Previously Downloaded OS X Installers No Longer Work: http://mjtsai.com/blog/2016/03/03/previously-downloaded-os-x-installers-no-longer-work/ … #mjtsaiblog
@pmod Sorry, not following you. Which certificate do you think was compromised? And how could that endanger the installer I already have?
-
-
@mjtsai Contemporary cert validation is a security feature, yeah? -
@pmod In general, yes. But in this case I downloaded Apple’s installer from Apple’s server over HTTPS. So how is code signing helping me? - View other replies
-
@mjtsai Your particular case of having gotten it over a secure channel cannot securely confer trust to the underlying OS. -
@pmod Right, but in this particular case, how would I be worse off if it weren't signed? (Like installers used to not be.) -
@mjtsai Right, so back to the top – signing installation provides critical assurance for provenance & tampering. This is essential.
-
-
-
@mjtsai The installer you have is signed with a cert; OS X phones home to validate the cert; cert is cancelled; installer doesn’t work. -
@pmod Everything I’ve seen says that in this case it just expired, was not compromised. -
@mjtsai To be clear, I am not excluding that their operational discipline needs dramatic improvement.
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Michael Tsai
Peter M. O’Donnell