• Repple (she/her)@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      20 days ago

      Yes, and additionally if I’m reading this correctly, this attack would only work for people whose security settings are to run any signed code from trusted developers. One of the standard options is trusting only App Store distributed code for which this attack would not work

      • bestboyfriendintheworld@sh.itjust.worksOP
        link
        fedilink
        arrow-up
        1
        ·
        edit-2
        13 days ago

        Most people install at least some kind of software from outside the App Store.

        Popular examples: VLC Media Player, LibreOffice, Adobe Software, Firefox, Dropbox, Transmission, TeamViewer

        Especially lots of FOSS applications aren’t on the AppStore, many aren’t even notarized.

        Cracked pirated software isn’t notarized either of course.

        • Repple (she/her)@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          12 days ago

          Sure. And I don’t have that setting enabled personally, but I am careful otherwise and I tell my family members who don’t know better to keep it on.