Live data from Hacker News

The ‘app’ you can’t trash: how SIP is broken in High Sierra

eclecticlight.co

51–60 of 100 posts

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#51
post #16

Earlier quoted context omitted.

It’s exaggerated but only slightly. Some of the worst messes I’ve seen were people who should have known better just blindly pasting google search results because they didn’t have time to do it right. More developers than sysadmins but definitely not exclusively so. Never underestimate the degree to which people are rushing or not questioning whether their initial diagnosis was correct.

I would add that these kinds of "Normal users click accept/next" are how "offers" on software gets installed. Case in point: uTorrent. Download and "install". You will, generally, get 2 screens that install junk. On one screen you can click "Decline". On another, you can click "Skip". These screens are between all the normal "which folder", "do you accept" and "thank you" screens. Case in point: Adobe Reader... downl…

The problem with most of your examples is that either they're not dialogs ("unclick optional offers"), or they are expected dialogs (you expect during installation dialogs that ask you this-and-that, and you knowingly triggered the installation, so you mistakenly/casually click the wrong button). They are dark patterns, that first train you to click "next-next-next" then present you with an "offer" where you're also expected to click "next".

The system security dialogs like the "permissions" dialogs are not like that - I even read the Android permissions dialog (though I realize most people don't, I still think a sizeable chunk of people do, and thus I considered the original claim - that nobody does, not even developers/dev-ops - to be hyperbolic).

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#52
post #21
post #18

This post annoys me for describing a problem which other people might encounter with a good level of detail but uses “broken” to get clicks rather than the more accurate “I don’t understand or agreee with the security model”. As misnome and others have noted, if someone loads a malicious kext the only safe option is a complete wipe and reinstall – or depending on how much you trust Apple’s firmware signing, buying a…

It's not just about malware. It's also really annoying if you need to uninstall a benevolent but buggy kext. And it's quite surprising that SIP+kext is a one way street (you can install while SIP is active, but you can't uninstall while SIP is active - hope you're not using a computer where someone else manages the mac firmware password, or you can end up shooting yourself in the foot).

If that's the user's situation, they should also be in a position to work out a better solution with whatever corporate/school IT is managing the firmware password.

If you're frequently installing and uninstalling buggy kexts, you're pretty far out of the mainstream as a user. Let alone if you also have a firmware password, and it's managed by someone else. Yes, that's a scenario where SIP will be annoying, but it's also not the scenario you can base the security model around for a consumer OS.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#53
post #3

> when some malware does manage to slip an evil kernel extension past a user and is rewarded with the protection of SIP, neither the user nor any anti-malware tool will be able to remove that extension, unless the user restarts from a different boot volume, or KernelExtensionManagement allows it. But isn't that scenario "Game Over" anyway? At least installing kernel extensions is a process that is explicit and - impo…

[deleted]

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#54
post #41

Earlier quoted context omitted.

The first usage I see of "SIP" after the title is in parenthesis after the full phrase.

Yes, but halfway through the article. It is a mystery until then.

Isn't that standard in both APA and MLA?

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#55
post #54

Earlier quoted context omitted.

Yes, but halfway through the article. It is a mystery until then.

Isn't that standard in both APA and MLA?

Regardless of the style guides, it’s in the title and not explained until late in the post. The author should have explained or at least expanded the acronym in the lede

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#58
post #20

Earlier quoted context omitted.

> not just another 'trained to ignore' permissions dialog. I have never seen any user reading a dialog message if it has a button with label "ok", "cancel", "allow" or "next". Including a lot of developers/dev-ops.

The dialog for kernel extension doesn't contain any of those labels though. Instead it offers you to open the "Security" preference pane where some additional UI will be displayed. If you blindly click buttons you will not accidentally enable a kernel extension.

I have barely any experience with macOS, but could an application perform those steps on a user's behalf if it were granted Accessibility access?

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#59
I ran into SIP yesterday trying to disable the notification center. Why there's no way to turn it off like every previous version of osx is beyond me. But basically you have to jump through a bunch of hopes to disable SIPs i recovery mode before being able to modify the setting to turn off the notification center.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#60
post #54

Earlier quoted context omitted.

Yes, but halfway through the article. It is a mystery until then.

Isn't that standard in both APA and MLA?

Sorry — I don't know what those acronyms mean. I assume they're writing style guides? (Associated Press.. Acronym? Metropolitan Literature... Acronym?)

Also, is this an example of irony?

Post reply on HN