https://github.com/shadowsocks/shadowsocks-iOS/issues/124#is...
Even with root account, you are not in full control of your Mac - you are sandboxed by Apple.
https://github.com/shadowsocks/shadowsocks-iOS/issues/124#is...
Even with root account, you are not in full control of your Mac - you are sandboxed by Apple.
It's a big step in the wrong direction [opinion], especially because it does nothing to verify "integrity". It prevents changes to the System directory by conventional means (and injection into system processes).
If malware were to figure out a way to disable SIP from userland, it could install itself in such a way that nothing short of disabling SIP could uninstall it.
(I have limited experience with OS X - only briefly played around with driver development and bootloaders in the 10.4 era with osx86 - and I did have to boot from the DVD a few times when I made the system unbootable.)
This raises the question, what good is root if it's not really root anymore?
It's easier than that. It's just a kernel argument to disable it. Simply add "rootless=0" to your boot-args and you have control of your machine back.
I'm running the 10.11 beta and I've already had to disable rootless because I like to have /usr/local as a symlink to somewhere else and by default the rootless configuration prevents writes to /usr. :-/
They know that rootless will break some applications/drivers, plus some types of development may need it disabled.
https://www.reddit.com/r/osx/comments/3hv3kk/update_on_rootl...
The idea is that a combination of a SecureBoot-style trusted boot sequence and technologies like Intel's SGX instructions to create an area that is protected from everything else, root included.
Ever since (heavily controlled) iOS was accepted by the tech crowd as a replacement for a proper General Purpose Computer, we've been slowly loosing more and more control. At least there seems to be workarounds for this particular OSX "feature". It is incredibly important to stop this trend now; it will be a lot harder to work around these restrictions when it gets hardware support.
However, this argument falls down a little if malware doesn't actually need to modify system files, which it doesn't for most typical evil stuff I can think of.
Since all System locations will now be signed (as part of the move to SIP), it means that the basic Apple recovery partition will be able to purge any such malware by a simple signature verification.
"all dtrace probes that target a system restricted process will not be matched" (i.e. will fail unless SIP is disabled).
But lets say you don't find a vulnerability in SIP userland detection, and instead find a kernel exploit to get around the protection:
If malware were to figure a way around it, then even antivirus software can't uninstall it. Only Apple can. It's not FUD.
SIP holes will be found, and Apple will patch them just like other security flaws.
With the condition that you have to upgrade to the very latest system :)
At the very least, the OS needs to be reinstalled from an off-disk source, and that's assuming you haven't been hit by something sophisticated enough to put itself in firmware. We're fast approaching an era where you need to trash the hardware. You should never trust an OS install that was ever compromised, and making it more difficult to do so is a good thing in my book.
[1] https://developer.apple.com/library/prerelease/mac/documenta...