4.9 • 696 Ratings
🗓️ 29 June 2020
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Monday, June 29th, 2020 edition of the Santernut Storm Center's Stormcast. |
0:07.2 | My name is Johannes Ulrich. |
0:08.6 | And I'm recording from Jacksonville, Florida. |
0:12.7 | One of the big events last week, of course, was Apple's developer conference and the reveal of the next versions of Mac OS and iOS. |
0:24.4 | Now, these developer conference, keynotes and such always highlight the features. |
0:30.6 | I want to focus a little bit on some of the security features, |
0:35.5 | and I'm leaning heavily here on a blog post published by Sentinel 1. |
0:42.1 | So I recommend if you're interested in some of these details, take a look at their blog post. |
0:47.7 | First of all, one thing that sort of caught my attention was kernel extensions. |
0:52.1 | Kernel extensions have always been sort of on the way out in |
0:56.7 | Mac OS. Now, you may have seen, for example, pop-ups that tell you, hey, that kernel extension |
1:03.2 | may no longer be support in a future. And then, of course, you had to approve individual kernel |
1:08.9 | extensions. Well, the good news here is that |
1:11.4 | in macOS 11, Big Sur kernel extensions will remain to exist. So they appear to continue to be |
1:20.3 | working the way they work now, where you have to approve them as you install them. Now, in the last |
1:27.1 | major update to macOS, Apple made this change to |
1:31.7 | how data is saved in the disk by splitting it into a system volume and a data volume where it |
1:38.5 | wasn't possible to change a system volume. It was a read-only volume. In order to make changes, you had to reboot and |
1:46.3 | turn it into a live file system, then make your changes. This is actually going to get more |
1:53.7 | difficult in macOS 11. The change here is that the system volume will not just not be writable, it will also be |
2:03.0 | cryptographically signed. So even if you manage to make a change to the system volume, well, it |
2:09.8 | won't work because the digital signature will not work out. However, you can disable the |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.