{"id":38696,"date":"2023-03-07T14:51:11","date_gmt":"2023-03-07T19:51:11","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=38696"},"modified":"2023-03-07T14:51:11","modified_gmt":"2023-03-07T19:51:11","slug":"how-troubleshooting-has-changed-with-macos-security","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2023\/03\/07\/how-troubleshooting-has-changed-with-macos-security\/","title":{"rendered":"How Troubleshooting Has Changed With macOS Security"},"content":{"rendered":"<p><a href=\"https:\/\/eclecticlight.co\/2023\/03\/06\/how-troubleshooting-has-changed-with-macos-security\/\">Howard Oakley<\/a>:<\/p>\n<blockquote cite=\"https:\/\/eclecticlight.co\/2023\/03\/06\/how-troubleshooting-has-changed-with-macos-security\/\">\n<p>With the guaranteed integrity of the SSV and cryptexes on IT2 and AS models, reinstalling the same version of macOS has no effect on the great majority of macOS. Similarly, installing an older version and updating it to the current one can only produce exactly the same result as installing the current version directly.<\/p>\n<p>Two procedures might be worth considering, though: replacing the latest version of macOS with an older one, in an attempt to clear new problems, and installing macOS and migrating to it from backups. Both of these can also make problems worse as they rely on migration, which could restore other components responsible for a problem, or those incompatible with the version of macOS being installed.<\/p>\n<p>[&#8230;]<\/p>\n<p>Just as successfully booting macOS is verification of its integrity, so launching an app without a code signature error verifies the code within that app. That applies to all Macs running Ventura, where replacing a misbehaving app with a fresh copy is likely to be pointless.<\/p>\n<\/blockquote>\n<p>Most non-bug problems these days seem to be caused by bad data files or file permissions.<\/p>\n\n<p><a href=\"https:\/\/eclecticlight.co\/2023\/03\/07\/do-venturas-signature-checks-work\/\">Howard Oakley<\/a>:<\/p>\n<blockquote cite=\"https:\/\/eclecticlight.co\/2023\/03\/07\/do-venturas-signature-checks-work\/\">\n<p>Every time you run an app or other executable code, such as a command tool, those first run checks are now repeated, although not quite in the same depth, and with slightly greater tolerance for minor errors, it appears.<\/p>\n<p>[&#8230;]<\/p>\n<p>This shows how Apparency reports an app I crafted to check whether macOS had fixed a longstanding vulnerability in signature checking. Code signatures apply to different architectures, including Intel and Apple silicon. For some time, Gatekeeper checks didn&rsquo;t cover all architectures correctly, a failure which could have been exploited. This crafted version of my app Cormorant contains two conflicting signatures, as recognised by Apparency.<\/p>\n<p>[&#8230;]<\/p>\n<p>Certificate expiry dates are a little more complicated than you might expect, and depend on the type and purpose of certificate. For ordinary app and other executable signing, a Developer ID <em>Application<\/em> certificate is used, and remains valid for Gatekeeper even though the certificate has long expired. The crucial date in this case is when the app was signed: so long as the Developer ID Application certificate was valid at that time, then Gatekeeper will accept the certificate many years later.<\/p>\n<p>That isn&rsquo;t true of certificates used to sign Installer packages, which are a different type, Developer ID <em>Installer.<\/em><\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/11\/07\/ventura-app-management\/\">Ventura App Management<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/09\/02\/why-xcode-tools-are-slow-after-reboot\/\">Why Xcode Tools Are Slow After Reboot<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2019\/08\/28\/installing-old-versions-of-macos\/\">Installing Old Versions of macOS<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2016\/03\/03\/previously-downloaded-os-x-installers-no-longer-work\/\">Previously Downloaded OS X Installers No Longer Work<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Howard Oakley: With the guaranteed integrity of the SSV and cryptexes on IT2 and AS models, reinstalling the same version of macOS has no effect on the great majority of macOS. Similarly, installing an older version and updating it to the current one can only produce exactly the same result as installing the current version [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2023-03-07T19:51:14Z","apple_news_api_id":"7ae96e91-6076-4c59-9d82-a168550e56b1","apple_news_api_modified_at":"2023-03-07T19:51:14Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/AeulukWB2TFmdgqFoVQ5WsQ","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[2355,466,75,465,30,2223,2277],"class_list":["post-38696","post","type-post","status-publish","format-standard","hentry","category-technology","tag-apparency","tag-codesigning","tag-developertool","tag-gatekeeper","tag-mac","tag-macos-13-ventura","tag-signed-system-volume-ssv"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/38696","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=38696"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/38696\/revisions"}],"predecessor-version":[{"id":38697,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/38696\/revisions\/38697"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=38696"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=38696"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=38696"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}