MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392 @SecurityWeekly
MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392  @SecurityWeekly
Uploaded July 2026 | Updated September 2026, 2 weeks ago
Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how he's seen malware shift from Windows to macOS, how Apple's aggressive stance on deprecation benefits security, and the areas of the OS where he still sees plenty of opportunity for more security research. We discuss how developers make defensible design choices, why privacy needs security, and some security principles that any app developer should keep in mind regardless of their programming language or operating system.

Resources:
- objective-see.org/blog/blog_0x86.html
- objective-see.org/products/lulu.html
- objectivebythesea.org/v9/index.html

Visit securityweekly.com/asw for all the latest episodes!

Show Notes: securityweekly.com/asw-392

00:00:00 Catching Up on AppSec News and Announcements
00:01:51 Reverse Engineering AI Cheats in Online Gaming
00:11:28 Windows Secure Boot Flaws and LLM Vulnerability Hunting
00:22:34 Building LLM Harnesses and Rustifying Chromium Code
00:37:23 Patrick Wardle on Mac Malware Evolution and Porting
00:45:10 Apple's Security Design Choices and User Interaction
00:57:11 Apple's Researcher Relations and Future Security Areas
01:05:02 Core App Security Principles and Episode Conclusion
MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392AI Tested Against Cyber ExpertsYour LLM Might Find Missing LogsAI Becomes Cybersecurity Operating SystemWhat Happens When AI Ignores RulesAgents at the Door: Vetting Non-Human Identities in External IAM - Rakesh Soni - CSP #219The AI Was the Route InYour CI Pipeline Becomes the AttackUsing LLMs for Vuln Discovery - Rishi Sharma - ASW #395Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland - SWN #598Can employees safely use AI agents? AI pentesting agent liabilities, and the news - ESW #473Cloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Neal - CSP #226
Security Weekly - A CRA Resource |

MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER