Since the start of June we have had barely a drop of rain here, a mere 3 mm (0.1 inches) by my reckoning, and four updates to macOS Tahoe, together with five to XProtect. On both counts, this summer has already made the record books, and there’s no end in sight to either our drought or further updates.
Both are also the result of climate change, the drought in England and other parts of Europe because of our failure to control carbon emissions, while the many fixes to macOS appear largely the result of widespread adoption of AI by security researchers. What had previously only been obtained by many days of painstaking work can now come almost effortlessly if you’re prepared to burn enough tokens, which must be galling to those security researchers who have mastered more traditional methods.
Standing out from the crowd of those nine updates is the most recent, surely the one that has attracted least attention, that to XProtect 5354 which I speculated about a couple of days ago. This marks the greatest change since Apple introduced its ‘behavioural’ flavour of XProtect three years ago in macOS Ventura. Since its introduction in 2009, XProtect’s on-demand code scanner has been entirely static, checking against a set of definitions of what’s known to be malicious. XProtect 5354 ventures into new territory, that of blocking potentially malicious code behaviour.
When the rules in its additional file come into force, an unauthorised app that tries to access any of its proscribed directories will be blocked from doing so. It remains to be seen what additional actions might ensue, such as termination of that app and warnings to the user. Although a similar approach is already used to protect privacy using TCC (Transparency, Consent and Control), it’s relatively novel as a security measure in macOS.
XProtect Behaviour Service has remained a bit of a mystery since it was quietly slipped into Ventura. Its only official mention in Apple’s Platform Security Guide appears to be:
“XProtect contains an advanced engine to detect unknown malware based on behavioral analysis. Information about malware detected by this engine, including what software was ultimately responsible for downloading it, is used to improve XProtect signatures and macOS security.”
It applies a set of Bastion rules conveniently tucked away inside XProtect Remediator’s bundle to observe and report code behaviour that could indicate malicious intent, such as accessing a browser’s support folder in ~/Library/Application Support, the same locations protected by XProtect’s new access rules. The number of Bastion rules has grown steadily to reach of total of 24, a year ago, but it seems content to continue providing Apple with intelligence rather than intervening to prevent potentially malicious actions.
Wise users have of course been using behavioural detection methods for many years, in sophisticated third-party software firewalls that intercept attempts to phone home, and in tools like Objective-See’s KnockKnock which screens for persistently installed software.
One implicit admission in XProtect’s new protection scheme is the limitations of notarisation in security assurance. According to its rules, apps that are authorised to access protected directories are required to be signed by specific Team and code signing IDs as their means of identification. Initially, this is only for the first eight apps, but is likely to grow as that list lengthens. It seems doubtful whether it will ever be feasible to add to general checks on notarisation tickets in the future, but for widely used apps from larger commercial developers that are most likely to be targets for impersonation, it could prove worthwhile.
For some, though, these changes won’t be welcomed. All the indications are that the new protection in XProtect 5354 will only be available to those Macs running macOS 27 Golden Gate. That unfortunately excludes all Intel models, leaving them forever vulnerable to the malicious behaviour from which Apple silicon Macs will be protected. As with all climate change, there will be winners and losers.
