Live data from Hacker News

The ‘app’ you can’t trash: how SIP is broken in High Sierra

eclecticlight.co

31–40 of 100 posts

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#31
post #20

Earlier quoted context omitted.

The dialog for kernel extension doesn't contain any of those labels though. Instead it offers you to open the "Security" preference pane where some additional UI will be displayed. If you blindly click buttons you will not accidentally enable a kernel extension.

> If you blindly click buttons you will not accidentally enable a kernel extension. As someone who's gone poking around system internals for twenty-plus years... I can tell you that you're very wrong here. I've forgotten about more completely broken operating systems than I care to discuss, but many of them have ended with me poking around and blindly clicking buttons in a vain hope of getting the OS to do what I wan…

You may want to use the workflow yourself to see how it differs and re-evaluate. It surprised me.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#32
post #5

The article doesn't mention that this is not new; nor is it 'the' app you can't trash: it joins Safari, Finder, and most other 'Apple apps'. I find it quite surprising. Even when Windows defaulted to IE without choice, it could always be removed with 'Add or Remove Windows Features', as I recall.

You forgot to mention Chess. You can't trash Chess.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#34
post #18

This post annoys me for describing a problem which other people might encounter with a good level of detail but uses “broken” to get clicks rather than the more accurate “I don’t understand or agreee with the security model”. As misnome and others have noted, if someone loads a malicious kext the only safe option is a complete wipe and reinstall – or depending on how much you trust Apple’s firmware signing, buying a…

I agree with the post --- this is broken behaviour regardless of whether you agree with the security or not --- if you have permissions to install something, you should also have permissions to remove it, and vice-versa.

If you're really into "higher security", then saying they shouldn't have the permissions to install it in the first place would also make sense, but this weird "can install but can't remove" doesn't.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#35
post #17

Earlier quoted context omitted.

You can not trust the user. Never.

How does that work in parallel with "It's my device, I'll do what I want with it"?

It doesn't.

We've had user-based permissions in the mainstream on personal devices ever since XP, and they have totally failed to protect us from anything. It is an utterly broken, worse than useless, backwards model of security for this class of device.

If you think I'm wrong, by all means tell me why instead of just downvoting like some reddit user. I'll happily provide you with a list of all the ransomware that didn't require even a single elevated permission to ruin someone's day.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#36
post #18

This post annoys me for describing a problem which other people might encounter with a good level of detail but uses “broken” to get clicks rather than the more accurate “I don’t understand or agreee with the security model”. As misnome and others have noted, if someone loads a malicious kext the only safe option is a complete wipe and reinstall – or depending on how much you trust Apple’s firmware signing, buying a…

On an organization's network, protecting resources from the user is a concept that makes sense.

On personal devices, protecting anything from the user is a backwards and broken model that doesn't respect reality. It's the user's device, they should be able to use it any way they want. There is no need, or desire, to protect it from the user. What we really want to do, is protect the user's data from malicious actors, and getting in the user's way and annoying the crap out of them doesn't accomplish that at all (case in point: ransomware).

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#37
post #18

This post annoys me for describing a problem which other people might encounter with a good level of detail but uses “broken” to get clicks rather than the more accurate “I don’t understand or agreee with the security model”. As misnome and others have noted, if someone loads a malicious kext the only safe option is a complete wipe and reinstall – or depending on how much you trust Apple’s firmware signing, buying a…

On an organization's network, protecting resources from the user is a concept that makes sense. On personal devices, protecting anything from the user is a backwards and broken model that doesn't respect reality. It's the user's device, they should be able to use it any way they want. There is no need, or desire, to protect it from the user. What we really want to do, is protect the user's data from malicious actors,…

> On personal devices, protecting anything from the user is a backwards and broken model that doesn't respect reality. It's the user's device, they should be able to use it any way they want.

I want to be protected from myself. I want my mom to not have to think about how she's using her device in order for her data to be safe.

> What we really want to do, is protect the user's data from malicious actors, and getting in the user's way and annoying the crap out of them doesn't accomplish that at all (case in point: ransomware)

Ransomware (at the time of writing) doesn't impact locked down platforms like iOS.

I'm happy to lose that freedom in exchange for protection!

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#38

Earlier quoted context omitted.

On an organization's network, protecting resources from the user is a concept that makes sense. On personal devices, protecting anything from the user is a backwards and broken model that doesn't respect reality. It's the user's device, they should be able to use it any way they want. There is no need, or desire, to protect it from the user. What we really want to do, is protect the user's data from malicious actors,…

> On personal devices, protecting anything from the user is a backwards and broken model that doesn't respect reality. It's the user's device, they should be able to use it any way they want. I want to be protected from myself. I want my mom to not have to think about how she's using her device in order for her data to be safe. > What we really want to do, is protect the user's data from malicious actors, and getting…

Then you should be able to get that behavior out of your OS if it is what you want. By all means, give yourself a web kiosk that runs on an overlay fs over a read-only boot media. I've set that up for people.

Ransomware isn't a huge problem on iOS because, like Android, the permissions apply to the application, not the user account. That's a model that makes sense.

Re: The ‘app’ you can’t trash: how SIP is broken in High Sierra

#39
post #16
post #15

Earlier quoted context omitted.

This seems a bit hyperbolic. I do, and I'm pretty sure a lot of people do - especially developers; and especially dialogs that you didn't explicitly expect. Not saying that the majority do; or that a dialog is "good security protection". I just don't think it's as useless as you seem to imply.

It’s exaggerated but only slightly. Some of the worst messes I’ve seen were people who should have known better just blindly pasting google search results because they didn’t have time to do it right. More developers than sysadmins but definitely not exclusively so. Never underestimate the degree to which people are rushing or not questioning whether their initial diagnosis was correct.

I would add that these kinds of "Normal users click accept/next" are how "offers" on software gets installed.

Case in point: uTorrent. Download and "install". You will, generally, get 2 screens that install junk. On one screen you can click "Decline". On another, you can click "Skip". These screens are between all the normal "which folder", "do you accept" and "thank you" screens.

Case in point: Adobe Reader... download it from their website WITHOUT unchecking the "Optional Offers". You then have a Reader with Benefits.

I consider myself "trained" and "knowledgeable" and I occasionally get bit by these... sidecars... included with desired software.

I have no faith that 95% of people know how to sidestep these "landmines". Decline? that means "don't install". Skip? Why would I skip an important part of the installation.

Post reply on HN