Mysk🇨🇦🇩🇪

@mysk@mastodon.social · Joined ⁨Feb⁩ ⁨2023⁩

We're two #iOS developers and occasional #security researchers on two continents. #CyberSecurity 🇨🇦🇩🇪

Replying to @⁨mysk@mastodon.social⁩

We made a few mockups showing how we think Apple could improve macOS permission prompts to make app-tampering attacks far less effective:

2) Show a clear warning if macOS detects that an app’s signing identity has changed since it was last opened.

Simple changes like these could make it much harder for attackers to trick users into granting sensitive permissions.

1) Display the developer’s signing identity in TCC permission dialogs and when an app is opened for the first time.
ALT
1) Display the developer’s signing identity in TCC permission dialogs and when an app is opened for the first time.
ALT
2) Show a clear warning if macOS detects that an app’s signing identity has changed since it was last opened.
ALT

Replying to @⁨mysk@mastodon.social⁩

Mysk Blog – In-Depth Cybersecurity & Mobile App Privacy ResearchSilent Replacement of Trusted macOS App ExecutablesA vulnerability in macOS allows an attacker to silently replace the main executable of any application downloaded from the web without requiring elevated privileges. As a result, trusted applications can be made to execute attacker-controlled code without triggering security warnings when relaunched. Apple assessed the reported behaviour as not requiring a security fix.

🚨 We're disclosing a macOS security bug that Apple says is not an issue.
Using a simple archive-and-restore trick, an attacker can silently replace the main executable of virtually any application downloaded from the web—no password or warning is required.
Here's a demo using Signal to steal its encryption key.
📝 Blog with technical details: link in the replies.
Do you think this should be considered a security bug?
🎬👇
#Apple #privacy #infosec #security #macOS

youtu.be/0bOC8S3NQxI

YouTubemacOS Security: Replacing Trusted App Executables (Demo with Signal)by Mysk