Is xfence now able to monitor changes made to inode?
Hi F-Secure dev team, thanks for making such a great App, however I found some issues related to command "mv".
Here are the steps:
- switch to "strict mode" and set a watch rule for folder "foo"
- use command "mv", moving files inside folder "foo" to $TMPDIR (located under /private/var/folders/, which is not included in the xfence's watch list.)
- Result: files are moved without a dialog
I think the root cause is, mv makes changes to inode instead of file data, and if the "DEST" isn't watched by xfence, then this could happen.
BR.
Accepted Answer
-
Hello!
A small update. We've identified the root cause of this behavior.
We indeed have support for handling of this operating system event type on DeepGuard (XFENCE) side. However, due to a bug on the implementation side only the target location is currently evaluated (in this case the temporary directory which is not included in monitoring). We are now adding evaluation of source that is being manipulated in this case and validating the fix internally. It will be included in the next FS Protection release.
We appreciate you reporting the issue to us and helping us improve the quality of the feature and making it more secure!
Best regards, Arthur
R&D Team
Best regards, Arthur
F-Secure Technology, Mac Team
Answers
-
Hi!
Unfortunately, I cannot hare any specific date as it has not been decided yet. But I'm hoping that it will happen in a week or two. We are currently verifying a couple of release blockers and if everything checks out, we will proceed with the release.
BR, Arthur
Best regards, Arthur
F-Secure Technology, Mac Team
🚩 What Do You Think?
We’d love your thoughts on our fresh look! Quick survey, big impact!