Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

pedzsan

macrumors 6502
Original poster
May 22, 2016
306
121
Leander, TX
Slash Dot has an article about how a package can bypass GateKeeper. I know what GateKeeper is but I'm having trouble understanding the practical implications. Please tell me where I'm confused.

For me to be affected by this, I first need to download the malware package. This implies that either the website I'm going to has been compromised or I'm going to random strange web sites.

For the case where the site has been compromised already, then all bets are off anyway.

In the case that I'm downloading random things from random sites, then I'm likely to be infected by something anyway so who cares if the package is clever about infecting me or not. I've already dropped my guard and am open to attack.
 
The novelty is that it breaks the presumption that any program downloaded through Safari will prompt a Gatekeeper alert. I am guessing that the average user will not pay attention and rely on this functionality. People who are cautious might not download let alone open untrusted files in the first place.
 
  • Like
Reactions: pedzsan
Thank you. It wasn't clear to me. So the warning pop up box is bypassed... I can see how that would be note worthy.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.