Apps shouldn’t be able to read my entire hard drive unless I give it permission. And the core OS should be immutable.
Also not sure what you’re talking about. Custom mouse drivers of course still work.
Apps shouldn’t be able to read my entire hard drive unless I give it permission. And the core OS should be immutable.
Also not sure what you’re talking about. Custom mouse drivers of course still work.
I had Firefox, Thunderbird, Pidgin and a few others running in complete isolation from the base system, and from each other. I even had a separate Firefox jail that was only allowed to get out via a Tor socks proxy to avoid leaks (more of an experiment than a necessity, to be fair).
Communication between jails was done via commonly mounted nullfs. I have also setup QoS via PF for each of them.
They were all running on the host’s Xorg, which was probably also the weakness of this setup.
It was a pretty sweet setup, but required quite a bit of effort to maintain, even tho I automated most of the stuff.
Now I use macOS, and I would like more control over what apps do what. I’m not particularly impressed with the direction of the UI (it also doesn’t bother me terribly), but I welcome the finer grained security control.
References:
[0]: https://en.wikipedia.org/wiki/FreeBSD_jail
[1]: https://www.freebsd.org/cgi/man.cgi?query=jail&sektion=8&for...
Or maybe I'll attempt to contribute the important parts to an established project, like ezjail [0][1], which seems to be quite competent at handling jails, but is specialized on running services.
Refs:
[0]: http://erdgeist.org/arts/software/ezjail/
[1]: https://www-legacy.freebsd.org/doc/en_US.ISO8859-1/books/han...
For one thing: I always require certificate logins on SSH. On Mac I used to simply change /etc/ssh/sshd_config to this effect, but since Catalina macOS reverts this with every update. Clearly they don't want me poking around in there :(
IMO if you offer SSH you should offer certificate-only access as well, either with a glitzy on/off button or with a config file change, whatever. But nope...
With Apple you get a lot of security for 'free', however you give up a lot of customisation in return, even in terms of security features.
You can override it with a commandline flag but that would mean changing the launchdaemon which is protected by SIP as far as I know. But I will have a look for that to doublecheck.
The resistance to them seems to be largely due to lazy developers: it would be EASIER if the system let a developer do whatever they want with a “trust me, I’m smart” justification. But we can’t design for the occasional safe and smart developer: we need to design for the sloppy ones and the malicious ones. The smart and safe ones can find a way to work within the constraints. As for lazy and sloppy ones who can’t adapt to the constraints - adapt.
OS security is generally a shit show anyway. I don't think it's bad to lock down the OS for most users, but it should still be possible for expert users to get expert access.
If there are security consequences, they should be trusted to learn how to deal with them.
Most will - and the rest will have bad experiences.
Last I checked, it still is—IIRC, you have to run some specific commands in Recovery Mode to disable the protections, but for "trust me, I'm smart" developers, that shouldn't be a problem.
Personally, I haven't seen any particular need to do that. I can count the number of times I've been blocked by SIP from doing things I wanted to do on one hand, and none of them were critical.
Unix file access permissions designed 50 years ago for multi-user shells are not adequate when dealing with potentially hostile applications accessing your data.
Today I'm more worried of a random App encrypting $HOME or hoovering up all my PII.
Also, actively circumvent protection devices is proof of malice and possibly even criminal intent (remember DMCA?) so I don't see your point.
I don’t think so.
Now if some people just give access to everything instead of using ACLs, that is another matter.
I've been trying unsuccessfully to childproof a Big Sur laptop for a 12 year old for some time now — disable access to some built-in apps etc. I have yet to figure out how, without resorting to disable SIP.
There is Screentime, but that's an unreliable joke which has caused us a massive amount of headaches on iOS due to unreliability, has very limited features and can only be protected by a 4-digit PIN.
"Configuring which programs a restricted user can run" is _such_ an elementary task for an OS that I cannot believe that recent macOS has no provisions for that. I _must_ be missing something.
Now how do I turn off the dozens of daemons that go everywhere on the internet without my control, uploading telemetry, etc? I've still not figured out how.
I’m not saying it’s bad. More security is great! My kids use MacOS. I’m grateful for it. I love iOS too. But it’s absolutely dumbing the OS down and making it less of a professional machine.
- docker - you need to be able to bind any folder
- IDE - you need to be able to edit basically anything
- office software beyond "I have some things in 'Documents'" - same
- python, ruby, any other interpreter - same
- brew, or any other package manager - same
etc. This simply doesn't work well for many developer workflows. I tried to use a dedicated app for per-app security control like that (can't remember the name anymore) - but for development it was a disaster. It just makes you click "allow" on a popup 10 times a day until you stop paying attention. Now, macos is not at that level yet, but the direction towards that is the complaint usually.
Consider: An interpreter needs to run homebrew which installs new app, but the same interpreter running a script for your project should not read anything apart from those project files. Same interpreter needs to update local packages via bundle and git, but a random script you run shouldn't be able to access your ssh key via git commands. This is basically impossible to achieve without large compromises outside of selinux right now.
So how would you apply this principle to the python interpreter or to a program that gets compiled to a new executable many times during development?
I like the idea of granting folder permissions to regular third party apps I install and use. I always wanted that and I'm glad Apple is moving in this direction with the Mac.
But contrary to regular apps, language runtimes and software under development do not have a specific purpose. The whole point of software development is to create and test arbitrary code. It is pointless to grant privileges to code that changes in arbitrary ways with every keystroke.
During development, privileges have to be granted to the developer account, not to any particular software artifact. I generally think that granting privileges to software and granting privileges to people each has its legitimate place. One isn't generally better or worse than the other.
..and, office?! Do you keep spreadsheets in system folders?
I keep spreadsheets in project folders. Allowing full writes to a project folder allows taking over the shell. See above.
Folder-level permissions are not sufficient. Sorry, I shortened it too much, but basically - there's almost no practical difference between allowing writes to a dev project folder and allowing writes everywhere. (It would stop some really trivial attempts) Your actual system folders are safe of course... but who cares about those really?