Thursday, July 6, 2023

How Ventura Checks the Security of Apps and Tools

Howard Oakley:

When you first run an app that you’ve just downloaded to your Mac from a source that results in it being put into quarantine, the following has occurred[…]


Some or all of those can also be triggered when a known app, which has already passed its first run tests, is run from a previously unknown path, when it’s put back into quarantine, or when it remains stuck in app translocation.


One situation where repeated security checks could have significant impact is when repeatedly executing a third-party command tool in a script. […] Provenance tracking thus appears to overcome overhead without compromising security.


