Restart macOS, holding ⌘+R. Open Terminal. Type `csrutil disable`. Restart macOS again.
Any day now…
But as far as I'm aware the reasoning is that if there's a way to access something from a normal user account (with admin privileges) it can be abused somehow.
Maybe a "key" would be the ability to boot/log in to a special mode with SIP enabled. Disabling/enabling it approximates this, but as far as I know an update will generally destroy your changes because Apple will just overwrite everything.
Stallman was right about "treacherous computing".
https://forums.macrumors.com/threads/if-you-disable-sip-all-...
I'm not sure what it really does (could not find any docs, maybe someone can enlighten?) but the text made me think it could allow stuff like running unsigned debuggers:
Allow the applications below to run software locally that does not meet the system's security policies
Again I'm really not sure, but maybe it can cover some use cases without going the nuclear route of fully disabling SIP?Funny thing is all computers used to run without SIP, but since they added it I’m now hesitant to turn it off even though I’m not any worse off than I used to be.
https://appleinsider.com/articles/19/09/25/google-chrome-upd...