Previously Downloaded OS X Installers No Longer Work: http://mjtsai.com/blog/2016/03/03/previously-downloaded-os-x-installers-no-longer-work/ … #mjtsaiblog
@pmod In general, yes. But in this case I downloaded Apple’s installer from Apple’s server over HTTPS. So how is code signing helping me?
-
-
@mjtsai But I do strongly feel that there's more here broadly than has been publicly disclosed. Sometimes certs need to be forcibly rotated. -
@pmod Based on what? Didn’t this certificate expire on the normal date as planned? -
@mjtsai Yes, and that’s good. Certs need limited lifetimes because of their security role. It’s credential rotation!
-
-
-
@mjtsai Your particular case of having gotten it over a secure channel cannot securely confer trust to the underlying OS. -
@pmod Right, but in this particular case, how would I be worse off if it weren't signed? (Like installers used to not be.) -
@mjtsai Right, so back to the top – signing installation provides critical assurance for provenance & tampering. This is essential.
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Michael Tsai
Peter M. O’Donnell