You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

"trustd" Possible malware or virus??

I found something with little snitch that is quite odd.


It showing that "trustd" is a protected rule and it's in path is /usr/libexec/trustd


The weird thing is in the notes for it, there is some german or other language, which I've never seen before.

Heres what it says in the notes...

Überprüft die Gültigkeit von Certificaten.


It says the Process Owner = System and can't be changed from "Allow any outgoing connection" because it's protected. Normally only apple rules are protected.


Anyone know what this trustd is, and why the notes are written in german??

iMac, OS X El Capitan (10.11.6), 3.4GHz Intel Core i7, 24GB Ram

Posted on Oct 20, 2016 3:01 PM

Reply
Question marked as Top-ranking reply

Posted on Dec 17, 2016 8:09 AM

Sigh.


I am trying to ANSWER THE QUESTION that the poster had. Are you?


The questions were "what is trustd?" And "why are the notes written in German?"


You answered the first and I answered the second. You seem to have no familiarity with Little Snitch or its notes facility. The poster has been using it for 4 years, examining the network connections in and out of his Mac. Good for him! That's how you learn. You attempted to answer but aren't even familiar with Little Snitch!


Frankly after 4 years of examining network connections he is quite aware of the complexity of MacOS. Better than most in here I'd bet! It isn't "overly complicated" by any means.


But what is incorrect is to dismiss the *possibility* of malware or claim that he has "paranoia" just because he has a sincere question! He might just want to block unwanted processes. He might be having fun playing around. He might be hardening the OS.


By the way you also do not need "extraordinary" evidence of malware. Any solid evidence will do. Malware and hacks are also not "extraordinarily rare." And if you are referring to the protections of SIP, that only debut with El Capitan a little over a year ago. Before that time it would have been far easier to replace a system process with a compromised version. Don't pretend this is hard.


Have a nice day.

19 replies

Dec 20, 2016 9:55 AM in response to GeorgeSupport6411

GeorgeSupport6411 wrote:


The Little Snitch developers market it primarily as a firewall. But did you know Little Snitch also examines packet traffic, and captures it?

No. I didn't know that. But apparently, it is not the standard behavior. You have to manually trigger it (as described here: http://www.chrisle.me/2012/11/little-snitchs-hidden-pcap-network-sniffer/ - the link is a few years old).


Indeed it is my primary capture tool these days to grab the traffic from an individual process, particularly terminal processes.


That said, to analyze the packets you need an analyzer, like tcpdump, Wireshark, or CPA. But we all have one of those free tools.

More importantly, you have to know about this feature, plan to capture those packets before you start, and then you have to be able to understand them. I have had people use Little Snitch to detect and complain about my app EtreCheck phoning home. But in its standard firewall mode, it doesn't provide any information beyond the web site, not even the full URL. Most network communication these days is encrypted. That level of network analysis is far beyond what anyone on Apple Support Communities is doing.


LS is a better tool than you think and if you are going to support users you might want to get another copy and experiment with it.

It is not my job to support Little Snitch. While I have made improvements to my software to be more compatible with Little Snitch, ultimately it is something that makes life more difficult for everyone involved.


"I have seen a number of cases where people get curious and start digging around into internals that they don't understand..."


This is the point. It's what we should all be doing, hopefully with some guidance! Breaking things is unfortunately sometimes part of the process. Luckily it isn't too difficult to reinstall the OS. And these days, with Time Machine and other technologies, breaking something isn't the big fear it used to be.

Sorry, but you are totally on the wrong platform. There are a handful of people using packet sniffers on a Mac and doing other kinds of security forensics. But you could put all of those people into a single room and have space left over. The many millions of other Mac users who only wind up scared, confused, and much less secure than when they started. Apple does a pretty good job of supporting the needs of such people. In the vast majority of cases, the best thing to do is keep 3rd party system modifications off the machine, use default settings, and let Apple do its job.

Dec 20, 2016 1:52 PM in response to etresoft

etresoft wrote:


It is not my job to support Little Snitch. While I have made improvements to my software to be more compatible with Little Snitch, ultimately it is something that makes life more difficult for everyone involved.

Sorry, but you are totally on the wrong platform. There are a handful of people using packet sniffers on a Mac and doing other kinds of security forensics. But you could put all of those people into a single room and have space left over. The many millions of other Mac users who only wind up scared, confused, and much less secure than when they started. Apple does a pretty good job of supporting the needs of such people. In the vast majority of cases, the best thing to do is keep 3rd party system modifications off the machine, use default settings, and let Apple do its job.

Hear, hear!!!

Thank you for saying this. You were able to express what I feel better than I could myself.


And of course thank you for creating Etrecheck.

"trustd" Possible malware or virus??

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.