Apple a valid\u00e9 une application macOS qui cachait un malware<\/title>\n<meta name=\"description\" content=\"Apple a laiss\u00e9 passer un malware entre les mailles de son authentification pour macOS. Depuis, le compte d\u00e9veloppeur associ\u00e9 \u00e0 \u00e9t\u00e9 supprim\u00e9.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apple a valid\u00e9 une application macOS qui cachait un malware\" \/>\n<meta property=\"og:description\" content=\"Apple a laiss\u00e9 passer un malware entre les mailles de son authentification pour macOS. Depuis, le compte d\u00e9veloppeur associ\u00e9 \u00e0 \u00e9t\u00e9 supprim\u00e9.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html\" \/>\n<meta property=\"og:site_name\" content=\"PhonAndroid\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/phonandroid\" \/>\n<meta property=\"article:published_time\" content=\"2020-09-01T17:27:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-11-05T07:41:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/wp-pa.phonandroid.com\/uploads\/2020\/09\/apple-authentifie-malware.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"750\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sam Azzemou\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Banquise_du_GP\" \/>\n<meta name=\"twitter:site\" content=\"@phonandroid\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sam Azzemou\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html\"},\"author\":{\"name\":\"Sam Azzemou\",\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/person\/3a97dd1bb4a918a5b3ff959857b59a16\"},\"headline\":\"Apple a valid\u00e9 une application macOS qui cachait un malware\",\"datePublished\":\"2020-09-01T17:27:11+00:00\",\"dateModified\":\"2021-11-05T07:41:45+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html\"},\"wordCount\":462,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.phonandroid.com\/#organization\"},\"articleSection\":[\"iPhone\"],\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html#respond\"]}],\"copyrightYear\":\"2020\",\"copyrightHolder\":{\"@id\":\"https:\/\/www.phonandroid.com\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html\",\"url\":\"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html\",\"name\":\"Apple a valid\u00e9 une application macOS qui cachait un malware\",\"isPartOf\":{\"@id\":\"https:\/\/www.phonandroid.com\/#website\"},\"datePublished\":\"2020-09-01T17:27:11+00:00\",\"dateModified\":\"2021-11-05T07:41:45+00:00\",\"description\":\"Apple a laiss\u00e9 passer un malware entre les mailles de son authentification pour macOS. Depuis, le compte d\u00e9veloppeur associ\u00e9 \u00e0 \u00e9t\u00e9 supprim\u00e9.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.phonandroid.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apple a valid\u00e9 une application macOS qui cachait un malware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.phonandroid.com\/#website\",\"url\":\"https:\/\/www.phonandroid.com\/\",\"name\":\"PhonAndroid\",\"description\":\"PhonAndroid\",\"publisher\":{\"@id\":\"https:\/\/www.phonandroid.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.phonandroid.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.phonandroid.com\/#organization\",\"name\":\"PhonAndroid\",\"url\":\"https:\/\/www.phonandroid.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.phonandroid.com\/wp-content\/themes\/phonadroid-v3\/assets\/images\/lg-phonandroid-amp-4.png\",\"contentUrl\":\"https:\/\/img.phonandroid.com\/2023\/06\/dark.png\",\"width\":280,\"height\":60,\"caption\":\"PhonAndroid\"},\"image\":{\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/phonandroid\",\"https:\/\/twitter.com\/phonandroid\",\"https:\/\/www.youtube.com\/user\/Phonandroidtv\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/person\/3a97dd1bb4a918a5b3ff959857b59a16\",\"name\":\"Sam Azzemou\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/e8f2d79c75a01aa1758ba0d6807a564d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/e8f2d79c75a01aa1758ba0d6807a564d?s=96&d=mm&r=g\",\"caption\":\"Sam Azzemou\"},\"description\":\"Sur la Banquise, en plein coeur du froid arctique, se trouve un havre de paix. Un havre pour les joueurs, les collectionneurs et les r\u00eaveurs. Dans ce refuge, le G\u00e9n\u00e9ral Pingouin a \u00e9lu domicile pour y concocter ses tests, ses news et ses billets d'humeur. Il y joue aussi... quand il peut.\",\"sameAs\":[\"https:\/\/twitter.com\/Banquise_du_GP\",\"@GenPingouin\"],\"url\":\"https:\/\/www.phonandroid.com\/author\/sam\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Apple a valid\u00e9 une application macOS qui cachait un malware","description":"Apple a laiss\u00e9 passer un malware entre les mailles de son authentification pour macOS. Depuis, le compte d\u00e9veloppeur associ\u00e9 \u00e0 \u00e9t\u00e9 supprim\u00e9.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html","og_locale":"fr_FR","og_type":"article","og_title":"Apple a valid\u00e9 une application macOS qui cachait un malware","og_description":"Apple a laiss\u00e9 passer un malware entre les mailles de son authentification pour macOS. Depuis, le compte d\u00e9veloppeur associ\u00e9 \u00e0 \u00e9t\u00e9 supprim\u00e9.","og_url":"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html","og_site_name":"PhonAndroid","article_publisher":"https:\/\/www.facebook.com\/phonandroid","article_published_time":"2020-09-01T17:27:11+00:00","article_modified_time":"2021-11-05T07:41:45+00:00","og_image":[{"width":1200,"height":750,"url":"https:\/\/wp-pa.phonandroid.com\/uploads\/2020\/09\/apple-authentifie-malware.jpg","type":"image\/jpeg"}],"author":"Sam Azzemou","twitter_card":"summary_large_image","twitter_creator":"@Banquise_du_GP","twitter_site":"@phonandroid","twitter_misc":{"Written by":"Sam Azzemou","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html#article","isPartOf":{"@id":"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html"},"author":{"name":"Sam Azzemou","@id":"https:\/\/www.phonandroid.com\/#\/schema\/person\/3a97dd1bb4a918a5b3ff959857b59a16"},"headline":"Apple a valid\u00e9 une application macOS qui cachait un malware","datePublished":"2020-09-01T17:27:11+00:00","dateModified":"2021-11-05T07:41:45+00:00","mainEntityOfPage":{"@id":"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html"},"wordCount":462,"commentCount":0,"publisher":{"@id":"https:\/\/www.phonandroid.com\/#organization"},"articleSection":["iPhone"],"inLanguage":"fr-FR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html#respond"]}],"copyrightYear":"2020","copyrightHolder":{"@id":"https:\/\/www.phonandroid.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html","url":"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html","name":"Apple a valid\u00e9 une application macOS qui cachait un malware","isPartOf":{"@id":"https:\/\/www.phonandroid.com\/#website"},"datePublished":"2020-09-01T17:27:11+00:00","dateModified":"2021-11-05T07:41:45+00:00","description":"Apple a laiss\u00e9 passer un malware entre les mailles de son authentification pour macOS. Depuis, le compte d\u00e9veloppeur associ\u00e9 \u00e0 \u00e9t\u00e9 supprim\u00e9.","breadcrumb":{"@id":"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.phonandroid.com\/apple-a-authentifie-une-application-macos-qui-cachait-un-malware.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.phonandroid.com\/"},{"@type":"ListItem","position":2,"name":"Apple a valid\u00e9 une application macOS qui cachait un malware"}]},{"@type":"WebSite","@id":"https:\/\/www.phonandroid.com\/#website","url":"https:\/\/www.phonandroid.com\/","name":"PhonAndroid","description":"PhonAndroid","publisher":{"@id":"https:\/\/www.phonandroid.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.phonandroid.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/www.phonandroid.com\/#organization","name":"PhonAndroid","url":"https:\/\/www.phonandroid.com\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.phonandroid.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.phonandroid.com\/wp-content\/themes\/phonadroid-v3\/assets\/images\/lg-phonandroid-amp-4.png","contentUrl":"https:\/\/img.phonandroid.com\/2023\/06\/dark.png","width":280,"height":60,"caption":"PhonAndroid"},"image":{"@id":"https:\/\/www.phonandroid.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/phonandroid","https:\/\/twitter.com\/phonandroid","https:\/\/www.youtube.com\/user\/Phonandroidtv"]},{"@type":"Person","@id":"https:\/\/www.phonandroid.com\/#\/schema\/person\/3a97dd1bb4a918a5b3ff959857b59a16","name":"Sam Azzemou","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.phonandroid.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/e8f2d79c75a01aa1758ba0d6807a564d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e8f2d79c75a01aa1758ba0d6807a564d?s=96&d=mm&r=g","caption":"Sam Azzemou"},"description":"Sur la Banquise, en plein coeur du froid arctique, se trouve un havre de paix. Un havre pour les joueurs, les collectionneurs et les r\u00eaveurs. Dans ce refuge, le G\u00e9n\u00e9ral Pingouin a \u00e9lu domicile pour y concocter ses tests, ses news et ses billets d'humeur. Il y joue aussi... quand il peut.","sameAs":["https:\/\/twitter.com\/Banquise_du_GP","@GenPingouin"],"url":"https:\/\/www.phonandroid.com\/author\/sam"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/posts\/2316334","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/users\/111"}],"replies":[{"embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/comments?post=2316334"}],"version-history":[{"count":16,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/posts\/2316334\/revisions"}],"predecessor-version":[{"id":2414562,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/posts\/2316334\/revisions\/2414562"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/media\/2316347"}],"wp:attachment":[{"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/media?parent=2316334"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/categories?post=2316334"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/tags?post=2316334"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}

Cr\u00e9dit : Unsplash<\/figcaption><\/figure>\n

Patrick Wardle est un d\u00e9veloppeur d\u2019applications de s\u00e9curit\u00e9 pour macOS. Il tient \u00e9galement un blog sp\u00e9cialis\u00e9 sur les questions de s\u00e9curit\u00e9 autour de l\u2019environnement Apple. Le week-end dernier, il a publi\u00e9 un article long, technique, mais fort int\u00e9ressant sur une histoire qui fait froid dans le dos\u00a0: l\u2019authentification par Apple d\u2019une application qui contient un malware. Et pas n\u2019importe lequel\u00a0: le plus connu de tous les malwares sous macOS\u00a0: Shlayer<\/strong>.<\/p>\n

Source : PayPal : une attaque phishing menace de vider le compte des utilisateurs en France<\/strong><\/p>\n

Revenons un peu en arri\u00e8re. En 2012, Apple pr\u00e9sente Gatekeeper<\/strong>, une nouvelle fonction de s\u00e9curit\u00e9 int\u00e9gr\u00e9e \u00e0 macOS Lion (10.7) qui permet de bloquer les applications dont le d\u00e9veloppeur n\u2019est pas identifi\u00e9. L\u2019id\u00e9e est d\u2019emp\u00eacher les utilisateurs d\u2019ouvrir des applications v\u00e9rol\u00e9es. Il est cependant toujours possible de contourner Gatekkeper.<\/p>\n

En 2019, Apple annonce que les logiciels devront \u00eatre obligatoirement authentifi\u00e9es pour fonctionner avec Catalina (macOS 10.17), qu\u2019ils soient distribu\u00e9s sur le Mac App Store ou non<\/strong>. Pas d\u2019authentification, pas de lancement, m\u00eame pour les d\u00e9veloppeurs authentifi\u00e9s. Et pas de contournement possible, contrairement \u00e0 avant. L\u2019objectif d\u2019Apple est d\u2019examiner chaque programme et de rassurer ses usagers, comme sur iOS, alors que cela pullule toujours du c\u00f4t\u00e9 d'Android<\/a>.<\/p>\n