[HN Gopher] Is macOS's new XProtect behavioural security prepari...
       ___________________________________________________________________
        
       Is macOS's new XProtect behavioural security preparing to go live?
        
       Author : GavinAnderegg
       Score  : 82 points
       Date   : 2023-09-04 13:04 UTC (9 hours ago)
        
 (HTM) web link (eclecticlight.co)
 (TXT) w3m dump (eclecticlight.co)
        
       | 1letterunixname wrote:
       | The industry bar is low: Is it any better than MDE?
        
       | callalex wrote:
       | I wonder why Apple finds the need to run all of this security
       | software in the shadows with zero documentation, near zero user
       | access to logging, and zero user access to what the system is
       | doing. Is it just some leftover pride because a handsome actor in
       | blue jeans said macs don't have viruses on TV 15 years ago?
        
         | kaba0 wrote:
         | Because a serious enough malware running rampant on their
         | platform would cause actual monetary loss for them, potentially
         | losing their image as a safe OS?
        
           | callalex wrote:
           | In that case isn't it better to be seen doing something to
           | counteract that possibility instead of hiding the effort?
        
       | [deleted]
        
       | GavinAnderegg wrote:
       | For those interested in more details on XProtect's status on
       | their systems, Howard Oakley (the author of this blog) also
       | provides free utilities: https://eclecticlight.co/downloads/
       | 
       | XProCheck, which allows for easier viewing of XProtect log
       | details: https://eclecticlight.co/consolation-t2m2-and-log-
       | utilities/
       | 
       | As well as SilentKnight + LockRattler for checking the status of
       | XProtect updates and other security configuration:
       | https://eclecticlight.co/lockrattler-systhist/
        
       | mattmcknight wrote:
       | Is there any software out there detecting an unusual volume of
       | file encryption activities from a process that could indicate it
       | is ransomware?
        
         | Unfrozen0688 wrote:
         | Sentinelone et al. places canary files that when encrypted
         | flags for ransomware to central management.
        
         | Terretta wrote:
         | _"RansomWhere? is a utility with a simple goal; generically
         | thwart OS X ransomware. It does so by identifying a commonality
         | of essentially all ransomware; the creation of encrypted
         | files."_
         | 
         | https://objective-see.org/products/ransomwhere.html
         | 
         | For a deep dive into this line of thinking, his post:
         | 
         |  _Towards Generic Ransomware Detection (04 /20/2016)_ --
         | https://objective-see.org/blog/blog_0x0F.html
         | 
         | Malwarebytes purchased an activity detecting product and
         | claimed to offer this type of protection, though that marketing
         | has become more generic now:
         | 
         | https://www.malwarebytes.com/cybersecurity/business/what-is-...
         | 
         | Given AV firms change hands and veer into dark patterns, forum
         | posts like this one shouldn't recommend anything in particular
         | as the ownership and policies can change overnight.
        
       | tokamak-teapot wrote:
       | More of this could be great for corporate machines. Currently
       | they are often bogged down with poorly behaving third party
       | security software, some of which causes real problems for users,
       | which could be lessened if some of that software could be
       | replaced with better behaving OS capabilities.
       | 
       | Windows Defender (or whatever it's called) looked like it might
       | help similarly on Windows, but I haven't seen it being used that
       | way. It looks to me like the third parties keep looking for new
       | features they can advertise, knowing that corporate InfoSec will
       | mandate support for them quickly, and that an OS-provided
       | solution isn't sold in the same way, so will be deemed
       | unsuitable.
       | 
       | Anyone feel more optimistic?
        
         | Unfrozen0688 wrote:
         | >Windows Defender (or whatever it's called) looked like it
         | might help similarly on Windows, but I haven't seen it being
         | used that way.
         | 
         | It is more and more, but you need the expensive Microsoft 365
         | license to use the web portal for it for, key word, MANAGEMENT.
         | 
         | You want to be able to scan computers, lock them out of all
         | network access besides the AV management, block usb/peripherals
         | etc etc when an attack happens.
         | 
         | You DONT want to just let it run headless.
        
         | bluedino wrote:
         | 3rd party software checks the security and regulatory teams
         | boxes, so no matter how bad they are, they won't be going away
         | anytime soon.
        
           | iancarroll wrote:
           | I have seen companies pass audits with just XProtect, but I
           | think it highly depends on your auditor and the wording you
           | use to justify it.
        
         | lloeki wrote:
         | Scenario 1: corp buys into Apple's protection, gets rid of
         | (most) third party software
         | 
         | Scenario 2: corp keeps third party software, which bangs its
         | head against Apple's protection which prevents such god
         | processes to access information, thus corp disables Apple's
         | protection and keeps using third party software.
        
           | ec109685 wrote:
           | Apple's software will never support DLP and other invasive
           | Corp spyware so I think there will always unfortunately be a
           | need for the latter.
           | 
           | E.g. https://www.bloomberg.com/news/features/2023-05-11/the-
           | plot-...
        
           | derefr wrote:
           | Scenario 3: Apple treats third-party software that "bangs its
           | head against Apple's protection" as malware, force-disabling
           | it; mandates all third-party software to be rewritten to just
           | use control APIs for Apple's internal protection mechanism.
           | 
           | (Compare/contrast: Hypervisor.framework)
        
             | kaba0 wrote:
             | For what it's worth, most if not all "anti-virus" software
             | that corps buy are borderline malware themselves and
             | doesn't worth shit. The reason they even exist is that
             | corps get to tick "security" on some bullshit bureaucracy
             | check list. One reason I prefer Macs on company laptops is
             | that corp doesn't get to modify it all that much.
        
               | AaronM wrote:
               | PCI compliance mandates virus/ malware protection, so
               | many orgs that handle card data are forced to run it.
        
               | olyjohn wrote:
               | [delayed]
        
             | GeekyBear wrote:
             | We've certainly seen Windows Defender delete software like
             | uTorrent without any input from the system Administrator.
        
           | greggsy wrote:
           | This is exactly how Symantec operated under Windows 7, which
           | required you to disable a key security feature at boot. Not
           | sure if it's still a thing.
        
           | g42gregory wrote:
           | Hopefully Scenario 3a: corp realized that they don't really
           | need Apple OS and move to Linux instead.
        
         | greggsy wrote:
         | IMO this is pulling the OS closer towards a more trusted
         | platform model that mobile devices have been afforded through
         | years of incremental refinement of corporate MDM solutions.
        
           | [deleted]
        
         | drewg123 wrote:
         | If you read the darwin-kernel mailing list archives from 10-15
         | years ago, some of the most ignorant questions were from AV
         | vendors. (like: "why does my system deadlock when I stop the
         | entire kernel waiting for a userspace helper ..") They seemed
         | so horrifically incompetent that I resolved to never run any
         | 3rd party AV software on any machine I control.
        
         | ChrisMarshallNY wrote:
         | I would hope so.
         | 
         | We used to write image processing pipelines.
         | 
         | This is code that _really_ needs to run fast.
         | 
         | We spent a huge amount of time tuning, analyzing, and re-tuning
         | the software.
         | 
         | Our IT group was completely focused on office workers, and
         | would force us to install their spyware on our test machines.
         | 
         | It was not a good fit.
        
       | davidmurdoch wrote:
       | Great. I already can't get my signed, notarized, and stapled Mac
       | version of my app to be runnable on mac. Apple is so hostile to
       | developers.
        
         | [deleted]
        
         | Angostura wrote:
         | Odd. I can get asn unsigned, un-notarised app running just
         | fine. I just need to hold control while opening it for initial
         | run. Something odd happening here.
        
           | davidmurdoch wrote:
           | Sure, there are workarounds. But I can't ask people that
           | download the app to perform Apple's rituals.
        
             | greggsy wrote:
             | Why not? If you're able to demonstrate that you're a
             | trusted developer, they'll respond positively to an FAQ.
             | It's not uncommon.
        
               | davidmurdoch wrote:
               | Users are fickle. And in the 5 years I've been deploying
               | this app I've never had to ask users to do that. I'm sure
               | it's fixable, the solution has just eluded me this far.
        
           | tough wrote:
           | Or jump through several hoops into System Settings > Privacy
           | & Security, and authorise the app.
           | 
           | It's designed so regular users don't / can't bother to do so,
           | tho
        
         | steve_adams_86 wrote:
         | I used to think this sentiment is overblown, but then I tried
         | to develop a Mac and iOS app. Although I live in Canada, it
         | took almost 3 weeks to become an Apple developer, having to
         | supply every piece of ID in my possession and having many
         | declined. They're British Columbian identification in perfectly
         | fine condition.
         | 
         | The development process could have been much worse, but some
         | aspects of swift development in XCode were frustratingly rough
         | with a range of extremely well document to barely documented
         | APIs.
         | 
         | Can I do X with SwiftUI? Who knows. Does it support Y pattern
         | well? Absolutely, and here are a dozen examples. Such a pain in
         | the ass.
         | 
         | I also have no idea when my app will be approved. It just
         | generates air quality forecasts from multiple sources, provides
         | alerts, shows active wildfire perimeters, and doesn't allow any
         | access to anything else. Just uses location, optionally. It's
         | been weeks now.
         | 
         | Overall I'd rather not develop for apple's devices again, but
         | mostly because so little is in my control. The rest was fine. I
         | strongly dislike having so little agency around being accepted
         | into the platform and then publishing on it. Not having a say
         | over my tool chain is also pretty frustrating when theirs is so
         | buggy, slow, and unintuitive.
        
           | jwells89 wrote:
           | > Can I do X with SwiftUI? Who knows. Does it support Y
           | pattern well? Absolutely, and here are a dozen examples. Such
           | a pain in the ass.
           | 
           | SwiftUI is still very green, especially on Mac where it
           | hasn't gotten as much attention as it has on iOS. There are
           | some things I'm starting to use it for over UIKit on iOS, but
           | on macOS I wouldn't bother -- AppKit might be a little rough
           | around the edges compared to UIKit, mainly due to its age,
           | but it's a great deal more suitable for production work on
           | macOS than SwiftUI is.
        
             | steve_adams_86 wrote:
             | I guess that was another hang up. What should you use? Why?
             | When is it reasonable to use cutting edge vs seasoned
             | libraries?
             | 
             | Thanks for that, though. I'll likely give that a shot soon,
             | because my current client loves the idea of MacOS apps. I
             | like the idea of common code to rub on multiple platforms,
             | but it seems like it's too green.
        
               | duped wrote:
               | It's not like Windows is any better, and Linux is kind of
               | a free for all.
        
               | jwells89 wrote:
               | I think that not just on macOS, but generally in desktop
               | software, the older, more mature, more "boring" option is
               | going to be best in the long run even if getting up and
               | running is faster in newer stuff. Of course platform devs
               | would like you to think otherwise because they want buy-
               | in for their new frameworks, but buy-in is earned. New
               | frameworks might eventually be great, but it's going to
               | be a while before they're able to compete with the likes
               | of frameworks such as AppKit, which have legacies
               | stretching back 3+ decades. That's a lot of time to allow
               | for refinement and better covering of common use cases.
               | 
               | It's somewhat true on mobile, too, though to a lesser
               | extent because mobile UI widgets don't need to be as
               | functional, which makes it easier for new things to
               | compete -- for instance a table view with sortable,
               | rearrangable columns and column headers is practically
               | unheard of on mobile whereas it's a cornerstone widget on
               | desktop. For user-facing platforms the web is the odd
               | exception where it's somewhat the norm to jump for the
               | latest trendy shiny thing on new projects.
        
         | [deleted]
        
         | VHRanger wrote:
         | Love the update from a year ago where you need to click through
         | 3 layers of settings to run code someone else wrote on MacOS
         | now.
         | 
         | And on the other end, window's UX is going down the drain year
         | over year.
        
         | RONROC wrote:
         | [flagged]
        
           | acdha wrote:
           | Look, I agree that this kind of non-specific rant isn't
           | useful but that level of response is pretty harsh. I'd at
           | least be charitable and ask whether he's doing something
           | uncommon which would explain why it's so much harder than
           | normal.
        
             | davidmurdoch wrote:
             | I had such a great reply to their unkind comment. I lost it
             | after hitting submit, because it was flagged by the time I
             | did. I wish they left it up.
        
         | mschuster91 wrote:
         | The bastion rulesets won't impact your macOS app, unless you're
         | attempting to do something that only malware or otherwise
         | sketchy software would do.
        
           | davidmurdoch wrote:
           | Hopefully that's true. If Apple misclassifies some benign
           | action an app makes I have a feeling it'll be nigh-impossible
           | for users to continue using the app, and I always worry that
           | automated negative consequences my come to my Apple developer
           | account.
        
           | diogenes4 wrote:
           | Surely it would be easier to simply disable internet access
           | until the user enables it. Bonus points if you can control
           | what it talks to at the IP stack and DNS level. Something
           | i've wanted for decades at this point.... yea, little snitch
           | does this, but it's not built in and belongs on my phone as
           | well.
           | 
           | Preventing an app from accessing browser data feels like an
           | approach to make people feel safe while providing no
           | meaningful protections from most malware behavior.
        
             | judge2020 wrote:
             | Disabling internet access only prevents exfiltration.
             | Ransomware, for instance, wouldn't need to access the
             | internet at all if it used hard-coded public keys to
             | encrypt content.
        
             | greggsy wrote:
             | I recently attempted to trace exactly which app is making a
             | particular DNS SOA query. I can confidently say that there
             | are very few applications in the *nix space that do proper
             | DNS reporting at all, and Little Snitch seems to be the
             | only one that would map the actual app. I found no working
             | solution to match a query to a pid in Linux.
             | 
             | This tells me that either people rarely need to do this, or
             | that it's very hard to do in userland.
        
             | mschuster91 wrote:
             | > Preventing an app from accessing browser data feels like
             | an approach to make people feel safe while providing no
             | meaningful protections from most malware behavior.
             | 
             | Depends on the threat model. Yes, protecting browser data
             | does not help if the attacker gained entry into the system
             | by exploiting a vulnerability in the browser. But it helps
             | against _all other_ entry points: USB sticks laced with
             | malware (common threat against companies), malware that
             | came as part of an email attachment or by dodgy warez, an
             | attacker that 's already in the network (either because
             | they're laterally moving or because the victim is in a
             | scenario like a public wifi) and exploits some
             | vulnerability in network-enabled software...
             | 
             | Classic defense in depth here, it massively raises the bar
             | for attackers because to steal Chrome user sessions or
             | passwords, you now need a code execution avenue but also a
             | kernel-level or at least sandbox exploit to bypass Bastion.
        
               | diogenes4 wrote:
               | > Classic defense in depth here, it massively raises the
               | bar for attackers because to steal Chrome user sessions
               | or passwords, you now need a code execution avenue but
               | also a kernel-level or at least sandbox exploit to bypass
               | Bastion.
               | 
               | Sure, but this is a very arbitrary threat model to
               | prioritize that doesn't seem to affect people. What about
               | ads? Tracking? Apps sending fingerprinting home? That
               | seems like a more obvious place to start.
        
               | mschuster91 wrote:
               | > Sure, but this is a very arbitrary threat model to
               | prioritize that doesn't seem to affect people.
               | 
               | Credential stealer malware is abundant, it's often enough
               | how attackers gain initial access to a company's internal
               | network - grab the credentials off of Chrome, Firefox or
               | one of the other popular password manager apps, and
               | you're bound to find a set of credentials there. Now all
               | you need is some piece of software that's reachable from
               | the Internet and lacks 2FA (which applies to a shocking
               | lot of legacy software), and you got some sort of
               | persistent access to the network.
               | 
               | And in ye early days of cryptocurrencies, before hardware
               | vaults became the norm among crypto enthusiasts, a fair
               | amount of people got their wallets drained by targeted
               | cookie (=session) stealers.
               | 
               | > What about ads? Tracking? Apps sending fingerprinting
               | home?
               | 
               | That is bad, but not "someone can drain your bank account
               | or take over your social media accounts to spam" bad.
        
               | duskwuff wrote:
               | > Sure, but this is a very arbitrary threat model to
               | prioritize that doesn't seem to affect people.
               | 
               | Malware exfiltrating users' browser sessions and
               | passwords is a "very arbitrary threat model" that
               | "doesn't seem to affect people"???
        
         | angulardragon03 wrote:
         | Weird. I just downloaded Ganache and it ran and opened just
         | fine, no warnings. Are you experiencing this on your own
         | machine, or just other machines? And what version of macOS?
        
           | davidmurdoch wrote:
           | The current published version is fine, thanks for trying it!
           | I'm working on a new release, and haven't been able to get
           | the Apple build to work. Lots has changed since the last
           | release, certainly on my side and I presume also on Apple's.
           | 
           | I've manually tested on Monterey.
        
             | angulardragon03 wrote:
             | Ah ok, makes sense.
             | 
             | I'd recommend you check out Apparency [1], which can
             | inspect .app bundles and show you what's up with the
             | signing on your bundle. It looks like you include a few
             | frameworks (which also need to be signed), so maybe you
             | have components missing signatures/with mismatched
             | signatures.
             | 
             | [1] https://mothersruin.com/software/Apparency/
        
               | davidmurdoch wrote:
               | This looks like it will be immensely useful! Thanks!
        
               | DueDilligence wrote:
               | [dead]
        
         | jamil7 wrote:
         | Can you share the app? Maybe someone here can tell what the
         | issue is. I'm able to distribute outside of the mac AppStore
         | without users needing to jump through any hoops or right click
         | etc.
        
           | stouset wrote:
           | [flagged]
        
             | davidmurdoch wrote:
             | You are a liar.
        
               | greggsy wrote:
               | There's an opportunity to remedy your problem but I don't
               | think this is the best way to leave that offer open.
        
               | smoldesu wrote:
               | There is no 'open offer' to consider. The _only thing_
               | the grandparent did was fabricate a lie, and the only
               | reasonable response is to call them out on it.
               | 
               | Their comment was against HN guidelines (Assume good
               | faith.), there's no reason to chide someone for calling
               | them out on that.
        
               | davidmurdoch wrote:
               | They just made something up about me that is not true.
               | They've insulted my integrity. They are a liar. No one in
               | good faith can disagree.
        
           | [deleted]
        
           | davidmurdoch wrote:
           | It's an Electron app AND blockchain related; hackernews's two
           | favorite things to hate. I don't expect much love from this
           | crowd. Heh.
           | 
           | It's certainly either something I'm doing wrong, or a big in
           | the software I'm using to automate signing, notification and
           | stapling.
           | 
           | Here's the issue I opened on the software I'm using to
           | automate: https://github.com/electron-userland/electron-
           | builder/issues... that issue kinks to the PR that adds the
           | automation.
           | 
           | It's a non-trivial thing to test, since it involves so many
           | secrets and the notarization step can take over an hour, so I
           | don't expect anyone here to actually want to look into it.
           | 
           | My original comment really was just venting my frustration,
           | not a cry for help (but I might be crying soon if I cant get
           | to the bottom of this!).
        
             | mike_hearn wrote:
             | You could try experimenting with Hydraulic Conveyor [1]. I
             | built it originally due to the frustrations involved in
             | distributing P2P software during my old Bitcoin days so you
             | won't get any hate from me about that ;)
             | 
             | Conveyor can package Electron apps and also do all the Mac
             | specific stuff from any platform including Linux. So it can
             | sign, notarize and staple the app itself, also bundling
             | Sparkle updates as it goes. We're listed on the Electron
             | website these days. You may have more luck with it. There's
             | a Discord channel for help too if you get stuck.
             | 
             | [1] https://hydraulic.dev/ (disclosure: my company)
        
               | davidmurdoch wrote:
               | Thanks for this! I've made a new issue to look into
               | switching. It'd be great to find something that Just
               | Works(tm)!
        
             | jamil7 wrote:
             | Thanks for the response. The output of `spctl` on your
             | latest build (2.7.2, downloaded from the build artefacts
             | section of Github Actions gives me the following:
             | 
             | /Applications/Ganache.app: rejected (invalid destination
             | for symbolic link in bundle) origin=Developer ID
             | Application: ConsenSys AG (48XVW22RCG)
             | 
             | I see you're also migrating to Github Actions for this
             | particular release and that the notarization process was
             | working correctly on your previous CI/CD? I guess there has
             | to be an issue with the new environment here or the way
             | you're building it now.
        
               | dunham wrote:
               | Probably the five links to /usr/local/bin/python3 in
               | node_modules. Does the app need node_modules bundled?
        
             | terhechte wrote:
             | I'm on mobile, so short help: in one of my projects I'm
             | building a binary in Rust and then using Xcode to notarize
             | it by replacing the binary of another shell app that I'm
             | Bildung in Xcode. This works really well. Check out the
             | description here: https://github.com/terhechte/Ebou
        
               | davidmurdoch wrote:
               | Thanks! I'll take a look at the specifics tomorrow.
        
         | bitwize wrote:
         | Apple has developed the first and _only_ generally available
         | "evil maid" resistant computer systems. Part of participating
         | in this secure ecosystem involves more effort on your part to
         | comply with the security requirements.
         | 
         | Or you can just develop for vulnerable-as-all-getout Linux or
         | Windows systems. Your choice.
        
           | realusername wrote:
           | > Apple has developed the first and only generally available
           | "evil maid" resistant computer systems.
           | 
           | If you exclude themselves from the threat model of course,
           | which I don't see why you would
        
             | acdha wrote:
             | Those are separate threats. You must accept the risk of
             | your hardware manufacturer being compromised but that's
             | very different from also accepting the risk that any third-
             | party with brief physical access can compromise your
             | device.
        
           | anthk wrote:
           | You are deluded. Once they get physical access, you are out
           | of luck.
        
             | watermelon0 wrote:
             | Do you have any evidence to support this?
             | 
             | macOS @ M1 boot process looks similar to that of iOS
             | devices: https://support.apple.com/en-
             | gb/guide/security/secac71d5623/...
             | 
             | Under the assumption that SIP is not disabled, and computer
             | doesn't have any 3rd party kernel extensions installed
             | (both of which are safe to assume for most people), it's
             | close to impossible to inject something in the boot chain.
             | 
             | ---
             | 
             | I think the best possible option might be to replace the
             | keyboard with the one with a hardware keylogger, and record
             | the actual password.
        
               | anthk wrote:
               | Yes, that option with the keyboard would be the easiest
               | option. See? The point on encrypting your whole disk is
               | not to avoid tampering, but to lock your machine in
               | public places and be sure that no one can access your
               | data upon placing that disk in another machine, or even
               | trying to boot it.
        
             | kaba0 wrote:
             | As always, security always operates with some threat model
             | in mind. Of course some government-level agency with
             | physical access and any amount of money to spend could
             | likely get access to your device (though the usual $5
             | wrench is probably still the "better" way) at the price of
             | a (or a few) zero days. But you are likely not a key person
             | in toppling a government and it would be a giant waste on
             | their parts.
             | 
             | The threat model the general populace faces ranges from
             | something as mundane as your ex wanting to extract
             | something from your device to basically being the know-all
             | key to every important document, photo and data you might
             | have. I think I can safely say that under this
             | circumstances not even physical access poses a real threat
             | to the device's security -- it is tamper-proof to replacing
             | most critical parts and the boot-sequence is
             | cryptographically secured. Biometric data is not stored in
             | software, so not even that can be spoofed.
        
           | BiteCode_dev wrote:
           | Having an evil made fidling my computer is not a big worry in
           | my life. Not being a slave to the gafams is.
        
             | acdha wrote:
             | It's not just the evil maid but what happens if your device
             | is stolen (or scanned by the police), or you run malware by
             | mistake and want to restore it to a trustworthy state. Most
             | people should worry about those more than the evil maid
             | scenarios.
        
           | davidmurdoch wrote:
           | If security was a spectrum Apple has gone into ultra-violet.
           | If The Onion did tech jokes there'd be a headline that reads:
           | The iBrick - it doesn't work, but at least it's hacker-proof!
           | 
           | But thanks for reminding me I have a choice, which I actually
           | do not.
        
           | smoldesu wrote:
           | > the first and only generally available "evil maid"
           | resistant computer systems.
           | 
           | "resistant" is a pretty low bar to pass. Do we get to include
           | the Nintendo Switch for having eFuses?
        
       | sam0x17 wrote:
       | Hah, my minecraft region protection mod used to be called
       | XProtect
        
         | shepherdjerred wrote:
         | I love seeing all of the fellow HN users who participated in
         | the Minecraft server community
        
       ___________________________________________________________________
       (page generated 2023-09-04 23:01 UTC)