@landonfuller @mikeash Sorry. Malware defense. Developers and tinkerers can turn it off.
-
-
- View other replies
-
- View other replies
-
-
-
-
@landonfuller task_for_pid()) restricted by Sandbox.kext MAC policy...Root can still load Kexts which can disable the corresponding hook -
@tweakbsd signed kexts only though, right? And that requires a special Apple cert. - View other replies
-
@rsesek That is not completely right. If you use Apple's kextload binary to load a kext it gets validated. But I implemented my own :-D - View other replies
-
@tweakbsd Is your kexttool code still available? SVN repo doesn't seem to be working. -
@landonfuller had a little server problem today...should all be running again, I should definitely go the github route as all do -
@tweakbsd Thanks! I actually like that you have it self-hosted, but ymmv. - View other replies
-
@landonfuller It's cause I pretty much prefer client-server model of SVN vs. distributed GIT that's why
-
-
-
@landonfuller so pretty useless this 'rootless'... - View other replies
-
@tweakbsd Sure, workarounds still exist -- for now. -
@landonfuller -> still <- that's exactly the right word...further lockdown is what Apple will do (or at least try)
-
-
-
@landonfuller It can be switched off. -
@mirekpetricek On OS X (not iOS). For now. With enough hassle that you can't depend on anyone doing it. That's not reasonable justification. - Show more
-
-
-
@landonfuller@trimosx Also, DTrace's system-wide traces become less useful as it can't see probes in restricted processes anymore. :-/ -
Tweet unavailable
-
@trimosx@landonfuller However, one of DTrace's selling points is/was that you can use it anytime on a production system (without reboot). -
@knweiss@trimosx@landonfuller I filed a bug for a rebootless way to disable SIP, for this reason. They seemed understanding, but
...
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Landon Fuller
Greg Parker
tweakbsd
Robert
Mirek Petricek
Karsten Weiss
Andre LaBranche