Live data from Hacker News

The ‘app’ you can’t trash: how SIP is broken in High Sierra

eclecticlight.co

21–30 of 100 posts

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#21
post #18

This post annoys me for describing a problem which other people might encounter with a good level of detail but uses “broken” to get clicks rather than the more accurate “I don’t understand or agreee with the security model”. As misnome and others have noted, if someone loads a malicious kext the only safe option is a complete wipe and reinstall – or depending on how much you trust Apple’s firmware signing, buying a…

It's not just about malware. It's also really annoying if you need to uninstall a benevolent but buggy kext. And it's quite surprising that SIP+kext is a one way street (you can install while SIP is active, but you can't uninstall while SIP is active - hope you're not using a computer where someone else manages the mac firmware password, or you can end up shooting yourself in the foot).

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#22
post #21
post #18

This post annoys me for describing a problem which other people might encounter with a good level of detail but uses “broken” to get clicks rather than the more accurate “I don’t understand or agreee with the security model”. As misnome and others have noted, if someone loads a malicious kext the only safe option is a complete wipe and reinstall – or depending on how much you trust Apple’s firmware signing, buying a…

It's not just about malware. It's also really annoying if you need to uninstall a benevolent but buggy kext. And it's quite surprising that SIP+kext is a one way street (you can install while SIP is active, but you can't uninstall while SIP is active - hope you're not using a computer where someone else manages the mac firmware password, or you can end up shooting yourself in the foot).

I agree that it’s annoying but doesn’t that sound like the post should be more like “here’s the radar number for my request that Apple improve their documentation”? Most people won’t encounter this and those who do won’t have much impact from ignoring it.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#24
post #17

Earlier quoted context omitted.

You can not trust the user. Never.

How does that work in parallel with "It's my device, I'll do what I want with it"?

Ask the user what kind of device it wants. (And then when the user says give me the developer hyper bleeding edge pro X, because my mom needs 4K cat videos, then maybe try to persuade the user that the regular non-devkit version would be the sane choice.)

And in the dev version protect the dev mode by some small ritual (like the 7-times tapping on About in Android).

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#25
post #3

> when some malware does manage to slip an evil kernel extension past a user and is rewarded with the protection of SIP, neither the user nor any anti-malware tool will be able to remove that extension, unless the user restarts from a different boot volume, or KernelExtensionManagement allows it. But isn't that scenario "Game Over" anyway? At least installing kernel extensions is a process that is explicit and - impo…

You can not trust the user. Never.

I'm an user too and I'd like to be treated like an adult by my operating system.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#26
post #5

The article doesn't mention that this is not new; nor is it 'the' app you can't trash: it joins Safari, Finder, and most other 'Apple apps'. I find it quite surprising. Even when Windows defaulted to IE without choice, it could always be removed with 'Add or Remove Windows Features', as I recall.

I think the difference is that those apps come preinstalled by Apple. Most users would think, if I install a bit of software, I can remove it later. That's normal behavior. If the KEXT installation process has a way of getting software into the special hidey-hole, it should provide a way of getting software out of it again if it is user-installed.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#27
post #20

Earlier quoted context omitted.

> not just another 'trained to ignore' permissions dialog. I have never seen any user reading a dialog message if it has a button with label "ok", "cancel", "allow" or "next". Including a lot of developers/dev-ops.

The dialog for kernel extension doesn't contain any of those labels though. Instead it offers you to open the "Security" preference pane where some additional UI will be displayed. If you blindly click buttons you will not accidentally enable a kernel extension.

> If you blindly click buttons you will not accidentally enable a kernel extension.

As someone who's gone poking around system internals for twenty-plus years... I can tell you that you're very wrong here. I've forgotten about more completely broken operating systems than I care to discuss, but many of them have ended with me poking around and blindly clicking buttons in a vain hope of getting the OS to do what I want it to do which is apparently frequently different from whatever OS producers want me to do.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#28
post #3

> when some malware does manage to slip an evil kernel extension past a user and is rewarded with the protection of SIP, neither the user nor any anti-malware tool will be able to remove that extension, unless the user restarts from a different boot volume, or KernelExtensionManagement allows it. But isn't that scenario "Game Over" anyway? At least installing kernel extensions is a process that is explicit and - impo…

You can not trust the user. Never.

This is essentially the mindset of iOS, which I think most folks would agree is more secure than macOS. It's much easier to secure a device when you can take this for granted.

Unfortunately, a lot of people still use computers instead of iOS devices explicitly because they want more control and power over what the machine is doing. Security is a lot harder to do in this case.

Ultimately, you can't protect a machine from an empowered user. The best you can hope for is to provide guide rails that make it easier to do the right thing, and harder to do the wrong thing.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#29
post #23
post #17

Earlier quoted context omitted.

How does that work in parallel with "It's my device, I'll do what I want with it"?

Make dangerous things hard to do, but not impossible

So someone could make a script simplifying them :)

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#30

-"MacOs is too closed! Apple lock the user" (Now you can install kernel extensions) -"It's insecure!

Apple in general has always been a bit further in this direction, but it seems companies are increasingly leaning towards security over freedom, which is perhaps even more scary than insecurity itself. It's a hard position for a company to be in, but I suppose it comes from the fact that it seems receiving negative PR about being insecure is worse than PR about being unfree.

As a memorable saying goes: "The security people won't be satisified until everyone is living in prison."

Post reply on HN