuth Security's Mark Dowd told Forbes. The attack forces the installation of a provisioning profile, and can alter iOS' Springboard to convince a device that the fake certificate is already trusted.
Kind of a showstopper as far as things like this go.
Labels: secure coding mac, security flaw
Mac Developer: Windows 10 Device Guard: Microsoft's effort to keep malware off PCs • The Register
Windows 10 Device Guard: Microsoft's effort to keep malware off PCs • The Register: "If the Windows 10 kernel, which has control over the PC, is compromised, Device Guard will remain fire-walled off, and cannot be subverted into allowing unauthorized code to run. A hypervisor running beneath the kernel and Device Guard enforces this.
Some interesting developments here.
Labels: sandbox, secure coding mac, security
Mac Developer: Stepson of Stuxnet stalked Kaspersky for months, tapped Iran nuke talks | Ars Technica
Stepson of Stuxnet stalked Kaspersky for months, tapped Iran nuke talks | Ars Technica: "in 2011 Duqu 1.0 attackers compromised computers at NetLock, a Hungarian certificate authority. That hack allowed them to sign their wares with digital stamps trusted by Windows machines."
Fascinating tale. Or "How I learned to stop worrying and love the Nation-state sponsored cyberwars."
Labels: secure coding mac, security, security flaw
Mac Developer: Bug in iOS Unicode handling crashes iPhones with a simple text
Bug in iOS Unicode handling crashes iPhones with a simple text
A peculiar iOS bug apparently that allows pranksters to crash a victim's iPhone by sending a text message from their own iPhone containing what appears to be a single line of seemingly innocuous Arabic script.
A little troubling to be sure. Labels: secure coding mac, security flaw
Mac Developer: China reportedly defers banking technology regulations, relieves pressure on foreign firms
China reportedly defers banking technology regulations, relieves pressure on foreign firms: "Citing an unnamed U.S. official, Reuters reports U.S. Treasury Secretary Jack Lew met with Chinese officials, including Premier Li Keqiang, in Beijing presumably to discuss concerns over security measures designed to protect state-backed banking institutions from outside threats.
Code security doesn't go any higher than this.
Labels: secure coding mac, security, security law
Mac Developer: Hundreds of iOS apps vulnerable to HTTPS-based FREAK attack
Hundreds of iOS apps vulnerable to HTTPS-based FREAK attack
Security researchers at FireEye recently went through thousands of iOS and Android apps and found that while a bulk are not vulnerable to the "FREAK" (Factoring RSA Export Keys) attack, a significant number are, reports Ars Technica.
Internal app security is the next frontier of security. Labels: secure coding mac, security flaw
Mac Developer: Quarantino - xattr com.apple.quarantine in an App
Introducing Quarantino.app for Mac OS X (10.6.8 through 10.10.x) - a simple and effective way to view the signing credentials of an app downloaded from the internet, and if so desired, remove the quarantine attribute (xattr -l com.apple.quarantine).
The fact of the matter is, some OS features are not available to properly signed applications if they are in the quarantine. Don't believe me? See if you can spot the differences in operation between Quarantino.app (quarantined) and after you remove it from the quarantine.
Available for download now from this website (DeveloperID credentials) and coming soon to the App Store (fingers crossed - in review)! Labels: com.apple.quarantine, quarantino, secure coding mac, security, utility
Mac Developer: Mac OS X Security Overview
http://www.giac.org/paper/gsec/28443/mac-security/124082
Nice security overview of Mac OS X. Different features and advantages are covered. Labels: mac runtime sandbox detection, sandbox policy language, secure coding mac, security, xprotect.plist
Mac Developer: Technical notes, my online memory: Gatekeeper, XProtect and the Quarantine attribute
Technical notes, my online memory: Gatekeeper, XProtect and the Quarantine attribute: "Apps can opt-in to Gatekeeper and Xprotect protection by adding LSFileQuarantineEnabled to their Contents/Info.plist. This means that any files created by that app will get tagged with the apple quarantine HFS+ extended attribute.
Everything you wanted to know about quarantine but were afraid to ask.
Labels: gatekeeper, quarantine, secure coding mac, security
Mac Developer: The Cocoa Distillery - How to build on 10.8 and earlier, then sign for...
The Cocoa Distillery - How to build on 10.8 and earlier, then sign for...: "The only way to obtain a v2 signature is by code signing under 10.9, but since Xcode 3 doesn’t run on anything newer than 10.6.8, I’ll have to separate the build process from the signing, packaging and submission process."
For those building under 10.6.8 for the Mac App Store or Gatekeeper.
Labels: codesign, gatekeeper, secure coding mac, security, version 2 signature
Mac Developer: genkiyooka/MacRuntimeSandboxDetection · GitHub
genkiyooka/MacRuntimeSandboxDetection · GitHub: "For CFPlugIn and AudioUnit developers - how to check Mac App Store sandbox capabilities at runtime."
Apologies for the delay, but just checked in bug fixes for detecting Mac OS X sandbox capabilities at runtime. I'm using this in production code now, and I believe it is stable and working correctly on 10.6-10.9.
This code is quite useful when building solutions that may be DeveloperID or Mac App Store and/or sandboxed. If you discover any cases that are not correctly handled, please let me know. Labels: app security, secure coding mac
Mac Developer: 'Canvas fingerprinting' has a new enemy, and its name is Ghostery | VentureBeat | Security | by Richard Byrne Reilly
'Canvas fingerprinting' has a new enemy, and its name is Ghostery | VentureBeat | Security | by Richard Byrne Reilly: "Critically, canvas fingerprinting cannot be blocked by refusing or deleting browser cookies, which is what most tracking tools use. Although canvas fingerprinting works on both desktop and mobile, it thrives in the former, because the technology is older."
All signs point to the browser as the main security vulnerability. Labels: secure coding mac
Mac Developer: genkiyooka/MacRuntimeSandboxDetection
genkiyooka/MacRuntimeSandboxDetection
For CFPlugIn and AudioUnit developers - how to check Mac App Store sandbox capabilities at runtime.
If you write system components (i.e. CoreAudio AudioUnit), CFPlugIn bundles or loadable Cocoa frameworks which are shared among applications (like haxies), you may wish to detect the capabilities of the sandbox environment into which you've been loaded so you can gracefully disable features and so forth.
Naive implementations of such loadable code often dump huge volumes of system messages into the Console.log - not useful to anyone.
Labels: app store, c++, cocoa, mac runtime sandbox detection, sandbox, secure coding mac, security tools mac
Mac Developer: Secure Coding Guide: Introduction to Secure Coding Guide
Secure Coding Guide: Introduction to Secure Coding Guide
The document begins with “Types of Security Vulnerabilities,” which gives a brief introduction to the nature of each of the types of security vulnerability commonly found in software. This chapter provides background information that you should understand before reading the other chapters in the document. If you’re not sure what a race condition is, for example, or why it poses a security risk, this chapter is the place to start.
A good overview that just popped up on my radar. Labels: sandbox, secure coding mac, security
| |
|