Previously Downloaded OS X Installers No Longer Work: http://mjtsai.com/blog/2016/03/03/previously-downloaded-os-x-installers-no-longer-work/ … #mjtsaiblog
-
-
@pmod What exactly is the security angle here?0 replies 0 retweets 0 likes -
@mjtsai Code signing with expiring certs? Have you not yet considered that some of the recent hiccups are related to compromised certs??0 replies 0 retweets 0 likes -
@pmod In what scenario would it be beneficial securitywise for Apple to disable their own installers that users downloaded from their store?0 replies 0 retweets 0 likes -
@mjtsai Because they had to retire a compromised certificate??0 replies 0 retweets 0 likes -
@pmod Sorry, not following you. Which certificate do you think was compromised? And how could that endanger the installer I already have?0 replies 0 retweets 0 likes -
@mjtsai Contemporary cert validation is a security feature, yeah?0 replies 0 retweets 0 likes -
@pmod In general, yes. But in this case I downloaded Apple’s installer from Apple’s server over HTTPS. So how is code signing helping me?0 replies 0 retweets 0 likes -
@mjtsai But I do strongly feel that there's more here broadly than has been publicly disclosed. Sometimes certs need to be forcibly rotated.0 replies 0 retweets 0 likes
@pmod Based on what? Didn’t this certificate expire on the normal date as planned?
-
@mjtsai Yes, and that’s good. Certs need limited lifetimes because of their security role. It’s credential rotation!0 replies 0 retweets 0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Michael Tsai
Peter M. O’Donnell