Hacker News new | past | comments | ask | show | jobs | submit login

> Once you need to be in the apple developer program to build and run from source or something, that’ll be a legitimate nightmare. But we’re nowhere near that yet.

This is the case for building and running things with restricted entitlements and system extensions.

Unless you disable system integrity protection entirely, which locks you out of your purchased App Store software, DRM content, etc.






>which locks you out of your purchased App Store software, DRM content

Also false. But Apple's glad you believe in that.


It does lock you out of iOS apps, Apple Pay, and 4K streaming of DRM content [1]. But that's not so bad I suppose.

[1] https://github.com/cormiertyshawn895/RecordingIndicatorUtili...


I was mistaken; I was conflating Permissive Security with SIP. Permissive Security does have those limitations.

You can no longer disable system integrity protection.


Source?

The release notes for Sequoia.

Nope. Not the enterprise release notes or the security content notes either.

What I'm referencing is that they removed `spctl --master-disable`. This was referenced in release notes that I read upon upgrading, and testing it on my own system confirms it is gone.

Looks like there might be a way of achieving the same thing through the GUI? https://www.reddit.com/r/MacOSBeta/comments/1e2xlcg/disablin...


That's Gatekeeper, not System Integrity Protection. You can disable SIP with `csrutil` by rebooting into the macOS recovery environment.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: