{
  "id": 12436100,
  "title": "A Mac App Is Not a Process",
  "url": "https://urgent.news/2026/10/06/a-mac-app-is-not-a-process",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-06T18:06:22.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/hugo_fernandes/a-mac-app-is-not-a-process-4768"
  },
  "original_language": "en",
  "account": "In the realm of application management, a key challenge lies in defining what constitutes an \"app\". On the surface, an app may be recognized as a single icon in Finder, yet beneath the surface it typically consists of a directory housing a primary executable, alongside various auxiliary components. These could include helper services, login items, extensions, update tools, and even standalone command-line programs. Any one of these elements could potentially engage in network communication. Consequently, if only the main executable is targeted for blocking, the approach can be straightforward yet potentially misleading, as it may overlook other interconnected processes that continue to operate.\n\nTo address this issue, the NetBlocker application has adopted a more comprehensive approach to app identification. When an app is dragged into NetBlocker's interface, the software initiates an inspection of the app's bundle. This inspection involves evaluating the signed identity of the running code, the developer team responsible for it, the relationship between the code and the selected bundle, and the process context associated with the network flow. By considering multiple factors, NetBlocker aims to create a more accurate and nuanced representation of an app's identity, thereby avoiding misunderstandings and misapplications of blocking rules.\n\nOne of the primary difficulties in application identification stems from the reliance on generic identifiers such as executable names. Terms like \"node\", \"java\", \"python\", \"bash\", and \"sh\" are ubiquitous across a multitude of unrelated products, making it difficult to discern a true identity based solely on these labels. Similarly, numeric process identifiers are often transitory and can be reused across different contexts. While file paths offer more informative context, they change when software is moved or updated. Apple's code signing services provide a more reliable source of identity-related data, encompassing the signing identity, developer team, and specific requirements attached to the code. However, even these identifiers may not fully capture the essence of an app's identity, as a signing identifier could be generic, and a developer team might oversee numerous unrelated binaries. Therefore, NetBlocker employs a multi-faceted approach to identity evaluation, combining various forms of evidence to establish a more robust and precise representation of an app's identity.",
  "summary": "What Photoshop, Android Studio and a process called node taught me about application identity At one point during development, NetBlocker broke the chat integration in Android Studio. The failure looked unrelated to a network filter. Android Studio reported a bad file descriptor, its embedded tooling stopped working, and restarting it made no difference. The actual cause was an early NetBlocker…",
  "key_points": [
    "NetBlocker app identifies software bundles beyond main executable",
    "Multi-faceted identity evaluation combines code signing, developer team, and process context",
    "Avoids misunderstandings by considering network flow and app relationships"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}