Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Are you implying you (or anybody) can somehow verify the intentions of any macOS app?

You should publish.



I can verify that running random executables you receive in email is a bad idea, as is downloading apps from untrusted sources. I don't think this is groundbreaking or worthy of publishing in a reputable journal.


Recently CCleaner was hacked to distribute infected versions through it's updating mechanism.

It sure would be nice if gaining a foothold on my computer didn't instantly mean gaining complete control over al my credentials.


For sure, Apple should fix this bug, and presumably they will. Some basic app hygiene greatly reduces the risk though.


Encrypt your credentials at rest and aggressively purge them from memory when any are decrypted.


The idea (and assumption) was that the macOS Keychain app does encrypt my credentials at rest (and allows access only after express user permission).


You've missed the point. "Trusted", signed applications can do the same things this PoC did.


Thats a straw man argument the comment you are replying to specifically said "verify the intentions of any macOS app".

If you disagree with his argument perhaps you could give an actual counter argument?


That comment itself was a straw man. Obviously the answer is no, no one can solve the halting problem and verify the intentions of any arbitrary app.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: