Slide 18
Slide 18 text
C O N F I D E N T I A L
18 ©2016 KUDELSKI GROUP / All rights reserved.
CODE SIGNING?
Recently in the news
“Malware bypassing Apple code signing mechanism”
AceDeceiver
Truth (explanation w/o the hype)
Still requires to be published and accepted by Apple at least
once in one of the stores (US, CH, CN, …)
Can use geolocation of incoming IP addresses to
enable/disable features in the code
Possible to exploit design flaw in the validation process
when installing from iTunes on Mac/PC
Allows to install the malware from Mac/PC even if certificate
revoked