back
1 comments
Keeping you secure requires keeping the computer secure from attackers. You can't be distinguished from an attacker, from the computer's perspective. Having the computer be able to attest that it's unmodified means that it doesn't have to mistrust you so aggressively, relative to today.

Requiring a reboot to rescue mode to disable SIP is sufficient to block most social engineering attacks that would otherwise have you click through dialogs to bypass it. A dedicated attacker can still overcome this, and once they do, they can impersonate you readily.

If the computer can attest that it's unmodified, then it's possible to throw up alarms for non-expert users when their computer is in that state. I don't think most websites will bother, but those that care sure would love to be able to do so. None of this is specifically for the benefit of users who want to hack the software internals of their computers, though — but those are not the target market for security practices today in any case, since they can overcome literally any barrier prior to this that says "please secure your device before entering".

Still, from an IT standpoint, it sure would be nice to find out how many expert technical users are lying about keeping their system in secure mode when they have privileged access, because they don't think it's necessary and they don't see any harm in lying about it. I'm guessing it's something like 10-20% of all IT admins using unmanaged devices. We'll find out soon enough!

> You can't be distinguished from an attacker, from the computer's perspective.

Then what's the point of things like passwords and fingerprint scanners?

> Having the computer be able to attest that it's unmodified means that it doesn't have to mistrust you so aggressively, relative to today.

How so?

> Requiring a reboot to rescue mode to disable SIP is sufficient to block most social engineering attacks that would otherwise have you click through dialogs to bypass it. A dedicated attacker can still overcome this, and once they do, they can impersonate you readily.

We need to lock people out of their own computers to protect them from social engineering?

> I don't think most websites will bother, but those that care sure would love to be able to do so.

In practice, this will end up just like the abomination that is SafetyNet on Android, where if you take control of your own device, you can't use Netflix, Snapchat, Pokemon Go, Super Mario Run, Android Pay, etc.

> keeping their system in secure mode

Really? "secure mode"? What kind of attacks specifically would this prevent that an IT department would care about, as opposed to Hollywood/RIAA/etc. caring about?

You’re already familiar with the difference between passwords and secure computing platforms, as evidenced by the citation of SafetyNet and Pokémon Go, and your use of the phrase “abomination” leaves no opportunity for further discussion, so I will stop now to avoid wasting any more of your time. Apologies and be well.