Adobe Creative Cloud Installer Deleting Hidden Files: http://mjtsai.com/blog/2016/02/12/adobe-creative-cloud-installer-deleting-hidden-files/ … #mjtsaiblog
@rosyna A bug from a legit developer is not malware or an exploit. I think you’re misunderstanding what his point was.
-
-
@rosyna Why not? Isn’t that part of why the Mac App Store requires sandboxing, as a backstop against malware? -
@mjtsai No, it's so the developers can define the resources they need up front. This prevents bugs/bad coding from accessing other resources - View other replies
-
@rosyna I don’t remember that being presented as the main motivation. I don’t think anyone’s worried about apps accidentally printing. - View other replies
-
@mjtsai That was the only motivation when sandboxing was added to OS X for system services, which was before the Mac App Store existed. - View other replies
-
@rosyna I’m not sure how the original reason the technology was developed is relevant to the policy decision about using it now. -
@mjtsai Because it's never been used to protect against malicious apps. As I said, those apps can always ask the user which files to destroy - View other replies
-
@rosyna Apple’s docs says "Enable App Sandbox to Minimize Damage from Malicious Code". https://developer.apple.com/library/mac/documentation/Miscellaneous/Reference/EntitlementKeyReference/Chapters/AboutEntitlements.html … -
@mjtsai Yes, malicious code that hijacks and exploits a security vulnerability in your app. - Show more
-
-
-
-
@jimmyjamesuk123@rosyna The point is that it’s perfectly understandable Adobe didn’t want to use the sandbox because of all its problems. - View other replies
-
- View other replies
-
@jimmyjamesuk123@rosyna In this case it didn’t offer security because it failed to convince the developer that it was worth adopting. -
-
@jimmyjamesuk123@rosyna Consider a feature that prompts for every FS access. No security in practice b/c users will turn off or not read. -
@jimmyjamesuk123@rosyna You could blame the user. But I would say it’s a poorly designed feature that failed in the real world. - View other replies
-
- Show more
-
-
@mjtsai Wil explicitly mentioned malicious apps in follow ups, which has nothing to do with sandboxing -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Michael Tsai
Rosyna Keller
James Atkinson