|
|
|
|
|
by cjbprime
2512 days ago
|
|
> If the attacker has filesystem access you're already hosed. I think that's not supposed to be true in modern (e.g. latest macOS) threat models. App Y isn't permitted to just replace App X unannounced, and on both Mac and Win there's a large codesigning infrastructure in place to provide that protection. |
|