
Patrick Wardle
Software analyst
5
APPEARANCES
4
PODCASTS
024
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
Sep 9, 2026
What's hitting Macs so far in 2026, plus OBTS v9 preview (Part 2)
6:02
6:11
6:39
6:59
7:10
7:14
17:16

Kseniia YamburhGUEST
Like it, it's kinda another business and I'm not sure how to reach them out to talk about [laughs] is it profitable or not.

Patrick WardleGUEST
not.It's, it's a very gray area too, because I remember, I think it was Malwarebytes that got sued by one of the adware companies 'cause they, like, flagged their adware as, like, malware or un- And it was like, well, the user clicked through the EULA and said, "I agree to install this plugin that will, you know, show me pop-ups." So the adware companies are like, "Legally we're not doing anything wrong here." And so it's this really weird gray area, and now I think they're just labeled potentially unwanted products, PUPs.

Patrick WardleGUEST
Um, but again, this was, like, something that was, I think, discussed a lot more, a lot more prevalent five plus years ago, where it might still be around, uh, to Kseniia's point, but, you know, I think stealers and those kind of things are, uh, at least in my opinion, impacting everyday users more dramatically as well.

Patrick WardleGUEST
Because that's the other thing, adware, it's annoying and it, yeah, it can be problematic and should be removed and deleted and prevented, but oh, you get hit by a stealer, like, man, that's can be super gnarly.

Patrick WardleGUEST
It's like all your accounts overnight are just like poof, your crypto's gone, whatever.

Patrick WardleGUEST
And so more f- more feasible or more profitable perhaps for the adversaries, and more impactful for the users, so there's a lot more discussion, uh, around them.
10 MINS LATER

Arin WaichulisHOST
Do you wanna give a little glimpse into any talks that you guys are presenting or are looking forward to in November?
Why Apple's making big changes to its bug bounty program (Part 1)
5:56
6:22
6:32
6:49
7:02
7:06
7:10
14:45

Arin WaichulisHOST
no no please go ahead um i was just gonna say i really wish apple would let their researchers and engineers go on podcasts like that's like the one gripe i've had with them for a while i'm like if they could just have them on a podcast just trust them to not reveal anything they're not supposed to reveal i feel like that'd be so beneficial to just have like pr like have pr on the security side of things i don't know i would what do you think about i

Patrick WardleGUEST
would love that i and perhaps naively pessimistic, but you know, Apple runs a very tight ship and I think their image is super important.

Patrick WardleGUEST
I think engineers and researchers, and I include myself in this, I have previously worked at companies and they have threatened to send me to PR training because sometimes the truth is maybe not the most tactical thing to say, uh, most tactful thing to say.

Patrick WardleGUEST
Uh, so, you know, I understand both sides, but from somebody on the outside who, uh, really thinks that bidirectional communication channel with Apple would be incredibly beneficial for the community.

Patrick WardleGUEST
I agree 100% that it would be really great to get their security researchers on.

Patrick WardleGUEST
And then I think it also would give them the opportunity to explain what they're seeing.

Patrick WardleGUEST
So for example, the bounty program, we are kind of picking on Apple here saying, hey, you did some good things, but there's definitely some negative things here.
7 MINS LATER

Arin WaichulisHOST
yeah I guess my train of thought is like do you see like less skilled attackers using that and reverse engineering those samples to come up with like better evasion techniques
MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392
42:09
47:55

Patrick WardleGUEST
And the first is ones that were written with cross-platform frameworks to begin with.
6 MINS LATER

Mike SchemaHOST
So what are the design choices or what's the approach that Apple's taken that you're alluding to that have actually made that malware creation more difficult or pushed more of that work onto the user?
MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392
42:04
42:13
42:26

Patrick WardleGUEST
So we see basically two types of Mac malware coming from other platforms, and the first is ones that were written with cross-platform frameworks to begin with.

Patrick WardleGUEST
Uh, so things like Electron, um, things like Java, if we're going kind of further back, 'cause Mac used to support, uh, Java.

Patrick WardleGUEST
The other thing we saw is, though, hackers taking their existing Windows capabilities and rewriting them in Swift or Objective-C, some Apple-specific language, and then also kind of implementing the Apple-specific techniques.
23 MINS LATER
MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392
42:09
47:55

Patrick WardleGUEST
And the first is ones that were written with cross-platform frameworks to begin with.
6 MINS LATER

Mike SchemaHOST
So what are the design choices or what's the approach that Apple's taken that you're alluding to that have actually made that malware creation more difficult or pushed more of that work onto the user?
