5 ms·
Users can develop and install custom kernel extensions (.kexts) that can access everything, but they first need to disable System Integrity Protection in recove
by terramex 6y ago
Users can develop and install custom kernel extensions (.kexts) that can access everything, but they first need to disable System Integrity Protection in recovery mode.
Over the years Apple expanded their frameworks library to reduce need for custom .kexts, but they are still supported even on M1 Macs (as long as they are compiled for ARM64).
So to answer you question - 'root' user on macOS is by default not a true root in unix sense, but can be trivially turned into one by booting computer in recovery mode and running single command in Terminal. Restart into recovery mode is required so that malicious applications cannot change it on their own, even if they would use unknown privilege escalation technique.
- filleduchaos 6y agoIt's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. The most egregious was someone complaining that /bin and other system folders are read-only [on systems under System Integrity Protection]. Surely anybody with a pressing desire to e.g. upgrade their bash install or any other thing that requires write access to those folders is also capable of figuring out how to turn off SIP?
- danieldk 6y agoIt's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well?
- deleted 6y ago[deleted]
- bergstromm466 6y ago> It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well? This. Apple is making the use of many security functions black or white: either you allow complete control by Apple, or you have little to no protection at all. Instead they could easily allow the user to customize, and make a selection that works for them (which was the standard in older versions of OSX - pre-Big Sur [1]). The above defending of a giant faceless corporation, by @filleduchaos, is what is mind-boggling. This feature obviously helps protect some users (non tech-literate ones), but for many it means completely turning off many useful security features ('opting out' by turning off SIP) with a lack of any sort of granular control/customization, on a device they supposedly own. It's a shame this new capitalist encroachment on user privacy is met with such understanding. [1] https://news.ycombinator.com/item?id=25078034 https://news.ycombinator.com/item?id=25078034, https://sneak.berlin/20201112/your-computer-isnt-yours/ https://sneak.berlin/20201112/your-computer-isnt-yours/
- vezycash 6y ago>Apple is making the use of many security functions black or white: either you allow complete control by Apple, or you have little to no protection at all. In that respect, no Apple's no different from Facebook's "agree to share your data or take a hike" move with WhatsApp
- sbarre 6y agoIt's extremely different. In Apple's case we're talking about a personal computer that someone paid a few thousand dollars for and is their general purpose machine for their own private affairs (unrelated to Apple), and in Facebook's case you're talking about a single-purpose centralized communication app that is free.
- FabHK 6y ago> This feature obviously helps protect some users (non tech-literate ones), but for many it means completely turning off many useful security features [...] I'm pretty sure you have the "some" and "many" the wrong way around. In reality, this feature protects many users (non tech-literate ones), but for some that feel the need to turn it off, it, well, won't protect them, because it's turned off.
- filleduchaos 6y agoStrangely enough you can re-enable SIP after making the changes you need to let you or your desired applications do what you want.
- ArchOversight 6y ago> letting Apple services go through a VPN as well Apple Services go through a VPN as well. A VPN redirects all traffic and does not use the content filtering framework which allows the Apple services to bypass restrictions. So if you install a VPN it will happily route all traffic over it, including traffic from Apple's own applications.
- m463 6y agoI wonder if it's possible to turn all this on before activating the machine?
- saagarjha 6y agoSystem directories are sealed as of Big Sur; disabling SIP is not enough to be able to modify them.
- Wowfunhappy 6y agoYou can still modify them though. It's just, uh, annoying.