Security Bite: Apple (finally) making it harder to override Gatekeeper is a telling move

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


Last week, Apple confirmed that users on macOS Sequoia will no longer be able to Control-click to override Gatekeeper to open software that isn’t signed or notarized by the company. This was a slight change with what I believe will have a significant impact. It also gives us a glimpse into what might happen behind the scenes at Apple as Mac malware gets more clever and the amount of it reach all-time highs.

I’ve always been baffled by how easily any non-sophisticated Jonny Appleseed user could bypass Mac’s two best security features (Gatekeeper and XProtect) in just two clicks.

This typically happens when a user attempts to download unsigned software, like a pirated application. When they double-click to open it, macOS will present an error message stating, “[application.pkg] can not be open because it is from an unidentified developer.” From here, the user might let out a quick sigh and Google the problem only to find they just have to right-click the package and hit “Open.”

I understand it’s a bit of a catch-22 to say that “non-sophisticated” users would know how to bypass macOS Gatekeeper and the XProtect suite, let alone find and download pirated software. However, what if they thought they were installing a legitimate app, and that’s how it instructed them to open it?

Malware authors are more clever than ever. One of the latest trends is cloning real applications, often productivity apps like Notion or Slack, and injecting malware somewhere in the code. Authors then create install screens like the one below, instructing the user to right-click and open the malware to get around Gatekeeper. The crazy part is that sometimes users will go on to use these applications for quite some time and never know their system has been infected. Persistence is key for cybercriminals.

I wouldn’t put it past my 79-year-old grandmother to be able to do this.
Image of Shlayer malware from Jamf.

Now in macOS Sequoia, users will need to independently review the app’s security details in System Settings> Privacy & Security before it is allowed to run. It’s great to finally see Apple taking proactive steps to encourage users to review what they’re installing.

However, is this an indication of how bad malware is getting on the platform? Maybe, but it could also be a move to encourage more developers to submit apps for notarization.

The facts are: In 2023, we witnessed a 50% YoY increase in new macOS malware families. Additionally, Patrick Wardle, founder of Objective-See, told Moonlock Lab that the number of new macOS malware specimens increased by about 100% in 2023 with no signs of a slowdown. And just a few months back, Apple pushed its largest-ever XProtect update with 74 new Yara detection rules.

Regardless, I’ve once brought this up to an employee internally and was not met with much interest. So, I’m glad someone changed their mind, no matter the reason.

More: Apple addresses privacy concerns around Notification Center database in macOS Sequoia


Add 9to5Mac to your Google News feed. 

FTC: We use income earning auto affiliate links. More.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Bored Tesla Cybertruck owners will be able to play Cyberpunk 2077, and the whole Steam roster thumbnail

Bored Tesla Cybertruck owners will be able to play Cyberpunk 2077, and the whole Steam roster

Reviews, News, CPU, GPU, Articles, Columns, Other "or" search relation.3D Printing, 5G, Accessory, AI, Alder Lake, AMD, Android, Apple, ARM, Audio, Biotech, Business, Camera, Cannon Lake, Cezanne (Zen 3), Charts, Chinese Tech, Chromebook, Coffee Lake, Comet Lake, Console, Convertible / 2-in-1, Cryptocurrency, Cyberlaw, Deal, Desktop, E-Mobility, Education, Exclusive, Fail, Foldable, Gadget, Galaxy Note, Galaxy S,…
Read More
CES 2022: The first quad-band gaming router in the world comes from ASUS!  It's called the ROG Rapture GT-AXE16000 and comes with an aggressive design thumbnail

CES 2022: The first quad-band gaming router in the world comes from ASUS! It's called the ROG Rapture GT-AXE16000 and comes with an aggressive design

Fără doar și poate, laptopurile și produsele de gaming din seria ROG de la ASUS au fost la înălțime în cadrul CES 2022. Au fost dezvăluite o mulțime de astfel de notebook-uri puternice, monitoare, dar și un nou router de gaming din seria ROG. Modelul Rapture GT-AXE16000 este primul router quad-band din lume, aduce conectivitate…
Read More
Capcom wants PC as the main platform! thumbnail

Capcom wants PC as the main platform!

Caso não saiba, até aqui, os estúdios Japoneses sempre preferiram desenvolver para as consolas, deixando o PC num segundo plano, quase sempre um pouco distante. Curiosamente, a Capcom é um dos grande exemplos desta estratégia! Afinal de contas, durante muitos (mesmo muitos!) anos, a gigante Japonesa decidiu lançar versões sempre um bocado manhosas para o…
Read More
The new Astro Bot PS5 controller is pretty dang adorable thumbnail

The new Astro Bot PS5 controller is pretty dang adorable

Sony’s currently prepping a Mario-like adventure game for PS5 that’s inspired by its cute little Astro Bot mascot character. That title arrives on September 6 and looks like an absolute blast. Taking a page from Nintendo, the company also just announced a themed DualSense controller to commemorate the release. It's pretty dang adorable.The Astro Bot
Read More
Windows 11: How to create an ISO image that bypasses the TPM thumbnail

Windows 11: How to create an ISO image that bypasses the TPM

A Media Creation Tool é uma ferramenta muito conhecida da Microsoft que permite descarregar os ficheiros ISO do Windows 10 e criar um disco de instalação, tanto em DVD como num PenDrive. Ora sempre que a Microsoft lança uma nova versão do Windows, atualiza a Media Creation Tool. Assim, permite que os utilizadores obtenham os…
Read More
Nvidia could introduce RTX 3090 SUPER, RTX 3070 Ti 16GB and RTX 2060 12GB in January thumbnail

Nvidia could introduce RTX 3090 SUPER, RTX 3070 Ti 16GB and RTX 2060 12GB in January

Prema navodima dojavljivača hongxing2020, Nvidia će početkom sledeće godine predstaviti RTX 3090 SUPER grafičku kartu. Pored ovog GPU-a, biće objavljen i RTX 2060 12GB (osveženi Turing GPU iz srednjeg segmenta). Izveštaj pominje da će Nvidia osvežiti i RTX 3070 Ti sa 16GB memorije.To znači da će Nvidia nadograditi tri grafičke karte iz različitih segmenata. Nije…
Read More
Index Of News
Total
0
Share