Login Register






The issue regarding searched threads returning 404s has been fixed. My apologies. - NekoElf
Thread Rating:
  • 0 Vote(s) - 0 Average


[Sentinel One] Macs aren't safe 'by design' filter_list
Author
Message
RE: [Sentinel One] Macs aren't safe 'by design' #3
(01-10-2022, 08:17 AM)Bricker Wrote: And let us not also forget the 2014 Goto Fail bug. Taught a whole bunch of people the importance of using brackets at the cost of clean code
If I'm understanding this correctly, Apple relies heavily on code-signing and built-in 'soft-fail' functions. The go-to fail bug exploiting a known (by Apple) code error with duplicate lines. This was patched soon after. The certificate revocation exploit was used for introduction of ransomware to devices through Apple's failed use of some of that same code-signing error from before, with tweaks to delivery and execution, but still similar. The code is not public so it can't be audited independently or peer-reviewed. The exploits are harder to patch and are therefore sought after by malware development campaigns and threat actors. You can't fix what you can't see.
(This post was last modified: 01-10-2022, 08:31 AM by ConcernedCitizen.)
ed25519/0x21AB6B6A6CB2C337
C87D87466FD205945CF10A3821AB6B6A6CB2C337

Reply





Messages In This Thread
RE: [Sentinel One] Macs aren't safe 'by design' - by ConcernedCitizen - 01-10-2022, 08:31 AM



Users browsing this thread: 5 Guest(s)