--- type: constraint title: This is friction, not a security boundary tags: [threat-model] --- The user is in `wheel` and can run `sudo systemctl stop`, `sudo nft flush ruleset`, or boot a live USB. No arrangement of systemd and nftables changes that while the user holds root. SelfControl on macOS is the same: an admin can `sudo pfctl -d`. Its own FAQ concedes that VPNs defeat it entirely ("not technically feasible" to fix) and that Firefox DoH made blocks "unreliable or fail entirely". It sells the promise anyway, and it works, because the product is cost rather than enforcement. So the design target is measured in seconds of deliberate sabotage, not in whether a bypass exists. Concretely: - No stop path anywhere in the UI or the CLI's happy path. - `RefuseManualStop=yes`, so the reflexive `systemctl stop` bounces. - A polkit action for `arm` (`allow_active yes`, no prompt) and one for `list-set` (`auth_admin_keep`, a password). None for `disarm`, so the UI has nothing to call. Starting is free; widening the hole costs a password. The one variant that is a real boundary needs a second admin account and the user's own removal from `wheel` for the duration. That is worth offering as an opt-in mode and is not the default, because it can lock a person out of their own machine.