Hacker News new | ask | show | jobs
by julien_p 4894 days ago
Files get a "quarantine flag" set on them as metadata when downloaded on OS X. Gatekeeper uses this (along with the developer signature) to check if an app is "safe" to open or not. Not sure where this sqlite database fits in, but it's very likely related to that.

See also https://support.apple.com/kb/HT3662

1 comments

The why is the Mac App Store exempt?
Trusted/controlled source.
Not just the Mac App Store, by the way. CDs or any other way of getting the file on the Mac except downloading are, too.

That all makes perfect sense. It doesn’t provide perfect protection, but it does provide sensible protection.