Related guides
“Damaged” on a Mac, and how to verify the installer
Updated
Short answer: the file is not broken and nobody tampered with it. On a Mac, “damaged” and “cannot verify the developer” are Gatekeeper blocking an app without an Apple signature and notarization — the desktop clients we distribute are not signed yet. Below: how to verify the installer yourself, then three ways to allow it, narrowest first. On Windows, installing Hiddify no longer triggers antivirus warnings in our tests; if your antivirus still flags it, the rule is the same — verify first, then allow.
Why it gets blocked (the honest version)
- The installer is unsigned. Apple’s developer signing and notarization require applying as a company or registered business with identity verification; we are still weighing the cost and trade-offs, so on a Mac the app is from an “unidentified developer”. Gatekeeper blocks exactly that — not the content, but the fact that it doesn’t know who made it.
- Files downloaded from the web get a quarantine flag. When macOS sees it, it checks for a signature and notarization and refuses if they are missing; the message says “damaged” or “cannot verify the developer”, but the cause is the same.
- What we do: the desktop clients are byte-for-byte mirrors of the upstream open-source releases. We don’t modify, repackage or inject anything; we host them only so they are easy to download.
Verify first, don’t allow blindly
Allowing an app means the system stops checking it, so verify first and allow second — never the other way round. The step below takes a few minutes and needs no special knowledge.
- Cross-check on VirusTotal. Drop the installer on virustotal.com/gui/home/upload and see how many engines flag it. A handful of (usually heuristic) engines flagging while the major vendors pass it is the classic false-positive pattern; if most major engines flag it, do not install — contact us.
- Only when the check passes, allow it using the next section. If in doubt, contact support first and we will check the download mirror.
macOS: three ways to allow it, narrowest first
Opening the app may show ““App” is damaged and can’t be opened. You should move it to the Trash”, or “can’t be opened because the developer cannot be verified”. The three steps below go from narrowest to broadest; don’t use the third if the first works.
- Use the xattr command only on files you have verified — see the previous section.
- Don’t run sudo spctl --master-disable to switch Gatekeeper off globally. That removes protection for the whole machine; Control-click → Open affects one app only.
- Since macOS 15 Apple has tightened the Control-click path, so most of the time you’ll need the System Settings step. That’s a system change, not a problem with the installer.
- In Finder → Applications, Control-click (or right-click) the icon, choose Open, then click Open again in the dialog. This is a one-time exception for this one app.
- If the context menu offers no usable Open, go to System Settings → Privacy & Security, scroll to the Security section, find ““App” was blocked from use because it is not from an identified developer”, click Open Anyway and confirm with your password.
- If the message says “damaged”, the first two steps usually don’t help because the system can’t even read a signature. Open Terminal, paste the command below, add a space and the app’s path after it (usually the .app under /Applications/), press Return, enter your login password, then open the app:
sudo xattr -dr com.apple.quarantineThis removes the download-quarantine flag. - On first launch the system asks for your password to install the network extension; approve it or the app can’t route traffic.
Rather not allow it? Use one of these three
We support several connection methods; three of them use clients signed and notarized by their vendors, which open on a Mac with a double-click and never show the prompts above. Same account for all of them.
- Private network (official Tailscale client): vendor-signed, install and go, good for leaving on all day.
- OpenVPN Connect: OpenVPN’s own signed installer; just import the profile.
- Cisco Secure Client: an enterprise client with full signing; many company laptops already have it.
- Setup steps are in “Which connection method” and each method’s guide; the same account works, nothing extra to pay.
FAQ
Is there malware in your app?
No — the desktop clients are unmodified mirrors of the upstream projects’ official releases. But you shouldn’t have to take our word for it: section two gives a check you can do yourself — upload the installer to VirusTotal and look at the spread of engine verdicts.
Why not just buy signing?
We’re evaluating it. Apple signing and notarization, and Windows code-signing certificates, both require applying as a company or registered business with identity verification, the registration details are public in most places, and there are yearly fees. It’s a trade-off between cost and how we operate; we’ll update this page when we decide.
Will Windows still flag it?
In our tests, the built-in Windows Security no longer flags the Hiddify installer. If your antivirus still does, verify the installer as in section two first, then mark Hiddify’s install folder as trusted in your antivirus; don’t turn off real-time protection to install.
Does this happen on phones?
Not on iOS when installing from the App Store; on Android a security app may occasionally warn about an unknown source — just allow it.
Related pages
- Hiddify page: client downloads →
- What the macOS “network extension” permission is →
- Using RustDesk for remote help →
- Which connection method fits which scenario →
- Contact: support groups and email →
- Tencent Video or iQIYI Blocked Abroad? Fix It in 5 Steps →
- How to Choose a China VPN →
- Does Cisco AnyConnect Work in China? →
- Choosing a VPN Router →
- How to Import a Hiddify Subscription →
- China VPN for Students Abroad →
- What a Web Proxy Is and When to Use One →
- Free or Paid China VPN? →
- What the Private Network (Tailscale) Is →
- How to Use OpenVPN and When to Choose It →
- Flashing the Router Firmware: From Stock to Ours, Step by Step →
- What the Router Firmware Does →
- How to Reach Us and Never Lose Contact →
- Where We Beat Other VPNs →
- How to Recognise a Risky VPN App →
- Which Region Is Fastest from Inside China →
- For the TV and the Grandparents at Home →
- Watching Home Cameras and a NAS in China from Abroad →
- What to Do When iOS Cannot Install an App →
- Cannot Connect, Slow, or Dropping: What to Check →
- Setting Up for Business Trips and Travel →
- On a Company Laptop: No Admin Rights, Corporate VPN Already On →
- Many Devices, One Setup, No Redo on a New Phone →
- Routing a Synology or QNAP NAS →
- Routing a Linux Server and Command-Line Tools →
- Real vs fake split routing on a VPN router →
- Not enough device slots? Temporary vs long-term fixes →
- Dropbox and other apps want an HTTP / SOCKS proxy — what to do →
- How to Get Good Answers from the AI Support →
- How to manually uninstall the Cisco client on a Mac →
- Cisco error “remote user is disabled” →