Post

Replies

Boosts

Views

Activity

Comment on Gatekeeper and binaries rejected by spctl
I had not appreciated all the nuances surrounding the tightening down what had originally been a fairly open system. I can imagine there are a lot of edge cases surrounding legacy code, code running in isolated networks, running open source code downloaded from the network, etc. (Part of me would like something like iPhone's Lockdown mode for my Mac.)
May ’23
Comment on Endpoint code signature failure
A note of warning: I booted back into Monterey (I have both Monterey and Ventura beta in different volumes on the same Mac), and amfi_get_out_of_my_way setting of 0x1 is set there too. That is, setting amfi_get_out_of_my_way in Ventura affects Monterey (same Mac, different volumes). Before leaving Ventura and booting back into Monterey, I now set amfi_get_out_of_my_way to 0x0. Hopefully that keeps Monterey protected when I am working in that OS.
Jul ’22