Live data from Hacker News

The ‘app’ you can’t trash: how SIP is broken in High Sierra

eclecticlight.co

71–80 of 100 posts

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#71
post #3

> when some malware does manage to slip an evil kernel extension past a user and is rewarded with the protection of SIP, neither the user nor any anti-malware tool will be able to remove that extension, unless the user restarts from a different boot volume, or KernelExtensionManagement allows it. But isn't that scenario "Game Over" anyway? At least installing kernel extensions is a process that is explicit and - impo…

"trained to ignore' permissions dialog."

Apple users terrify me.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#73
post #17

Earlier quoted context omitted.

You can not trust the user. Never.

How does that work in parallel with "It's my device, I'll do what I want with it"?

Oh man the hoops I had to jump through to get full admin control over windows 10. I understand the necessity of hiding power options but that was excessive.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#74
post #5

The article doesn't mention that this is not new; nor is it 'the' app you can't trash: it joins Safari, Finder, and most other 'Apple apps'. I find it quite surprising. Even when Windows defaulted to IE without choice, it could always be removed with 'Add or Remove Windows Features', as I recall.

You forgot to mention Chess. You can't trash Chess.

[deleted]

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#75

Earlier quoted context omitted.

It took Linux/BSD years to get it right, too. It often takes a long time for the user-facing interface to catch up to the kernel functionality.

> It often takes a long time for the user-facing interface to catch up to the kernel functionality. A long time to catch up for a company that revolutionized UX?

Revolutions in user interfaces rarely occur overnight. The current Mac is the culmination of over 25 years of continuous development, and it's still imperfect.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#76
post #71
post #3

> when some malware does manage to slip an evil kernel extension past a user and is rewarded with the protection of SIP, neither the user nor any anti-malware tool will be able to remove that extension, unless the user restarts from a different boot volume, or KernelExtensionManagement allows it. But isn't that scenario "Game Over" anyway? At least installing kernel extensions is a process that is explicit and - impo…

"trained to ignore' permissions dialog." Apple users terrify me.

You say this as if every single Windows user in the history of Windows doesn't just click every dialog box that says "OK" or immediately dismiss the UAC boxes that come up when something needs Admin access on Windows 7 and above. On Macs, at least, you have to enter the user's password to do anything damaging.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#77
post #72

A lot of people are forgetting that security prompts look like this to ordinary users https://i.imgur.com/H0uVqFer.jpg ”But they had to allow installation first” is no defense.

In this case, it is, though, because the security prompt to enable the kext in question doesn't have an "OK" button. It doesn't really offer a button to perform the action at all. It offers a shortcut to the System Preferences pane where the user would have to unlock the pane, type in their admin password, click on the extensions button, and then click to allow the extension. If the user has jumped through those hoops to enable this, they've already passed the barrier of entry. This isn't something someone can accidentally do.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#78
post #15

Earlier quoted context omitted.

> not just another 'trained to ignore' permissions dialog. I have never seen any user reading a dialog message if it has a button with label "ok", "cancel", "allow" or "next". Including a lot of developers/dev-ops.

This seems a bit hyperbolic. I do, and I'm pretty sure a lot of people do - especially developers; and especially dialogs that you didn't explicitly expect. Not saying that the majority do; or that a dialog is "good security protection". I just don't think it's as useless as you seem to imply.

If 1% of the population reads even half of their dialog boxes I'd be amazed.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#79
post #71
post #3

> when some malware does manage to slip an evil kernel extension past a user and is rewarded with the protection of SIP, neither the user nor any anti-malware tool will be able to remove that extension, unless the user restarts from a different boot volume, or KernelExtensionManagement allows it. But isn't that scenario "Game Over" anyway? At least installing kernel extensions is a process that is explicit and - impo…

"trained to ignore' permissions dialog." Apple users terrify me.

Watch the average user do something similar with the Windows UAC popup. At least Apple requires a sudoers password for most of theirs.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#80
post #65
post #62

Add "System Integrity Protection" to the list of reasons why my next laptop won't be a Mac. Although based on a free operating system, Mac OS is gradually taking away users' control over their own devices. Either the user controls the software, or the software controls the user.

Just as with SELinux or AppArmor, you can ignore it if you think your normal practices keep you safe. That's probably mistaken but it's fully under your control: https://developer.apple.com/library/content/documentation/Se...

I don't mind those features in and of themselves, and I see their value; it's Apple's paternalistic attitude that bothers me. I've used Macs for my entire life and always felt I still had a semblance of control over the hardware and software that I bought, but that feeling of control is going away.
Post reply on HN