3 ms·
Immediately upon reading 'csrutil disable' I thought of 'setenforce 0' and the fact that this is usually the first measure taken to deal with SELinux by many us
by drvdevd 11y ago
Immediately upon reading 'csrutil disable' I thought of 'setenforce 0' and the fact that this is usually the first measure taken to deal with SELinux by many users, usually against better judgement. However this, like SELinux, begs the question: is this a good user interface design? Or simply a small stumbling block for malware authors? I suppose the devil is at least partly in the details: can a kernel exploit at runtime easily flip a few bits somewhere and disable SIP?