4.9 • 696 Ratings
🗓️ 16 August 2023
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Wednesday, August 16th, |
0:03.1 | 2003 edition of the Sandt and Stormsenders Stormcast. My name is Johannes Ulrich, |
0:10.0 | and then I'm recording from Jacksonville, Florida. Let's start today a little bit with |
0:16.3 | Apple security in particular macOS Ventura, which did introduce a background task manager. |
0:23.9 | The goal with background task manager was to alert the user if a process sort of becomes |
0:29.9 | persistence, basically runs in the background. And the idea behind this is if you have a process |
0:36.7 | that all of a sudden keeps running in the background, |
0:39.1 | there's a little pop-up, the alerts you of it. |
0:41.5 | If you just install some new software, well, then you sort of know, okay, I know why this is running. |
0:46.6 | You can discard the warning. |
0:48.7 | The problem is that apparently this particular feature doesn't really work as well as it's supposed to work. |
0:55.6 | And Patrick Wardle, who has had a rich history in finding flaws in macOS and iOS, has presented |
1:03.5 | at DefCon, some of the methods that can be used here. |
1:08.1 | Out of the three different bypass methods at Wardle found, one requires root access, |
1:14.4 | that's still potentially a problem because, well, that's sort of exactly one of the attacks |
1:19.2 | that the background manager is supposed to protect yourself from. |
1:24.2 | But there are two others that do not require route access and could still bypass |
1:31.3 | any persistence notification by the background task manager. Patrick has been in communication |
1:38.0 | with Apple about sort of the issues with the background task manager. Now, the specific flaws here haven't been disclosed to Apple, |
1:47.9 | but the overall sort of problems that Patrick found, |
1:51.6 | not clear if there will be a patch coming from Apple anytime soon |
1:57.1 | or maybe something like with the next macOS release, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.