@landonfuller @siracusa FWIW, it’s not particularly hard to get a kext signing cert, all we had to do write a couple of lines why we need it
-
-
- View other replies
-
@pajp Someone I know working on a Mac OS X kernel internals book was refused a kext signing cert; the problem is: Apple picks the winners. -
@landonfuller it’s a problem if Apple also takes the tools away to choose the trusted CA certificate roots; do they? -
@pajp Yeah; unlike MS' signing requirements, Apple themselves is the only trusted CA root. -
@landonfuller source? I thought kext codesigning checks use the SecAssessment trust policy modifiable with spctl. If not, it’s pretty crappy - View other replies
-
@pajp What good does spctl do normal users if the default CA list is constrained to 1? Adding a CA is a bigger deal than a kext - View other replies
-
@landonfuller someone could set up a separate CA with easy-to-install app that sets it up, if there would be demand for it -
@pajp Not seeing how this is an optimal approach to a healthy creative exploratory platform; this gives Apple the leverage to yank the rug. - Show more
-
-
-
@landonfuller kernel space programming is extremely hard to get right, dangerous for stability. I’d love these use cases solved without it. -
@mgorbach It's impossible to anticipate all use-cases, and we've already seen what an attempt looks like on iOS. - View other replies
-
@landonfuller and add the highest-value APIs. Think FUSE. Kext programming hoops scare me less if there is a concerted API effort. -
@mgorbach Strict restrictions scare me regardless; if anyone has a clever idea or a unique requirement, they can't even explore it. - View other replies
-
@landonfuller would it bother you less if there was a way to “dev” or “enterprise”-sign kexts? - View other replies
-
@mgorbach I'd rather err on the side of open creativity that doesn't require vendor pre-approval, even if that means some sharp edges.
-
-
@landonfuller hrm. Arbitrary signing is good, IMO. From user controllable root cert set? Great! Strict vendor gatekeeping? Not so much. -
@landonfuller@siracusa another possibility is them realizing real security requires a kernel rearchitecture around capabilities (ala EROS). -
@landonfuller@0xced kext is also a perfect way to compromise security big time. -
@landonfuller@siracusa After having living nightmares with kernel_task running amok, I'm kinda glad as a user. -
@landonfuller all your examples are valid, but wouldn’t you rather there be userspace API to build those?
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Landon Fuller
Rasmus Sten
Michael Gorbach
Phil Holland
Laurent Giroud
Oleg Andreev
Halex Pereira
Dad