Researchers at Okta Security have stumbled across something big. Recently, they discovered a flaw in Apple's OS that would have allowed hackers to completely undermine Apple's code signing process.
Alpha Omega’s Commitment During COVID-19. On-Site DBS Support Services - Case Report. New Brain Research Center in Guangzhou. MOTORIZED COMMUTATOR THAT PREVENTS CABLE TANGLING IN FREE MOVING SET-UP. Reem and Imad's Younis journey to success. Amaya defines two kinds of keyboard shortcuts for Mac OS X: shortcuts using standard Apple modifier keys (ex. Cmd+C to copy the selection) and shortcuts using sequences (ex. Ctrl-t Ctrl-t to create a table). As Mac OS X users are not familiar with shortcut sequences in menu entries, only standard shortcuts are shown by default.
While at first glance that doesn't sound so bad, the implications are terrifying. In a nutshell, code signing uses cryptographic 'signatures' to verify and validate code. If code bears the digital signature, it is considered trusted. If it's trusted, then it's given an automatic free pass, straight into the heart of any system. No danger is too much mac os.
Unfortunately, this flaw in Apple's code signing process dates back more than a decade. It was only recently discovered, and purely by chance at that.
An extensive forensic analysis has turned up no evidence suggesting that this exploit was ever used for nefarious purposes, which is the one silver lining in all of this.
Upon discovering the flaw, Okta personnel reached out to Apple and other vendors who could have been impacted by the flaw, including tech giants like Google, Facebook and also smaller players like VirusTotal, Objective Development, Yelp, and Carbon Black.
Apple moved swiftly and has since fixed the issue, so this one can be considered a bullet dodged.
Josh Pitts, an Okta engineer, sums the issue up:
Alpha Omega Marco Island
'Different types of tools and products use code signing to implement actionable security; this includes whitelisting, antivirus, incident response and threat hunting products. To undermine a code signing implementation for a major OS would break a core security construct that many depend on for day to day security operations.'
Alpha Omega Masonry Bangor
A completely fair assessment. Thankfully (at least in this particular case), although the issue was hiding in plain sight, it does not appear to have been exploited before being fixed. We won't always be so lucky.