@rosyna But, aside from your example of Flash, where is the code that’s exploiting these bugs?
-
-
@mjtsai The bugs are in the apps. The malicious code is delivered multiple ways. Wikipedia has an article on RCE. https://en.wikipedia.org/wiki/Arbitrary_code_execution …0 replies 0 retweets 1 like -
@drewthaler@mjtsai That actually happened to Twitter for Mac OS X a few years ago due to an image parsing bug.0 replies 0 retweets 1 like -
@rosyna@drewthaler Even for things that would never be approved in the Mac App Store, so that every Developer ID app can be sandboxed.0 replies 0 retweets 0 likes -
@mjtsai@rosyna@drewthaler If such entitlements existed, a lot of Developer ID apps would be on the store.0 replies 0 retweets 0 likes -
@ameaijou@rosyna@drewthaler No, I mean the entitlements should go beyond what Apple would accept in the store.0 replies 0 retweets 0 likes -
@mjtsai@ameaijou@drewthaler There are entitlements non-MAS apps can use that MAS apps can't.0 replies 0 retweets 0 likes -
@rosyna@ameaijou@drewthaler Yes, I’m saying there should be more. I don’t want to run into a road block *after* adopting sandboxing.0 replies 0 retweets 0 likes -
@mjtsai@ameaijou@drewthaler But which ones are missing that you'd run into?0 replies 0 retweets 0 likes
@rosyna @ameaijou @drewthaler First issue is what’s not possible, even with non-MAS entitlements, at least in a documented/supported way.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Michael Tsai
Rosyna Keller
Drew Thaler
Gwynne Raskind