Slashdot Mirror


Apple's Gatekeeper Still Broken (csoonline.com)

itwbennett writes: This weekend, Apple security expert Patrick Wardle will detail a vulnerability in Apple's Gatekeeper that makes it possible to bypass the anti-malware defense. This is the same vulnerability that was disclosed last April, which Apple said it patched later. Wardle was able to easily bypass Apple's fixes. He says "all Apple did was blacklist the signed apps he was abusing, but didn't fix the underlying issue, which is that, essentially, Gatekeeper functions as a guard that doesn't check" software already on the whitelist.

4 of 80 comments (clear)

  1. Doesn't matter. by Anonymous Coward · · Score: 4, Insightful

    People will still flock to Apple and buy the shit out of it. And Apple knows it.

    1. Re:Doesn't matter. by The-Ixian · · Score: 5, Insightful

      Yeah no kidding.

      I don't personally like Apple the company. I just think they are too much about marketing hype. I was also not a fan of Steve Jobs personally.

      But I still will recommend a Mac to someone when appropriate.

      Computers and operating systems are tools not ideologies. Use the best tool for the job.

      I won't be buying Apple products any time soon, but that is because there are tools out there that work better for me.

      --
      My eyes reflect the stars and a smile lights up my face.
    2. Re:Doesn't matter. by ComputerGeek01 · · Score: 3, Insightful

      Windows? Which is taking away control of your computer and sending analytics to the mother ship whether you agree or not?

      As opposed to Apple where you never had any control over any of their devices to begin with? Apple IS the worst of all possibilities; they are overpriced, have ZERO support options outside of the "Mac Geniuses", nothing is documented and there is no ability to customize their software or tweak the system performance. You might be as happy as a pig in shit with a device that just does one thing adequately right out of the box and is useless for anything else, but this is a site for engineers; not social runoff that thinks it's too smart for Facebook.

  2. Re:Lack of interest based security by dgatwood · · Score: 3, Insightful

    In any mode, you can run an unsigned or non-Apple-signed installer or app by control-clicking on it and choosing "Open".

    --

    Check out my sci-fi/humor trilogy at PatriotsBooks.