• To the uk.comp.sys.mac regulars!

    From David B.@David@hotmail.co.uk to uk.comp.sys.mac on Sun Jun 28 18:53:58 2026
    From Newsgroup: uk.comp.sys.mac

    Subject: Re: A serious question for malware experts

    To the uk.comp.sys.mac regulars .....

    I'd be interested to get the wider group's perspective on this, moving
    away from Brock's loop.

    My original query was essentially about how we audit and trust the
    provenance of software that bypasses traditional installer packages
    (.pkg) and thus doesn't leave a footprint in System Information
    Installations.

    While I understand that modern real-time scanners, Gatekeeper, and
    XProtect monitor binaries on execution and do background cryptographic
    checks, I still prefer seeing a concrete, physical audit trail on the
    machine.

    How do the rest of you handle or feel about auditing the visibility and installation footprint of drag-and-drop utilities (like EtreCheck or Storeograph) before letting them run? Do you rely entirely on Apple's
    silent background notarisation, or do you use other tools to inspect the
    apps first?

    --
    David B.
    --- Synchronet 3.22a-Linux NewsLink 1.2