@csoghoian @JZdziarski @mattblaze @micahflee Xcode downloads over plain HTTP. how do I know it's not the CIA?https://twitter.com/ageis/status/575345440356450304 …
When you tweet with a location, Twitter stores that location. You can switch location on/off before each Tweet and always have the option to delete your location history. Learn more
@csoghoian @JZdziarski @mattblaze @micahflee Xcode downloads over plain HTTP. how do I know it's not the CIA?https://twitter.com/ageis/status/575345440356450304 …
@ageis @csoghoian @JZdziarski @micahflee The package is signed, no?
@mattblaze @csoghoian @JZdziarski @micahflee yeah, must be. that's all underneath the surface so I dunno, I don't know much about App Store.
@ageis @csoghoian @JZdziarski @micahflee But if your machine was compromised to accept some additional signatures, who knows...
@mattblaze @ageis @csoghoian @JZdziarski yes the package is signed--all apps from App Store are signed by an Apple key
@mattblaze @ageis @csoghoian @JZdziarski downloading over http makes censorship attacks easy tho, preventing a user from downloading an app
@micahflee then you could force target to get it from a compromised channel. the developer just wants Xcode, they're not verifying anything
@micahflee I imagine that a lot of ops that deliver compromised binaries are dirty like that and make use of multiple vectors.
.@ageis @matthew_d_green the binaries are signed, though. Right?
.@ageis @matthew_d_green Uh, guys? Should I be worried that Xcode doesn't have a valid signature?pic.twitter.com/naTpVpX3Wa
@brian_reiter @ageis @matthew_d_green To be even more clear:pic.twitter.com/2aGHdpToRb
@bertrandmt @ageis @matthew_d_green what does `--no-strict` do? It isn't documented in the man page for codesign(1).
@brian_reiter @ageis @matthew_d_green or it enables the special CIA code path where codesign pretends that your signature is okay…
@ageis @hackerfantastic the binaries are code signed and update packages also. doesn't mean ppl verify them ehehehe
@ageis But is it sigchecked separately? I know this happens on iOS but don't know about Mac.
@ageis @matthew_d_green Given the closed garden approach to distribution in the app store, I'm not sure what the big deal is.
@ageis @matthew_d_green Even if an app is modified at the developer's site, it has to go through Apple review before being published.
@bertrandmt @ageis Unless it's an enterprise app.
@ageis @matthew_d_green dude that’s why God invented sha. Lol
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.