Some — but not all — Touch Bar models of the new MacBook Pro are shipping with System Integrity Protection disabled, potentially exposing them to malware threats, according to discussions on Twitter.
The issue was called out by developers Jonathan Wight and Steve Troughton-Smith. The latter suggested that there seems to be no obvious trend, other than Pros with a function key row having SIP on as usual.
While Macs do have other safeguards, SIP has been on by default since OS X El Capitan, and limits root permissions — mitigating the amount of damage malware can do if it does infect a system.
Apple is allegedly aware of the problem, and likely working on a software update. Technically confident Mac owners can turn SIP back on themselves holding down Command-R when booting, releasing when a progress bar appears, then selecting Terminal from the Utilities menu in recovery mode. Entering "csrutil enable" and restarting should complete the process.
11 Comments
to check:
csrutil status
Just got my new 15" MBP today and checked it. It is disabled, but on my other two Retina MBPs (work and personal that I'm replacing with the new one), they both had it enabled.
This article is lacking in details:
Where's the reports of it being enabled on some of the shipping "models"? They only talk about one or two instances of it being disabled. Could it be disabled due to the functionality of the Touch Bar, and they are still working to resolve some compatibility issues? Or is it merely an oversight on the configuration of "some" models?
Was disabled on mine that just arrived today.
on my Mac Mini, it is disabled ..but that is because I have it set to Download Apps from Anywhere, under Mac OS Sierra. I am the gatekeeper. :)