|
|
|
|
|
by kafrofrite
992 days ago
|
|
> I don't think OS becomes any less vulnerable than usual Linux/Windows installation. is not a good enough argument. For the story, SIP is Apple's "rootless". Effectively the OS runs with less privileges than root. Disabling SIP significantly increases the attack surface. That being said, I'm grateful that someone decided to do something more native for containers in macOS. |
|