-download from App Store; app runs normally
-function in app hits boundary
- OS: "app Example has request access to <files: all/this directory/this folder> this time/always/not now/never"
Would solve this problem pretty quick right?
I don't want handbrake to have access to my photos, I'd love Native fine-tuned permissions like this.
For example, the first time I use Chrome to visit a website, it would trigger a dialog requesting permission to “Connect to websites” (i.e. initiate outbound TCP connections toward ports 80 and 443).
The first time I tried to use WebRTC, the dialog would appear for that.
I mean, yes, that's what it's doing. But a permission system that allowed it to say "Rewrite URL references for a, img, style, video, etc. tags, modifying the protocol, except where you also need to modify other things like s|^http://(\w{2})\.wikipedia\.org/wiki|https://secure.wikimedia... would essentially be presenting me with the source code for HTTPS Everywhere to approve.
And I certainly don't want it prompting on each website, which would be the natural way to implement a permission dialog system. Remember in the late '90s when web browsers would ask you for every cookie, or prompt you when going from HTTP to HTTPS?
Meanwhile, if a remote-code-execution bug is ever found in HTTPS Everywhere, it will have access to literally everything I do on the web. So it's not clear the permission system is really helping anything.
Another browser extension might want to automatically save images I come across to a directory. That one would prompt for access to my Documents folder. It wouldn’t request URL rewrite privileges, or camera, etc.
EDIT: So to answer your question, what is “something”? In this case, that would be: “HTTPS Everywhere wants to be able to edit the web addresses you visit”. Or something like that.
It can't just be the web addresses you visit, since it needs to change embedded tags inside the page to request https urls.
Unfortunately, with the state of the macOS dev team at Apple (merged into iOS?) chances for a feature like this are kinda slim.
If you put an exit door on a sandbox and give the user the key, it isn't a sandbox anymore.
But this sort of thing is universally considered a bad idea: https://i.imgur.com/H0uVqFe.jpg
http://nshipster.s3.amazonaws.com/core-location-always-autho...
Anecdotally, my tech-adverse friends choose Don't Allow when in doubt.
Access /foo?
Access /bar?
Access /baz?
But you have the seed of a great idea, which is that the app developer should explicitly request permission, so that they can request it once in a way that covers all the folders they need, rather than one by one. Like:
if requestAccess("~/Documents") == ALLOWED {
// Do the work.
} else {
print "Sorry, the app needs access to your documents"
}
The key thing is that all apps start with zero permissions, and escalate their access only when needed, rather than starting with full permissions, as happens today, which is insecure.
It is ridiculous we are having this conversation about strictness of a sandbox requirements in the App Store and in another thread people bitch about Dropbox acting like an out of control virus.
As a user: I want it all sandboxed.
That doesn't work for all of your use cases, but it solves some of them (the backup app and file compressor, if you're only backing up your own stuff and not the whole laptop).
I think there are two forces at work here. One is the increasing lack of trust in any piece of software downloaded on phones and computers. This because advertising, spyware, spies, etc. The other one is the habit of renting vs owning. People is used not to really own music, books, apps, etc and even files to some extent. They are in the cloud and we can lose access to them if the owner of the cloud terminates our account. So we're growing accustomed with the idea that less and less of what we use and produce is really ours. Pieces of the hw, sw and data we paid for are somebody's else property. That's bad IMHO.
I'm not on a Mac and I'm backing up all my laptop, included configuration files owned by root and other system users. I understand that non technical users are fine with appliance like laptops that can be returned to the manufacturer and replaced with a new one as I do with a refrigerator. As a developer I prefer to keep control over my stuff. If I were in the refrigerator industry I would probably like to service my fridge myself.
In general though, the idea is not to grant extra permissions to one process but to run other programs that DO have the required permission. This can all "appear" to be happening in one application on macOS even though multiple subprocesses are involved.