Hacker News new | ask | show | jobs
by Muromec 442 days ago
How do you know they didnt install a rootkit?
2 comments

Persistence in modern macOS is only really possible in userspace, as the OS partition is immutable. There are only a handful of places this is possible, which are fairly easy to detect.

Unless border agents are burning 0-days on random passersby, it’s fairly unlikely they installed anything persistent that can’t be removed.

He looked through my files in front of me.
I’ve always been mildly curious about this. When you say “looked through my files” what exactly do you mean? They opened finder and scrolled through the standard folders like downloads, documents, pictures, etc?
My laptop boots to a text-mode getty prompt, I wonder what would happen...