[HN Gopher] Is macOS's new XProtect behavioural security prepari...
___________________________________________________________________
Is macOS's new XProtect behavioural security preparing to go live?
Author : GavinAnderegg
Score : 82 points
Date : 2023-09-04 13:04 UTC (9 hours ago)
(HTM) web link (eclecticlight.co)
(TXT) w3m dump (eclecticlight.co)
| 1letterunixname wrote:
| The industry bar is low: Is it any better than MDE?
| callalex wrote:
| I wonder why Apple finds the need to run all of this security
| software in the shadows with zero documentation, near zero user
| access to logging, and zero user access to what the system is
| doing. Is it just some leftover pride because a handsome actor in
| blue jeans said macs don't have viruses on TV 15 years ago?
| kaba0 wrote:
| Because a serious enough malware running rampant on their
| platform would cause actual monetary loss for them, potentially
| losing their image as a safe OS?
| callalex wrote:
| In that case isn't it better to be seen doing something to
| counteract that possibility instead of hiding the effort?
| [deleted]
| GavinAnderegg wrote:
| For those interested in more details on XProtect's status on
| their systems, Howard Oakley (the author of this blog) also
| provides free utilities: https://eclecticlight.co/downloads/
|
| XProCheck, which allows for easier viewing of XProtect log
| details: https://eclecticlight.co/consolation-t2m2-and-log-
| utilities/
|
| As well as SilentKnight + LockRattler for checking the status of
| XProtect updates and other security configuration:
| https://eclecticlight.co/lockrattler-systhist/
| mattmcknight wrote:
| Is there any software out there detecting an unusual volume of
| file encryption activities from a process that could indicate it
| is ransomware?
| Unfrozen0688 wrote:
| Sentinelone et al. places canary files that when encrypted
| flags for ransomware to central management.
| Terretta wrote:
| _"RansomWhere? is a utility with a simple goal; generically
| thwart OS X ransomware. It does so by identifying a commonality
| of essentially all ransomware; the creation of encrypted
| files."_
|
| https://objective-see.org/products/ransomwhere.html
|
| For a deep dive into this line of thinking, his post:
|
| _Towards Generic Ransomware Detection (04 /20/2016)_ --
| https://objective-see.org/blog/blog_0x0F.html
|
| Malwarebytes purchased an activity detecting product and
| claimed to offer this type of protection, though that marketing
| has become more generic now:
|
| https://www.malwarebytes.com/cybersecurity/business/what-is-...
|
| Given AV firms change hands and veer into dark patterns, forum
| posts like this one shouldn't recommend anything in particular
| as the ownership and policies can change overnight.
| tokamak-teapot wrote:
| More of this could be great for corporate machines. Currently
| they are often bogged down with poorly behaving third party
| security software, some of which causes real problems for users,
| which could be lessened if some of that software could be
| replaced with better behaving OS capabilities.
|
| Windows Defender (or whatever it's called) looked like it might
| help similarly on Windows, but I haven't seen it being used that
| way. It looks to me like the third parties keep looking for new
| features they can advertise, knowing that corporate InfoSec will
| mandate support for them quickly, and that an OS-provided
| solution isn't sold in the same way, so will be deemed
| unsuitable.
|
| Anyone feel more optimistic?
| Unfrozen0688 wrote:
| >Windows Defender (or whatever it's called) looked like it
| might help similarly on Windows, but I haven't seen it being
| used that way.
|
| It is more and more, but you need the expensive Microsoft 365
| license to use the web portal for it for, key word, MANAGEMENT.
|
| You want to be able to scan computers, lock them out of all
| network access besides the AV management, block usb/peripherals
| etc etc when an attack happens.
|
| You DONT want to just let it run headless.
| bluedino wrote:
| 3rd party software checks the security and regulatory teams
| boxes, so no matter how bad they are, they won't be going away
| anytime soon.
| iancarroll wrote:
| I have seen companies pass audits with just XProtect, but I
| think it highly depends on your auditor and the wording you
| use to justify it.
| lloeki wrote:
| Scenario 1: corp buys into Apple's protection, gets rid of
| (most) third party software
|
| Scenario 2: corp keeps third party software, which bangs its
| head against Apple's protection which prevents such god
| processes to access information, thus corp disables Apple's
| protection and keeps using third party software.
| ec109685 wrote:
| Apple's software will never support DLP and other invasive
| Corp spyware so I think there will always unfortunately be a
| need for the latter.
|
| E.g. https://www.bloomberg.com/news/features/2023-05-11/the-
| plot-...
| derefr wrote:
| Scenario 3: Apple treats third-party software that "bangs its
| head against Apple's protection" as malware, force-disabling
| it; mandates all third-party software to be rewritten to just
| use control APIs for Apple's internal protection mechanism.
|
| (Compare/contrast: Hypervisor.framework)
| kaba0 wrote:
| For what it's worth, most if not all "anti-virus" software
| that corps buy are borderline malware themselves and
| doesn't worth shit. The reason they even exist is that
| corps get to tick "security" on some bullshit bureaucracy
| check list. One reason I prefer Macs on company laptops is
| that corp doesn't get to modify it all that much.
| AaronM wrote:
| PCI compliance mandates virus/ malware protection, so
| many orgs that handle card data are forced to run it.
| olyjohn wrote:
| [delayed]
| GeekyBear wrote:
| We've certainly seen Windows Defender delete software like
| uTorrent without any input from the system Administrator.
| greggsy wrote:
| This is exactly how Symantec operated under Windows 7, which
| required you to disable a key security feature at boot. Not
| sure if it's still a thing.
| g42gregory wrote:
| Hopefully Scenario 3a: corp realized that they don't really
| need Apple OS and move to Linux instead.
| greggsy wrote:
| IMO this is pulling the OS closer towards a more trusted
| platform model that mobile devices have been afforded through
| years of incremental refinement of corporate MDM solutions.
| [deleted]
| drewg123 wrote:
| If you read the darwin-kernel mailing list archives from 10-15
| years ago, some of the most ignorant questions were from AV
| vendors. (like: "why does my system deadlock when I stop the
| entire kernel waiting for a userspace helper ..") They seemed
| so horrifically incompetent that I resolved to never run any
| 3rd party AV software on any machine I control.
| ChrisMarshallNY wrote:
| I would hope so.
|
| We used to write image processing pipelines.
|
| This is code that _really_ needs to run fast.
|
| We spent a huge amount of time tuning, analyzing, and re-tuning
| the software.
|
| Our IT group was completely focused on office workers, and
| would force us to install their spyware on our test machines.
|
| It was not a good fit.
| davidmurdoch wrote:
| Great. I already can't get my signed, notarized, and stapled Mac
| version of my app to be runnable on mac. Apple is so hostile to
| developers.
| [deleted]
| Angostura wrote:
| Odd. I can get asn unsigned, un-notarised app running just
| fine. I just need to hold control while opening it for initial
| run. Something odd happening here.
| davidmurdoch wrote:
| Sure, there are workarounds. But I can't ask people that
| download the app to perform Apple's rituals.
| greggsy wrote:
| Why not? If you're able to demonstrate that you're a
| trusted developer, they'll respond positively to an FAQ.
| It's not uncommon.
| davidmurdoch wrote:
| Users are fickle. And in the 5 years I've been deploying
| this app I've never had to ask users to do that. I'm sure
| it's fixable, the solution has just eluded me this far.
| tough wrote:
| Or jump through several hoops into System Settings > Privacy
| & Security, and authorise the app.
|
| It's designed so regular users don't / can't bother to do so,
| tho
| steve_adams_86 wrote:
| I used to think this sentiment is overblown, but then I tried
| to develop a Mac and iOS app. Although I live in Canada, it
| took almost 3 weeks to become an Apple developer, having to
| supply every piece of ID in my possession and having many
| declined. They're British Columbian identification in perfectly
| fine condition.
|
| The development process could have been much worse, but some
| aspects of swift development in XCode were frustratingly rough
| with a range of extremely well document to barely documented
| APIs.
|
| Can I do X with SwiftUI? Who knows. Does it support Y pattern
| well? Absolutely, and here are a dozen examples. Such a pain in
| the ass.
|
| I also have no idea when my app will be approved. It just
| generates air quality forecasts from multiple sources, provides
| alerts, shows active wildfire perimeters, and doesn't allow any
| access to anything else. Just uses location, optionally. It's
| been weeks now.
|
| Overall I'd rather not develop for apple's devices again, but
| mostly because so little is in my control. The rest was fine. I
| strongly dislike having so little agency around being accepted
| into the platform and then publishing on it. Not having a say
| over my tool chain is also pretty frustrating when theirs is so
| buggy, slow, and unintuitive.
| jwells89 wrote:
| > Can I do X with SwiftUI? Who knows. Does it support Y
| pattern well? Absolutely, and here are a dozen examples. Such
| a pain in the ass.
|
| SwiftUI is still very green, especially on Mac where it
| hasn't gotten as much attention as it has on iOS. There are
| some things I'm starting to use it for over UIKit on iOS, but
| on macOS I wouldn't bother -- AppKit might be a little rough
| around the edges compared to UIKit, mainly due to its age,
| but it's a great deal more suitable for production work on
| macOS than SwiftUI is.
| steve_adams_86 wrote:
| I guess that was another hang up. What should you use? Why?
| When is it reasonable to use cutting edge vs seasoned
| libraries?
|
| Thanks for that, though. I'll likely give that a shot soon,
| because my current client loves the idea of MacOS apps. I
| like the idea of common code to rub on multiple platforms,
| but it seems like it's too green.
| duped wrote:
| It's not like Windows is any better, and Linux is kind of
| a free for all.
| jwells89 wrote:
| I think that not just on macOS, but generally in desktop
| software, the older, more mature, more "boring" option is
| going to be best in the long run even if getting up and
| running is faster in newer stuff. Of course platform devs
| would like you to think otherwise because they want buy-
| in for their new frameworks, but buy-in is earned. New
| frameworks might eventually be great, but it's going to
| be a while before they're able to compete with the likes
| of frameworks such as AppKit, which have legacies
| stretching back 3+ decades. That's a lot of time to allow
| for refinement and better covering of common use cases.
|
| It's somewhat true on mobile, too, though to a lesser
| extent because mobile UI widgets don't need to be as
| functional, which makes it easier for new things to
| compete -- for instance a table view with sortable,
| rearrangable columns and column headers is practically
| unheard of on mobile whereas it's a cornerstone widget on
| desktop. For user-facing platforms the web is the odd
| exception where it's somewhat the norm to jump for the
| latest trendy shiny thing on new projects.
| [deleted]
| VHRanger wrote:
| Love the update from a year ago where you need to click through
| 3 layers of settings to run code someone else wrote on MacOS
| now.
|
| And on the other end, window's UX is going down the drain year
| over year.
| RONROC wrote:
| [flagged]
| acdha wrote:
| Look, I agree that this kind of non-specific rant isn't
| useful but that level of response is pretty harsh. I'd at
| least be charitable and ask whether he's doing something
| uncommon which would explain why it's so much harder than
| normal.
| davidmurdoch wrote:
| I had such a great reply to their unkind comment. I lost it
| after hitting submit, because it was flagged by the time I
| did. I wish they left it up.
| mschuster91 wrote:
| The bastion rulesets won't impact your macOS app, unless you're
| attempting to do something that only malware or otherwise
| sketchy software would do.
| davidmurdoch wrote:
| Hopefully that's true. If Apple misclassifies some benign
| action an app makes I have a feeling it'll be nigh-impossible
| for users to continue using the app, and I always worry that
| automated negative consequences my come to my Apple developer
| account.
| diogenes4 wrote:
| Surely it would be easier to simply disable internet access
| until the user enables it. Bonus points if you can control
| what it talks to at the IP stack and DNS level. Something
| i've wanted for decades at this point.... yea, little snitch
| does this, but it's not built in and belongs on my phone as
| well.
|
| Preventing an app from accessing browser data feels like an
| approach to make people feel safe while providing no
| meaningful protections from most malware behavior.
| judge2020 wrote:
| Disabling internet access only prevents exfiltration.
| Ransomware, for instance, wouldn't need to access the
| internet at all if it used hard-coded public keys to
| encrypt content.
| greggsy wrote:
| I recently attempted to trace exactly which app is making a
| particular DNS SOA query. I can confidently say that there
| are very few applications in the *nix space that do proper
| DNS reporting at all, and Little Snitch seems to be the
| only one that would map the actual app. I found no working
| solution to match a query to a pid in Linux.
|
| This tells me that either people rarely need to do this, or
| that it's very hard to do in userland.
| mschuster91 wrote:
| > Preventing an app from accessing browser data feels like
| an approach to make people feel safe while providing no
| meaningful protections from most malware behavior.
|
| Depends on the threat model. Yes, protecting browser data
| does not help if the attacker gained entry into the system
| by exploiting a vulnerability in the browser. But it helps
| against _all other_ entry points: USB sticks laced with
| malware (common threat against companies), malware that
| came as part of an email attachment or by dodgy warez, an
| attacker that 's already in the network (either because
| they're laterally moving or because the victim is in a
| scenario like a public wifi) and exploits some
| vulnerability in network-enabled software...
|
| Classic defense in depth here, it massively raises the bar
| for attackers because to steal Chrome user sessions or
| passwords, you now need a code execution avenue but also a
| kernel-level or at least sandbox exploit to bypass Bastion.
| diogenes4 wrote:
| > Classic defense in depth here, it massively raises the
| bar for attackers because to steal Chrome user sessions
| or passwords, you now need a code execution avenue but
| also a kernel-level or at least sandbox exploit to bypass
| Bastion.
|
| Sure, but this is a very arbitrary threat model to
| prioritize that doesn't seem to affect people. What about
| ads? Tracking? Apps sending fingerprinting home? That
| seems like a more obvious place to start.
| mschuster91 wrote:
| > Sure, but this is a very arbitrary threat model to
| prioritize that doesn't seem to affect people.
|
| Credential stealer malware is abundant, it's often enough
| how attackers gain initial access to a company's internal
| network - grab the credentials off of Chrome, Firefox or
| one of the other popular password manager apps, and
| you're bound to find a set of credentials there. Now all
| you need is some piece of software that's reachable from
| the Internet and lacks 2FA (which applies to a shocking
| lot of legacy software), and you got some sort of
| persistent access to the network.
|
| And in ye early days of cryptocurrencies, before hardware
| vaults became the norm among crypto enthusiasts, a fair
| amount of people got their wallets drained by targeted
| cookie (=session) stealers.
|
| > What about ads? Tracking? Apps sending fingerprinting
| home?
|
| That is bad, but not "someone can drain your bank account
| or take over your social media accounts to spam" bad.
| duskwuff wrote:
| > Sure, but this is a very arbitrary threat model to
| prioritize that doesn't seem to affect people.
|
| Malware exfiltrating users' browser sessions and
| passwords is a "very arbitrary threat model" that
| "doesn't seem to affect people"???
| angulardragon03 wrote:
| Weird. I just downloaded Ganache and it ran and opened just
| fine, no warnings. Are you experiencing this on your own
| machine, or just other machines? And what version of macOS?
| davidmurdoch wrote:
| The current published version is fine, thanks for trying it!
| I'm working on a new release, and haven't been able to get
| the Apple build to work. Lots has changed since the last
| release, certainly on my side and I presume also on Apple's.
|
| I've manually tested on Monterey.
| angulardragon03 wrote:
| Ah ok, makes sense.
|
| I'd recommend you check out Apparency [1], which can
| inspect .app bundles and show you what's up with the
| signing on your bundle. It looks like you include a few
| frameworks (which also need to be signed), so maybe you
| have components missing signatures/with mismatched
| signatures.
|
| [1] https://mothersruin.com/software/Apparency/
| davidmurdoch wrote:
| This looks like it will be immensely useful! Thanks!
| DueDilligence wrote:
| [dead]
| jamil7 wrote:
| Can you share the app? Maybe someone here can tell what the
| issue is. I'm able to distribute outside of the mac AppStore
| without users needing to jump through any hoops or right click
| etc.
| stouset wrote:
| [flagged]
| davidmurdoch wrote:
| You are a liar.
| greggsy wrote:
| There's an opportunity to remedy your problem but I don't
| think this is the best way to leave that offer open.
| smoldesu wrote:
| There is no 'open offer' to consider. The _only thing_
| the grandparent did was fabricate a lie, and the only
| reasonable response is to call them out on it.
|
| Their comment was against HN guidelines (Assume good
| faith.), there's no reason to chide someone for calling
| them out on that.
| davidmurdoch wrote:
| They just made something up about me that is not true.
| They've insulted my integrity. They are a liar. No one in
| good faith can disagree.
| [deleted]
| davidmurdoch wrote:
| It's an Electron app AND blockchain related; hackernews's two
| favorite things to hate. I don't expect much love from this
| crowd. Heh.
|
| It's certainly either something I'm doing wrong, or a big in
| the software I'm using to automate signing, notification and
| stapling.
|
| Here's the issue I opened on the software I'm using to
| automate: https://github.com/electron-userland/electron-
| builder/issues... that issue kinks to the PR that adds the
| automation.
|
| It's a non-trivial thing to test, since it involves so many
| secrets and the notarization step can take over an hour, so I
| don't expect anyone here to actually want to look into it.
|
| My original comment really was just venting my frustration,
| not a cry for help (but I might be crying soon if I cant get
| to the bottom of this!).
| mike_hearn wrote:
| You could try experimenting with Hydraulic Conveyor [1]. I
| built it originally due to the frustrations involved in
| distributing P2P software during my old Bitcoin days so you
| won't get any hate from me about that ;)
|
| Conveyor can package Electron apps and also do all the Mac
| specific stuff from any platform including Linux. So it can
| sign, notarize and staple the app itself, also bundling
| Sparkle updates as it goes. We're listed on the Electron
| website these days. You may have more luck with it. There's
| a Discord channel for help too if you get stuck.
|
| [1] https://hydraulic.dev/ (disclosure: my company)
| davidmurdoch wrote:
| Thanks for this! I've made a new issue to look into
| switching. It'd be great to find something that Just
| Works(tm)!
| jamil7 wrote:
| Thanks for the response. The output of `spctl` on your
| latest build (2.7.2, downloaded from the build artefacts
| section of Github Actions gives me the following:
|
| /Applications/Ganache.app: rejected (invalid destination
| for symbolic link in bundle) origin=Developer ID
| Application: ConsenSys AG (48XVW22RCG)
|
| I see you're also migrating to Github Actions for this
| particular release and that the notarization process was
| working correctly on your previous CI/CD? I guess there has
| to be an issue with the new environment here or the way
| you're building it now.
| dunham wrote:
| Probably the five links to /usr/local/bin/python3 in
| node_modules. Does the app need node_modules bundled?
| terhechte wrote:
| I'm on mobile, so short help: in one of my projects I'm
| building a binary in Rust and then using Xcode to notarize
| it by replacing the binary of another shell app that I'm
| Bildung in Xcode. This works really well. Check out the
| description here: https://github.com/terhechte/Ebou
| davidmurdoch wrote:
| Thanks! I'll take a look at the specifics tomorrow.
| bitwize wrote:
| Apple has developed the first and _only_ generally available
| "evil maid" resistant computer systems. Part of participating
| in this secure ecosystem involves more effort on your part to
| comply with the security requirements.
|
| Or you can just develop for vulnerable-as-all-getout Linux or
| Windows systems. Your choice.
| realusername wrote:
| > Apple has developed the first and only generally available
| "evil maid" resistant computer systems.
|
| If you exclude themselves from the threat model of course,
| which I don't see why you would
| acdha wrote:
| Those are separate threats. You must accept the risk of
| your hardware manufacturer being compromised but that's
| very different from also accepting the risk that any third-
| party with brief physical access can compromise your
| device.
| anthk wrote:
| You are deluded. Once they get physical access, you are out
| of luck.
| watermelon0 wrote:
| Do you have any evidence to support this?
|
| macOS @ M1 boot process looks similar to that of iOS
| devices: https://support.apple.com/en-
| gb/guide/security/secac71d5623/...
|
| Under the assumption that SIP is not disabled, and computer
| doesn't have any 3rd party kernel extensions installed
| (both of which are safe to assume for most people), it's
| close to impossible to inject something in the boot chain.
|
| ---
|
| I think the best possible option might be to replace the
| keyboard with the one with a hardware keylogger, and record
| the actual password.
| anthk wrote:
| Yes, that option with the keyboard would be the easiest
| option. See? The point on encrypting your whole disk is
| not to avoid tampering, but to lock your machine in
| public places and be sure that no one can access your
| data upon placing that disk in another machine, or even
| trying to boot it.
| kaba0 wrote:
| As always, security always operates with some threat model
| in mind. Of course some government-level agency with
| physical access and any amount of money to spend could
| likely get access to your device (though the usual $5
| wrench is probably still the "better" way) at the price of
| a (or a few) zero days. But you are likely not a key person
| in toppling a government and it would be a giant waste on
| their parts.
|
| The threat model the general populace faces ranges from
| something as mundane as your ex wanting to extract
| something from your device to basically being the know-all
| key to every important document, photo and data you might
| have. I think I can safely say that under this
| circumstances not even physical access poses a real threat
| to the device's security -- it is tamper-proof to replacing
| most critical parts and the boot-sequence is
| cryptographically secured. Biometric data is not stored in
| software, so not even that can be spoofed.
| BiteCode_dev wrote:
| Having an evil made fidling my computer is not a big worry in
| my life. Not being a slave to the gafams is.
| acdha wrote:
| It's not just the evil maid but what happens if your device
| is stolen (or scanned by the police), or you run malware by
| mistake and want to restore it to a trustworthy state. Most
| people should worry about those more than the evil maid
| scenarios.
| davidmurdoch wrote:
| If security was a spectrum Apple has gone into ultra-violet.
| If The Onion did tech jokes there'd be a headline that reads:
| The iBrick - it doesn't work, but at least it's hacker-proof!
|
| But thanks for reminding me I have a choice, which I actually
| do not.
| smoldesu wrote:
| > the first and only generally available "evil maid"
| resistant computer systems.
|
| "resistant" is a pretty low bar to pass. Do we get to include
| the Nintendo Switch for having eFuses?
| sam0x17 wrote:
| Hah, my minecraft region protection mod used to be called
| XProtect
| shepherdjerred wrote:
| I love seeing all of the fellow HN users who participated in
| the Minecraft server community
___________________________________________________________________
(page generated 2023-09-04 23:01 UTC)