Adobe Creative Cloud Installer Deleting Hidden Files: http://mjtsai.com/blog/2016/02/12/adobe-creative-cloud-installer-deleting-hidden-files/ … #mjtsaiblog
-
-
@rosyna Apple’s docs says "Enable App Sandbox to Minimize Damage from Malicious Code". https://developer.apple.com/library/mac/documentation/Miscellaneous/Reference/EntitlementKeyReference/Chapters/AboutEntitlements.html … -
@mjtsai Yes, malicious code that hijacks and exploits a security vulnerability in your app. -
@rosyna Where is that code running? And why wouldn’t it also be able to make the app ask the user which files to destroy, as you say? -
@mjtsai the malicious code runs inside the legitimate app. That's how all flash exploits work. A user would notice an unusual dialog. - View other replies
-
@rosyna So you’re saying that the reason the Mac App Store requires sandboxing is to protect against Flash, which most apps don’t use? -
@mjtsai No, it's to prevent bugs in the apps from being exploited and doing harm to other parts of the system. - View other replies
-
@rosyna But, aside from your example of Flash, where is the code that’s exploiting these bugs? -
@mjtsai The bugs are in the apps. The malicious code is delivered multiple ways. Wikipedia has an article on RCE. https://en.wikipedia.org/wiki/Arbitrary_code_execution … - View other replies
- Show more
-
-
-
@rosyna Macworld and others have reported it’s to protect against malicious apps that made it through App Review:http://www.macworld.com/article/2937239/zero-day-exploit-lets-app-store-malware-steal-os-x-and-ios-passwords.html … -
@mjtsai Then they are also incorrect as the sandbox is not capable of doing that.
-
-
@mjtsai Also, none of Apple's documentation claims it can protect against malicious apps. https://developer.apple.com/videos/play/wwdc2012-700/ …
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Michael Tsai
Rosyna Keller