Help doc: https://support.apple.com/en-us/102149#:~:text=System%20Inte....
TLDR: it restricts even the root user from modifying system files. Like the ones that would otherwise be the target of malware.
TLDR: it restricts even the root user from modifying system files. Like the ones that would otherwise be the target of malware.
Wouldn't it be far easier to enumerate what you want an app to access?
Enumerating what I do want an app to access is handled by Gatekeeper.
...and all its children, which is effectively the entire operating system
> Enumerating what I do want an app to access is handled by Gatekeeper.
Gatekeeper is not capable of this.