The Final Chapter: Unlimited ways to bypass your macOS privacy mechanisms

  Рет қаралды 1,048

Black Hat

Black Hat

Күн бұрын

"ThereIsNoPrivacy.app" would like to access the camera and spy on you, and access all of your private data.
In this talk we return for a third time to talk about bypassing macOS's privacy mechanisms. In the last 4 years we submitted over 100 vulnerabilities to Apple which allowed us to either fully or partially bypass macOS's privacy protection framework (TCC). We gave talks about our findings and various techniques in previous BlackHat conferences.
We will start by briefly explaining how the privacy framework works on macOS, how various databases, configuration files and the Sandbox play various roles in fulfilling a single goal - protecting your private data.
Then we will switch gears and show many new vulnerabilities and a couple of new techniques and ideas which allowed us to bypass privacy protection. As usual, you may expect full exploits, tons of demos and a lot of fun. Believe it or not but we bypassed the TCC again with /usr/bin/grep… multiple times.
Finally, we will talk about how Apple improved the privacy framework over the years, what new features were added in macOS Ventura, Sonoma, since the last time we talked about this topic. We will briefly review a few techniques, which we consider mostly dead due to new mitigations and fixes.
By:
Csaba Fitzl | Principal macOS Security Researcher, Kandji
Wojciech Reguła | Principal Security Consultant, SecuRing
Full Abstract & Presentation Materials:
www.blackhat.c...

Пікірлер
Building a Realtime Video and Chat App in React Native with Stream
3:59:43
Build a Local First Trello Clone with React Native & Realm
3:59:20
notJust․dev
Рет қаралды 107 М.
When mom gets home, but you're in rollerblades.
00:40
Daniel LaBelle
Рет қаралды 148 МЛН
1, 2, 3, 4, 5, 6, 7, 8, 9 🙈⚽️
00:46
Celine Dept
Рет қаралды 89 МЛН
How Strong is Tin Foil? 💪
00:25
Brianna
Рет қаралды 69 МЛН
Amazing remote control#devil  #lilith #funny #shorts
00:30
Devil Lilith
Рет қаралды 15 МЛН
Privacy Detective: Sniffing Out Your Data Leaks for Android
30:04
Keynote - Securing Our Cyberspace Together
1:02:26
Black Hat
Рет қаралды 1,7 М.
MacOS Sequoia is AWESOME - Try these 8 things FIRST!
14:57
Proper Honest Tech
Рет қаралды 395 М.
Dismantling DDoS - Lessons in Scaling
56:12
Black Hat
Рет қаралды 2 М.
Making an atomic trampoline
58:01
NileRed
Рет қаралды 10 МЛН
$50 vs $50,000 Computer
27:53
Linus Tech Tips
Рет қаралды 2,3 МЛН
Niall Ferguson Stuns World Leaders at ARC Australia - "Are We The Soviets Now?"
19:44
Alliance for Responsible Citizenship
Рет қаралды 405 М.
When mom gets home, but you're in rollerblades.
00:40
Daniel LaBelle
Рет қаралды 148 МЛН