4 ms·
Yes, without drivers for the SoC and other Apple hardwares, we may only have hackintosh kind of OSes on these ARM Mac. Moreover, you have to cripple your own m
by webmobdev 6y ago
Yes, without drivers for the SoC and other Apple hardwares, we may only have hackintosh kind of OSes on these ARM Mac.
Moreover, you have to cripple your own macOS to run others OS, which seems a deliberate design to discourage users:
> Permissive Security: Does not enforce any requirements on the bootable operating system. Note: The Permissive Security option appears only when System Integrity Protection (SIP) is disabled. To disable SIP, start up your Mac in macOS Recovery, open Terminal, then run the command csrutil disable.
- josephcsible 6y agoDisabling SIP doesn't cripple macOS.
- arcticbull 6y agoIt simply affords you the same level of security enjoyed on macOS up to and including 10.10 (Yosemite) -- which was state of the art until July 9, 2018.
- josephcsible 6y agoAre Windows and Linux insecure? They don't have anything like SIP. Also, the whole idea of SIP has a strong https://xkcd.com/1200/ https://xkcd.com/1200/ vibe.
- warkdarrior 6y agoWindows has Windows Resource Protection (previously known as Windows File Protection) with same goals as SIP. SELinux for Linux can achieve similar levels of protection.
- Wowfunhappy 6y agoWindows Resource Protection doesn't prevent code injection, and can be disabled from within the OS. I don't consider them equivalent.
- Wowfunhappy 6y agoIt's worth noting that macOS without SIP is a bit more permissive than Windows—it allows you to load unsigned kernel extensions, for instance, whereas 64bit Windows will not load unsigned drivers†. But I generally agree—power users should feel fine disabling SIP.
- crb002 6y agoDisabling allows you to run dtrace...
- floatingatoll 6y agoOn Apple Silicon, you may lose access to e.g. Touch ID login to websites and Apple Wallet, as Apple’s Touch ID protocol allows^ websites to require a secured+unmodified system partition and Wallet may require the same for anti-fraud purposes. I expect Steam VAC and Xbox cross-platform multiplayer will take note of this someday, too. This relates closely to the likelihood of future PCs with Microsoft Pluton^ firmware as well. I assume that Microsoft saw the writing on the wall about secure OSes and remote education and online testing and is repurposing their Xbox anti-tampering system for Windows before they get locked out of that market by Apple Silicon. It’s not about disallowing you from tampering, or about blocking third-party operating systems — it’s about attesting whether or not you are able to tamper, in scenarios where a remote third-party has no physical access to your system. The Linux secureboot shims probably will not be sufficient to earn ‘tamperproof’ as they boot arbitrary unsigned code with tamper-capable privileges via /sbin/init or whatever. ^ via crypto-signed attestations by the Apple firmware+OS, working in tandem to attest that the stack is not and cannot be tampered with as currently booted. ^ https://news.ycombinator.com/item?id=25123990 https://news.ycombinator.com/item?id=25123990 EDIT: Apologies, the missing paragraph connecting to the parent comment is — IT departments will begin updating SSO/MFA systems to require, when deployed hardware permits it, the tamperproof attestations. This will protect them from the liability risk of employees turning off key security protections such as SIP, and may result in Apple Silicon being widely adopted by sensitive industries such as banking and IT once they realize they can reduce their risk and liability insurance costs by doing so.
- josephcsible 6y agoSo SIP isn't about keeping me secure. It's about keeping my computer secure from me.
- floatingatoll 6y agoKeeping you secure requires keeping the computer secure from attackers. You can't be distinguished from an attacker, from the computer's perspective. Having the computer be able to attest that it's unmodified means that it doesn't have to mistrust you so aggressively, relative to today. Requiring a reboot to rescue mode to disable SIP is sufficient to block most social engineering attacks that would otherwise have you click through dialogs to bypass it. A dedicated attacker can still overcome this, and once they do, they can impersonate you readily. If the computer can attest that it's unmodified, then it's possible to throw up alarms for non-expert users when their computer is in that state. I don't think most websites will bother, but those that care sure would love to be able to do so. None of this is specifically for the benefit of users who want to hack the software internals of their computers, though — but those are not the target market for security practices today in any case, since they can overcome literally any barrier prior to this that says "please secure your device before entering". Still, from an IT standpoint, it sure would be nice to find out how many expert technical users are lying about keeping their system in secure mode when they have privileged access, because they don't think it's necessary and they don't see any harm in lying about it. I'm guessing it's something like 10-20% of all IT admins using unmanaged devices. We'll find out soon enough!
- kevinh456 6y agoBased on the presentation from WWDC, each OS partition can have a different security policy.