@mjtsai the malicious code runs inside the legitimate app. That's how all flash exploits work. A user would notice an unusual dialog.
@ameaijou @mjtsai @drewthaler Also, non-MAS Apps can declare sandbox exceptions for AppleEvents and Mach messaging, the two major issues.
-
-
@rosyna@ameaijou@drewthaler But only specific targets/ports that are known at compile time, right? -
@mjtsai@ameaijou@drewthaler No, they can be blanket exceptions. - View other replies
-
@rosyna@mjtsai@ameaijou@drewthaler huh what, rosnya? Apple event targets are only blessed by bundle id known at build time. - View other replies
-
@Schwieb For MAS apps, yes. There's a non-MAS exception -
@rosyna where? -
@Schwieb Granted, they may not be suitable if you have an app that allows things inside (like macros/VBA) to extend functionality. -
@rosyna I’ve read that page many times. I don’t see entitlements that are disallowed in MAS. Anything can be approved with justification. - Show more
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Rosyna Keller
Michael Tsai
Drew Thaler
Gwynne Raskind
Erik Schwiebert