|
Tighten Pro C/C++/Cocoa tool for codesign security, Developer ID, & Mac App Store Receipt Validation
  Tighten Pro - in the Mac App Store
Tighten Pro is now available in the Mac App Store.
Simply click on the icon to the left to purchase directly from Apple.
Or choose PKCS#7Viewer.app by clicking the image to the right.
|
Mac Developer: Google launches “Shielded VMs” to protect cloud servers from rootkits, data theft | Ars Technica
Google launches “Shielded VMs” to protect cloud servers from rootkits, data theft | Ars Technica: "Both Microsoft and Google have launched confidential computing technologies; Microsoft's Azure Confidential Compute was announced last September, and Google's Asylo framework was launched in beta in May. These platforms run application containers in "trusted execution environments"—enclaves that prevent access to the data within those instances from being read by anything running on the underlying operating system or virtual environment."
Hum dada. Labels: 1984, security is hard, security policy
Mac Developer: Security study finds old or improperly updated Macs in limited danger from EFI attack vectors
Security study finds old or improperly updated Macs in limited danger from EFI attack vectors: "
Duo suggests that Mac system administrators use the Apple-provided combo OS update, instead of delta updates —and to not use restore images to update machines even though it may be quicker."
Executive summary! Labels: security policy
Mac Developer: Ad industry complains Apple Safari update is 'unilateral and heavy-handed' against tracking
Ad industry complains Apple Safari update is 'unilateral and heavy-handed' against tracking: "Six ad industry organizations have crafted an open letter complaining about changes coming to Apple's Safari browser, claiming that a new feature — "Intelligent Tracking Prevention" — will hurt both them and the public."
Awesome! Labels: security policy
Mac Developer: Microsoft says it won't fix kernel flaw: It's not a security issue. Suuuure • The Register
Microsoft says it won't fix kernel flaw: It's not a security issue. Suuuure • The Register: "spotted this week by enSilo security researcher Omri Misgav, lies within the system call PsSetLoadImageNotifyRoutine, which has been part of Microsoft's operating system since Windows 2000 and is still active in the latest builds."
Things that go hmmmm in the night. Labels: security policy
Mac Developer: Revealed: The naughty tricks used by web ads to bypass blockers • The Register
Mac Developer: Suspected sextortionist hiding behind Tor is outed by booby-trapped video | Ars Technica
Suspected sextortionist hiding behind Tor is outed by booby-trapped video | Ars Technica: "The FBI used a booby-trapped video to identify a California man who allegedly used the Tor network to anonymously extort sexually explicit material from minors online."
Score one for the good guys! Labels: security exploit, security flaw, security policy
Mac Developer: Kid found a way to travel for free in Budapest. He filed a bug report. And was promptly arrested • The Register
Kid found a way to travel for free in Budapest. He filed a bug report. And was promptly arrested • The Register: "The arrest of a Hungarian bloke after he discovered a massive flaw in the website of Budapest's transport authority – and reported it – has sparked a wave of protests."
How to ensure that security, which is already ridiculously difficult, remains impossible. Labels: security policy
Mac Developer: Microsoft’s secret weapon in ongoing struggle against Fancy Bear? Trademark law | Ars Technica
Microsoft’s secret weapon in ongoing struggle against Fancy Bear? Trademark law | Ars Technica: "In other words, any time an infected computer attempts to contact a command and control server through one of the domains, it will instead be connected to a Microsoft-controlled, secure server. "
That bear is dance. Labels: security policy
Mac Developer: Google drops the boom on WoSign, StartCom certs for good | Ars Technica
Google drops the boom on WoSign, StartCom certs for good | Ars Technica: "The investigation uncovered a pattern of bad practices at WoSign and its subsidiary StartCom dating back to the spring of 2015. As a result, Google moved last October to begin distrusting new certificates issued by the two companies, stating "Google has determined that two CAs, WoSign and StartCom, have not maintained the high standards expected of CAs and will no longer be trusted by Google Chrome."
Now for the root CAs in lala land. Labels: security policy
Mac Developer: Apple no longer accepting VPN-based ad blockers to App Store, report says
Mac Developer: Qubes OS will ship pre-installed on Purism’s security-focused Librem 13 laptop | Ars Technica
Qubes OS will ship pre-installed on Purism’s security-focused Librem 13 laptop | Ars Technica: "Qubes OS, the security-focused operating system that Edward Snowden said in November he was “really excited” about, announced this week that laptop maker Purism will ship their privacy-focused Librem 13 notebook with Qubes pre-installed."
This is the future of something, possibly the future of everything. Labels: security policy, security research
Mac Developer: Global Web standard for integrating DRM into browsers hits a snag | Ars Technica
Mac Developer: Google Chrome's HTTPS ban-hammer drops on WoSign, StartCom in two months • The Register
Mac Developer: Leaked recording reveals Apple's plan to stop leakers | Cult of Mac
Mac Developer: Fearing Shadow Brokers leak, NSA reported critical flaw to Microsoft | Ars Technica
Fearing Shadow Brokers leak, NSA reported critical flaw to Microsoft | Ars Technica: "Four weeks later, MS17-010 was released. And precisely 28 days after that, the Shadow Brokers published EternalBlue, DoublePulsar, and dozens more hacking tools."
Hmmmm. Labels: security leak, security policy
Mac Developer: Kaspersky Denies Report It Might Help Russian Government Spy on US Citizens
Kaspersky Denies Report It Might Help Russian Government Spy on US Citizens: "Some of the accusations and fears are based on the fact that Eugene Kaspersky, founder and CEO of Kaspersky Lab, was trained by the KGB and worked as a Soviet intelligence officer in the Red Army, a period which he previously declined to talk about."
May you live in interesting times... Labels: security policy
Mac Developer: New 'Dok' malware targets Macs using signed Apple developer certificate
New 'Dok' malware targets Macs using signed Apple developer certificate: "The code, dubbed "Dok" by security firm Check Point, is said to affect "all versions" of macOS/OS X, and be the first "major scale" malware directed at Mac owners through a "coordinated email phishing campaign." The emails are aimed mostly at Europeans, one example being a German-language message from a supposed Swiss official, claiming problems with the target's tax return."
Revoke! Revoke! Remote delete! Remote delete? Labels: gatekeeper, quarantine, security policy
Mac Developer: UK.gov throws hissy fit after Twitter chokes off snoop firm's access • The Register
UK.gov throws hissy fit after Twitter chokes off snoop firm's access • The Register: "Twitter has reportedly blocked a third-party firm used by the Home Office from accessing its firehose, prompting the government to complain that the social network is siding with terrorists."
Big brother is watching you tweet. Labels: security policy
Mac Developer: We're spying on you for your own protection, says NSA, FBI • The Register
We're spying on you for your own protection, says NSA, FBI • The Register: "The document even claims that it is surveilling US citizens for their own protection while at the same time claiming that it is not doing so.
Hmmm. Labels: security policy
Mac Developer: Google slaps Symantec for sloppy certs, slow show of SNAFUs • The Register
Google slaps Symantec for sloppy certs, slow show of SNAFUs • The Register: "Google's Chrome development team has posted a stinging criticism of Symantec's certificate-issuance practices, saying it has lost confidence in the company's practices and therefore in the safety of sessions hopefully-secured by Symantec-issued certificates."
Securing internet transactions: a house of cards. Will I buy a $9.99/year Google-issued certificate? The answer is a resounding yes, Go Daddy! Labels: security fail, security policy
| |
|