This carried and I can still do that. But not on System apps. So now any system app is twice without ability to easily 'diet' it:
file /System/Applications/TextEdit.app/Contents/MacOS/TextEdit /System/Applications/TextEdit.app/Contents/MacOS/TextEdit: Mach-O universal binary with 2 architectures: [x86_64:Mach-O 64-bit executable x86_64] [arm64e:Mach-O 64-bit executable arm64e] /System/Applications/TextEdit.app/Contents/MacOS/TextEdit (for architecture x86_64): Mach-O 64-bit executable x86_64 /System/Applications/TextEdit.app/Contents/MacOS/TextEdit (for architecture arm64e): Mach-O 64-bit executable arm64e
It won't be marketing wonder when new macOS dropping Intel will be it's 25% smaller (I guess they'll take the extra size for on-device models are other feature you won't be able to remove :) )
Right off the bat, XProtect, MRT, Gatekeeper, amfid, system updates, telemetry, MDM...
----
semi-unrelated tip - on ios, most telemetry options can be disabled under
Settings -> privacy & security -> Analytics & Improvements
However, there is a whole separate telemetry setting:
Settings -> search -> help apple improve search
note that this doesn't show up if you search for it in settings. (try searching for "help apple" or "improve")
and of course the whole "learn from this app" and other siri settings that are all individual settings.
Nobody knows how to do anything because nobody lets them.
But your average 20 year old who only knows an iPhone would be out of his/her depth quickly.
Computers are no longer made for me.
This is really irritating, both that:
- I can't "accept the risk" and force disk encryption anyway. This may be technically possible if you bludgeon the OS enough, but it's definitely not something the built in CLI tooling supports.
- I can't use the old full disk encryption mode. Presumably, this code does or did still exist somewhere, but isn't supported because it's not used in any supported configuration.
So you're left with the option of having no disk encryption on your laptop, or having SIP.
EDIT: I'm thinking of SSV, not SIP per se. But when it comes to disabling the built-in launchd services like Spotlight, you have to disable SSV to do so, and that requires disabling FileVault.
But still -- you can't "unlock" the system (in this sense) without disabling SSV, which requires disabling FileVault.
(Unless I'm wrong about that too, and there is a way to disable Spotlight without disabling SSV)
I'm finally starting to de-Applify my home computing and slowly removing my and my family's dependence on the Apple ecosystem. Replacing an old Mac Mini here, replacing an old MacBook there. It's been a long time coming, but I'm out.
I'm not even mentioning Tahoe which is a disaster but doesn't bother me because I don't have a single machine that can run anything past Ventura anyway.
If the evil maid could boot macOS from an external disk, on the other hand, that would definitely be a problem. I think you need to authenticate in order to boot from an external disk for the first time (cf. [1]) but I'm not sure how this works.
[1] https://eclecticlight.co/2023/03/15/ownership-of-apple-silic...
Edit: Actually I guess an attacker trying to disable SSV themselves (via exploit of recovery mode) wouldn’t have the machine owner key needed to sign the new LocalPolicy. But could they reset it and still keep the data somehow? I don’t know.
I'm also curious about this specific case.
In general: https://www.youtube.com/watch?v=o_XaJdDqQA0
All consumer-operating systems also used to be single user with administrative access by default. Shall we return to that, too?