Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > uk.comp.sys.mac > #183807

Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck

From "David B." <"David B."@invalid.org>
Newsgroups alt.computer.workshop, uk.comp.sys.mac
Subject Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck
Date 2026-06-04 21:59 +0100
Organization Retired
Message-ID <n8e79sFhmjaU1@mid.individual.net> (permalink)
References <n7obu5F9snuU1@mid.individual.net> <6a219431$1$21$882e4bbb@reader.netnews.com> <6a21a5e3$1$21$882e4bbb@reader.netnews.com> <n8e0n7Fge4rU1@mid.individual.net> <6a21cf11$0$19$882e4bbb@reader.netnews.com>

Cross-posted to 2 groups.

Show all headers | View raw


On 04/06/2026 20:16, Brock McNuggets wrote:
> On Jun 4, 2026 at 12:07:18 PM MST, ""David B."" wrote
> <n8e0n7Fge4rU1@mid.individual.net>:
> 
>> On Jun 4, 2026, Brock McNuggets wrote:
>>> This is how macOS works. Any such app. So what is your point? You dropped the
>>> /Library claim and now are looking to have me argue other things.
>>
>> My point, Michael, is that standard security architecture evolves
>> precisely because saying "this is how it works, so what?" is how systems
>> stay vulnerable.
> 
> I am not going to change how macOS works. LOL! More than that, I think Apple
> does a pretty good job of improving as they go. With that said, sure, there is
> a place to talk about the theory and how an OS can be made better. No issue
> with that. But you are not doing that. You are looking at EtreCheck and saying
> it is a risk -- when you have not shown it to be any more of a risk than
> similar software that needs similar permissions.
> 
> You have started with a conclusion -- EtreCheck is evil -- and are looking to
> show it. And failing. And in doing so you are looking to see what that
> software does not knowing what is the norm. Without knowing the norm you
> cannot know if what it is doing is outside of the norm.
> 
> Below you change topics to things that are not in contention.
> 
>> Modern macOS apps using privilege separation explicitly avoid leaving
>> raw, executable helper binaries sitting inside user-writable directories
>> (/Applications/) for exactly the Local Privilege Escalation (LPE)
>> reasons I just laid out. They use modern system daemons precisely
>> because allowing user-space assets to elevate straight to root upon
>> admin authentication is a known architectural hazard.
>>
>> But I'll let you have your minor victory lap on the directory path
>> cleanup.
> 
> It was the one thing I was questioning you about. And you have conceded the
> point (again). Not sure what we are even arguing about.
> 
>> Yes, we established the tool relies on on-demand escalation
>> inside the bundle rather than a persistent drop into /Library.
> 
> Good to see you have learned since you said this
> <6a1fdbc4$1$55442$882e4bbb@reader.netnews.com>:
> 
>    Clarifying that the binary is written to /Library/PrivilegedHelperTools/
> 
> And I responded with:
> 
>    Please show a screenshot backing this.
> 
> That was my point. I did not believe you were correct -- though even in my
> wording there I was open to being shown I was wrong.
> 
>> The
>> screenshot cleared the air, which is exactly why I posted it.
> 
> The screenshot did not back your claim quoted above... and you have since
> given up on your claim. With that I am not even sure what we are discussing or
> even more disagreeing about. You keep assuming I meant things I never said. Of
> course, you are using AI and it is not getting the context and is possibly
> hallucinating and otherwise leading you astray. So be it. A bit amusing but
> also a bit sad -- I have no quarrel with you. I do disagree with your extreme
> focus on trying to find wrongdoing in EtreCheck. As I have said, it is harmful
> to all involved. But it is not like you go to the extremes of my stalker, so
> not gonna get too worked up over it.
>>
>> I am glad to hear the holiday and business are both going well! Keep
>> soaking up the sun, enjoy the rest of your trip, and don't think about
>> UNIX file permissions for at least the next few days.
> 
> I am working with someone with a mixed environment -- Windows and macOS. No
> Linux.
>>
>> I'll hold you to that round of drinks when you're back.
>>
>> Cheers!
>>
>> David


On Jun 4, 2026, Brock McNuggets wrote:
> The screenshot did not back your claim quoted above... and you have since
> given up on your claim. With that I am not even sure what we are discussing or
> even more disagreeing about. You keep assuming I meant things I never said. Of
> course, you are using AI and it is not getting the context and is possibly
> hallucinating and otherwise leading you astray. So be it. 
> ...
> I am working with someone with a mixed environment -- Windows and macOS. No
> Linux.

Oh, Michael, you just had to get the last word in from your deck chair, 
didn't you? 😄

Blaming "AI" for a standard local privilege escalation argument that I 
illustrated
with my own physical file screenshot is a wonderfully creative way to
exit a technical corner.
As for your mixed environment—Windows and macOS but no Linux?
My condolences to your client! They don't know what they are missing out 
on.

We've both made our points, the screenshot cleared up the mechanics for 
the group,
and the thread has thoroughly run its course. Put the phone away, get
back to your business and your holiday, and I'll see you at the pub when
you get back to Blighty.

In a manner of speaking!
-- 
David

Back to uk.comp.sys.mac | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-05-27 15:03 +0100
  Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-05-27 14:29 +0000
    Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Gremlin <nobody@haph.org> - 2026-05-27 15:15 +0000
      Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-05-27 15:34 +0000
    Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-05-27 18:34 +0100
      Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-05-27 20:00 +0000
        Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-05-27 23:36 +0100
          Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-05-27 23:33 +0000
    Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-05-28 12:48 +0100
  Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-05-27 20:31 +0000
    Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-05-27 23:42 +0100
      Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-05-27 23:39 +0000
        Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-05-28 08:48 +0100
          Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-05-28 12:26 +0000
            Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck David B. <boaterdave@hotmail.co.uk> - 2026-06-02 10:51 +0000
              Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-02 16:13 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-06-02 21:58 +0100
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-02 21:03 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck David B. <boaterdave@hotmail.co.uk> - 2026-06-02 21:21 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-02 21:46 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck David B. <boaterdave@hotmail.co.uk> - 2026-06-02 21:57 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-03 00:35 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck David B. <boaterdave@hotmail.co.uk> - 2026-06-03 07:46 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <Brock.McNuggets@gmail.com> - 2026-06-03 14:02 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck David B. <boaterdave@hotmail.co.uk> - 2026-06-03 14:54 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-03 15:43 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck David B. <boaterdave@hotmail.co.uk> - 2026-06-03 16:00 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-03 19:06 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck David B. <boaterdave@hotmail.co.uk> - 2026-06-03 19:40 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-03 19:48 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck David B. <boaterdave@hotmail.co.uk> - 2026-06-03 19:58 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-03 23:53 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck David B. <boaterdave@hotmail.co.uk> - 2026-06-04 08:08 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-04 13:53 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck David B. <boaterdave@hotmail.co.uk> - 2026-06-04 14:32 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <Brock.McNuggets@gmail.com> - 2026-06-04 14:47 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck David B. <boaterdave@hotmail.co.uk> - 2026-06-04 15:05 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-04 16:20 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-06-04 20:07 +0100
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-04 19:16 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-06-04 21:59 +0100
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-04 21:15 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-06-04 22:38 +0100
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-04 22:28 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-06-04 22:50 +0100
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-04 22:27 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-06-04 23:34 +0100
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-04 22:57 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-03 15:45 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-06-03 17:01 +0100
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-03 19:06 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck David B. <boaterdave@hotmail.co.uk> - 2026-06-03 19:46 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-03 19:49 +0000
  Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-06-02 09:59 +0100
    Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-02 16:14 +0000
      Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-06-02 22:02 +0100
        Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-02 21:05 +0000
        Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck pothead <pothead@snakebite.com> - 2026-06-02 22:23 +0000
          Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-03 00:40 +0000
          Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-06-03 08:51 +0100
            Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <Brock.McNuggets@gmail.com> - 2026-06-03 14:02 +0000
      Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Gremlin <nobody@haph.org> - 2026-06-03 20:22 +0000
        Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-03 23:45 +0000
    Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Gremlin <nobody@haph.org> - 2026-06-03 20:22 +0000
      Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-03 23:45 +0000
        Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-06-04 08:31 +0100
          Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-04 13:56 +0000
            Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-06-04 15:59 +0100
              Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-04 16:06 +0000
              Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Gremlin <nobody@haph.org> - 2026-06-05 03:42 +0000
                Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-05 03:59 +0000
      Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck "David B." <"David B."@invalid.org> - 2026-06-04 08:26 +0100
        Re: macOS Technical Note: Privileged Helpers, dragging to Trash, and EtreCheck Brock McNuggets <brock.mcnuggets@gmail.com> - 2026-06-04 13:57 +0000

csiph-web