Also, don’t irritate any nation states.
Also, while SIP wouldn't have helped in this particular situation, consider if it's really necessary to disable it. Living with SIP on is occasionally cumbersome, but I don't trust myself enough to run without it on, even as someone who's been a technically-minded computer user for coming up on a quarter of a century and a dev for over half of that.
If disabling SIP is ever truly necessary for me I think I'd do it in a VM. Especially on M-series machines virtualization of macOS has gotten quite good.
If Linux were to become my daily driver OS I'd probably enforce a greater degree of separation between machines, with e.g. one Linux box exclusively for work things, another for finance, etc which is pretty easy to do with cheap old laptops. This limits the potential blast radius and reduces chances of getting hit in the first place, with e.g. how there's no good reason to run random untrusted binaries on the finance laptop.
There are two categories of Mac malware: Ones where you have to enter your admin password into something that should have already raised several red flags by the time you see the prompt, or zero-days that are so stratospherically expensive that if you are an individual who would be targeted by one, malware is only one part of your overall threat model.
For the less paranoid, Mac malware is still incredibly rare if you only download and execute files from trusted sources (preferably the Mac App Store)
And keep all software/OS up to date.
PS - slightly unrelated but I’ve always been so confused as to why Mac comes with the firewall disabled by default.
Unfortunately these are design weaknesses, so any "software stack" would just be a bandaid.
macOS as many times more secure than the Linux desktop. The only reason Linux is not a malwarefest is because the market share is so small that it is not that interesting.
[1] https://0pointer.net/blog/brave-new-trusted-boot-world.html
If any government has backdoors in macOS outside open source software in macOS, it is probably very limited (the US government if any, but Apple seems to resist most attempts at weakening security).
[1] https://arstechnica.com/information-technology/2010/12/fbi-a...
That’s much harder with open source software, not due to technical reasons, but because there is a good chance that eventually it will be discovered by some developer or security researcher. That will cause distrust of the government, and people going to defensive mode, making it much harder for governments to routinely hack into devices.
So, for example, the discovery of the flaw in the Debian random number generator had a huge impact. People who design security systems really pay attention to PRNGs nowadays (to the point that it seems weak PRNGs are no longer a significant concern in the mainstream desktop operating systems, though the issue obviously remains in IoT, virtual machines, HSMs etc).
Hiding the code for malware is common sense. That’s also why governments severely punish leaks these days.
But when thinking about state actors they almost have unlimited money/resources thus even if adding a backdoor is a bit harder on open source having unlimited money/resources makes it irrelevant.
Where “unlimited” = to the size of the open source organisation that maintains a bit of software.
It's easy to detect backdoors in closed source applications.
People should definitely be using open source for as much as possible, because I want to live in a world that makes it as easy as possible for beginners to understand how their underlying software systems are working. The whole "backdoor" FUD just seems lazy though.
No reason to make your life harder unless you’re doing it for your own enjoyment.
This is something that hasn't been fixed despite years of complaints from the security community for exactly this reason.
It's especially annoying as touchid provides a standard authentication mechanism on macOS, that doesn't provide reusable credentials to anything.