4 ms·
On a Mac, just keep up with software updates and think really hard before overriding security warnings. Also, don’t irritate any nation states.
by mwint 3y ago
On a Mac, just keep up with software updates and think really hard before overriding security warnings.
Also, don’t irritate any nation states.
- kitsunesoba 3y ago> On a Mac, just keep up with software updates and think really hard before overriding security warnings. Also, while SIP wouldn't have helped in this particular situation, consider if it's really necessary to disable it. Living with SIP on is occasionally cumbersome, but I don't trust myself enough to run without it on, even as someone who's been a technically-minded computer user for coming up on a quarter of a century and a dev for over half of that. If disabling SIP is ever truly necessary for me I think I'd do it in a VM. Especially on M-series machines virtualization of macOS has gotten quite good.
- olliej 3y agoI've literally never had a need to disable SIP. About the only reason you could possibly need to is if you're doing particularly weird kernel driver development, and I'm not sure that's needed even then.
- kitsunesoba 3y agoI think the most common cited reason to disable it that I've seen is the ability to attach a debugger to any program, even those using the hardened runtime, which isn't something I've needed thus far.
- saagarjha 3y agoThat’s not true, debugging system components is an important use case.
- josephcsible 3y agoDo you trust yourself to use Linux, even though it has no equivalent to SIP?
- kitsunesoba 3y agoAs things stand currently, sure. Nothing critical or tied to my livelihood is done on my gaming tower's dual booted Fedora install, it's mainly there to scratch tinkering itches. Similarly that tower's Windows install is used only for games and MS platform tinkering. If Linux were to become my daily driver OS I'd probably enforce a greater degree of separation between machines, with e.g. one Linux box exclusively for work things, another for finance, etc which is pretty easy to do with cheap old laptops. This limits the potential blast radius and reduces chances of getting hit in the first place, with e.g. how there's no good reason to run random untrusted binaries on the finance laptop.
- mortenjorck 3y agoThis is really the only Mac security advice anyone needs. There are two categories of Mac malware: Ones where you have to enter your admin password into something that should have already raised several red flags by the time you see the prompt, or zero-days that are so stratospherically expensive that if you are an individual who would be targeted by one, malware is only one part of your overall threat model.