This can be disabled but I wouldn’t advise doing so unless you have a really good reason to.
This can be disabled but I wouldn’t advise doing so unless you have a really good reason to.
> a really good reason?
I think access to my own filesystem is good enough. I admit when I looked at the reviews, I made sure there were no major issues before upgrade but missed this "sys integrity" thing.
Since it is possible to disable, why not disable it as-needed rather than always?
i am. ;)
Windows also has the System Integrity Protection equivalent.
Game Center is ~4MB, and you'll never remove all the potential "phone home" hooks without rewriting the OS. Your approach is akin to taking wheels off a car to reduce weight so it goes faster.
If I may say so though, I think you're coming at this the wrong way.
Trying to disable every component in the OS that phones home simply doesn't scale, may I suggest you explore gateway firewall devices such as PFSense, or the free version of Sophos' UTM if you prefer a more polished UI?
I use a Sophos UTM at home and I can see (and block) every request that my Macs use to try to phone home, with HTTP, HTTPS or regular network traffic.
I also use the Always-On VPN on my phone to apply ad blocking at the firewall level which protects my phone as well.
Very much worth checking out. Gateway protections are the only way to go these days IMO.
Edit: Just to add, at first glance I find the SIP system to be rather anti-user, but people in this thread are right. It's valuable protection to have in place. If I used a Mac at home I would only disable this to make the changes I needed before turning it back on again.
Edit to clarify: I use a Mac, but only has a HTPC and not as a desktop or workstation, and all outbound traffic is blocked by default.
I will look into those suggestions. Do to the differences and additions in caputan little snitch does not work. I havent connected to internet yet whoch ice floor needs to be configured properly. Does SOPHOS UTM work well even as a free version. It is annoying when snitch lets traffic out after 3grs.
As sad as this will sound, I cant afford a VPN. I set one up myself using OpenDNS and tunnelblick, which I should probably spin back up. Any other security suggestions? I can only use free stuff ATM .
The utm itself actually hosts and serves the VPN connection by the way. My phone connects directly to the VPN on my UTM. You'll see a speed hit because of the extra hop unless you put your utm in the cloud.
I hope that's helpful :)
The current state of affairs means that users - even non-technical ones - are routinely asked for their admin pwds in everyday use, but every time they enter it they are susceptible to be totally and utterly pwned.
Even expert users fall victim when they turn off system safeguards - XcodeGhost being only the most recent example, where only users who actively disabled Gatekeeper/codesign checking were susceptible.
It's kind of annoying for power users, but time and time again I think we've proven that power users aren't in any way immune to social engineering or simple blanket malware attack.
> > a really good reason?
Honestly, as devs, we're more susceptible to this kind of attack than the average user, not less (e.g. see XcodeGhost). System integrity protection is great for us, yet I see a great deal of hubris when it's mentioned–as if we're somehow immune, or that we audit all the code we run.
I download all manner of tools for development work, and use sudo as and when necessary, and I'm thankful there's now an extra layer of security. If I needed to modify the filesystem (e.g. if I wanted to delete an app like another poster did), I'd disable SIP temporarily to do so, and I think that's fine, but I think it would be unwise to disable it permanently, especially on a whim. I would hope that modification of these sorts of files would be rare enough that it's not a big inconvenience anyway.
No. Not Game Center.app. Grand parent is right, this is bloatware that neither he, nor I, nor many others want. If I wanted a bloatware Windows box I would have bought one. There's no excuse for making this app non-removable.
On the other hand, if we’re talking about the junk that your average Windows or Android device comes preinstalled with that is either configured to run at startup and/or modifies the stock UI (TouchWiz for example), yeah, that’s definitely bloatware and it’s reprehensible to make that unremovable. That isn’t what Apple is doing, however.
No, it doesn't, but what does bother me are the gigabyte+ apps that, like Game Center, Apple does not allow users to remove (without jumping through hoops that are probably both scary and technically challenging for most users).
Are you an Apple fan? Because I am (or was). I've been with Apple since the OS 7 days.
This lack of attention to detail is very uncharacteristic of the Apple I knew and loved.
The comparison to "what others are doing" is also very un-Apple like. Apple did not use others as a benchmark to decide what it should be doing, and the day it starts to do that is the day it's no longer Apple.
While the attention to detail is lacking, it is becoming even more walled off. I reapect that because the market wants all there stuff synced all the time. Howecer, i don't. I dont need my search results sent to apple so i can get recommendations, i font want every message i text to be an imessage so it goes through there servers as well as att. I am disappoinr.
On 10.11, there are many apps that are not deleteable, but all of them seem to be under a gig (unless I'm missing something because I had, long ago, deleted an app and the OS update didn't restore it).
These include: Game Center, iBooks, Safari, iTunes, Photos, Contacts, Maps, Automator, Font Book, Dictionary, Notes, FaceTime, Chess, Reminders, Photo Booth, and perhaps a few other small-ish apps. These are less than 1 gig. I don't know why Apple did not choose to simply make whatever is so vital in the app bundle a system framework instead.
It's not a big deal to me if these small apps are non-deleteable. I assumed—incorrectly—that the big ones (iMovie, Garage Band, etc.) were non-deleteable as well.
I used game center as an example. Of coure the launchctl list uses an insane amount of resources for apple stuff. I also deleted several other apps and a few other things. Shit, running monolingual alone saved me ~1.2GB.
So thanks. I agree as well. If possible I will turn it back on after.
what happens when you assume apps that came with the OS are legit?
You can't do that unless you turned it off in the first place. And if you did, you're on your own anyway.
On the other hand, maybe this question is rather stupid as I really can't see Apple scaring away the developer community in such an unnecessary way.
/usr/local is not one of the SIP protected paths. The idea behind SIP is to protect system binaries from being surreptitiously patched by malicious parties, not to make the system totally useless.
> Reading about it, one might think 10.11 could have problems with someone trying to use anything but the system-shipped ruby version, or python, etc.
Aside from being really stupid from a customer standpoint, what would be the security benefit of doing this?
> /usr is shareable, read-only data. That means that /usr should be shareable between various FHS-compliant hosts and must not be written to.
Pretty much all modern unices consider that /usr, aside from /usr/local (which the FHS defines as "for use by the system administrator when installing software locally. It needs to be safe from being overwritten when the system software is updated."[1]), is part of the operating system.
It is thus very much unusual to modify /usr[2], and in line with current practices to lock it down tightly.
/usr/local is not under SIP.
[0] http://refspecs.linuxfoundation.org/FHS_3.0/fhs/ch04.html#pu...
[1] http://refspecs.linuxfoundation.org/FHS_3.0/fhs/ch04s09.html
[2] in fact the FHS specifically notes[3]:
> Software placed in /usr may be overwritten by system upgrades. For this reason, local software must not be placed outside of /usr/local without good reason.
"we specify that the system can overwrite or remove anything you put there" is pretty much a dead ringer for "modifying this is unusual"
[3] http://refspecs.linuxfoundation.org/FHS_3.0/fhs/ch04s09.html...