logoalt Hacker News

brigade • yesterday at 5:11 PM • 1 reply • view on HN

If you're arguing that SIP isn't a useful defense against malware, I agree there.

Sandboxing full disk reads is orthogonal to what SIP actually provides. It's entirely possible for an unsandboxed binary to slurp your private data even with SIP enabled.


Replies

lapcat • yesterday at 5:26 PM

> If you're arguing that SIP isn't a useful defense against malware

No? I'm not.

SIP is of course not a universal defense against every possible kind of attack, but did anyone ever expect it to be?

> Sandboxing full disk reads is orthogonal to what SIP actually provides.

No, because again, as I already said, disabling SIP also disables some TCC privacy protections.

> It's entirely possible for an unsandboxed binary to slurp your private data even with SIP enabled.

Not the data protected by TCC.

➕ show 1 reply