you are viewing a single comment's thread
view the rest of the comments
[–] 1 point 2 years ago (1 child)

I see. How effective is a security tool that can't stop malicious software that makes itself in ring 0?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 years ago (1 child)

    You don’t have to run in Ring 0 to detect events occurring in Ring 0.

    Besides which, as kexts are being obsoleted by Apple getting code to run inside Ring 0 in macOS that isn’t from Apple itself is going to be extremely difficult.

  • source
  • parent
  • hideshow 2 child comments