Links...
 
Tighten Pro
C/C++/Cocoa tool for codesign security, Developer ID, & Mac App Store Receipt Validation

Tighten Pro - in the Mac App Store

Tighten Pro is now available in the Mac App Store. Simply click on the icon to the left to purchase directly from Apple. Or choose PKCS#7Viewer.app by clicking the image to the right.

7.16.2017
Mac Developer: Objective-See

Objective-SeeBlockBlock has the ability query VirusTotal to see if either the process or startup item that was persisted, is known malware. Clicking on the 'virus total' button will generate a network request, which contains the path, name, and hash of both the process and startup item.
This looks very promising.

Labels:

By : Tighten Objective-See 0 comments

8.04.2016
Mac Developer: OS X file guard tool in alpha • The Register

OS X file guard tool in alpha • The Register: "A new OS X utility called FlockFlock that monitors file-system accesses for malicious activity is available as an alpha release for experienced developers to test."

Yessssss...

Labels:

By : Tighten OS X file guard tool in alpha • The Register 0 comments

10.11.2015
Mac Developer: Apple removes several apps that could spy on encrypted traffic | Ars Technica

Apple removes several apps that could spy on encrypted traffic | Ars Technica Remember Superfish?
LENOVO PCS SHIP WITH MAN-IN-THE-MIDDLE ADWARE THAT BREAKS HTTPS CONNECTIONS [UPDATED] Superfish may make it trivial for attackers to spoof any HTTPS website. In any event, third-party root certificates installed on any device—whether it's a computer or phone—can have an extremely powerful effect on security and privacy. A case in point is Lenovo's former practice of selling computers that were preloaded with a self-signed root HTTPS certificate that intercepted and decrypted encrypted traffic for every website a user visited. When users visited an HTTPS-protected site, the adware known as Superfish used the self-signed certificate to encrypt the traffic and bypass the trusted key provided by the visited site.
Remember SUPERFISH? No, I don't remember it.

Labels: , ,

By : Tighten Apple removes several apps that could spy on encrypted traffic | Ars Technica 0 comments

11.07.2014
Mac Developer: Apple blocks WireLurker malware apps from opening, but needs to do more, argues security researcher | 9to5Mac

Apple blocks WireLurker malware apps from opening, but needs to do more, argues security researcher | 9to5Mac: "We are aware of malicious software available from a download site aimed at users in China, and we’ve blocked the identified apps to prevent them from launching. As always, we recommend that users download and install software from trusted sources."
I believe the USB exploit is more or less impossible to defend against.

Labels: , ,

By : Tighten Apple blocks WireLurker malware apps from opening, but needs to do more, argues security researcher | 9to5Mac 0 comments

10.06.2014
Mac Developer: 'iWorm' malware controls Macs via Reddit, more than 17K affected

'iWorm' malware controls Macs via Reddit, more than 17K affected: "Entered into the virus database of Russian research firm Dr. Web as 'Mac.BackDoor.iWorm,' the new threat is described as a complex multi-purpose backdoor capable of issuing a variety of commands to be carried out by an affected host Mac. Among the operations available to the malware are data gathering and limited system remote control.
The name is Evil, Dr. Evil. Ha ha ha!

Labels: ,

By : Tighten 'iWorm' malware controls Macs via Reddit, more than 17K affected 0 comments

6.28.2014
Mac Developer: genkiyooka/MacRuntimeSandboxDetection

genkiyooka/MacRuntimeSandboxDetection
For CFPlugIn and AudioUnit developers - how to check Mac App Store sandbox capabilities at runtime.


If you write system components (i.e. CoreAudio AudioUnit), CFPlugIn bundles or loadable Cocoa frameworks which are shared among applications (like haxies), you may wish to detect the capabilities of the sandbox environment into which you've been loaded so you can gracefully disable features and so forth.

Naive implementations of such loadable code often dump huge volumes of system messages into the Console.log - not useful to anyone.

Labels: , , , , , ,

By : Tighten genkiyooka/MacRuntimeSandboxDetection 0 comments

11.09.2013
Mac Developer: Developers need to start thinking about security now | VentureBeat

Developers need to start thinking about security now | VentureBeat - The fundamental relationship between security and development is broken. It’s broken because security teams drive security, and development teams let them. There needs to be a re-balancing of this relationship, driven by an awakening in the developer community.


Some thoughts about security and development.

Labels: ,

By : Tighten Developers need to start thinking about security now | VentureBeat 0 comments

7.24.2013
Mac Developer: fseventer [fernLightning]

fseventer [fernLightning]: "Observes filesystem changes using the same underlying API as Spotlight Provides a graphical representation of the file activity Example use could be to determine what files are changed via software installation, preferences, etc"


Very handy tool that shows what processes are opening and writing to files. Very cool.

Labels: ,

By : Tighten fseventer [fernLightning] 0 comments

 

 
 
 

 Tighten    
 Generate    
 Secure    
 Inspect    
 Quarantino    
 QTZ    
 Downloads    
 Support    
 Documentation    
 Tighten App.app    
 Tighten Pro.app    
 PKCS#7Viewer.app    
 Quarzenegger.app    
 About    
 Hire    
 Contact    
 Blogger    
 FaceBook    
 iTunes Direct Link    
 Hollywood CA    
 spctl --assess -vvv    
 spctl --master-enable    
 spctl --master-disable    
 Mac App Store Receipt Validation    
 Apple Code Signing Certificates    
 Gatekeeper Developer ID Apple    
 Xcode codesign tutorial    
 [Site Map]    
 


Copyright © 2005-2020
All Rights Reserved
Tighten Pro