But that’s still after the fact and after the damage has been done. I’m not aware of any time that Apple has a removed an app from devices instead of removing it from the App Store v
Well, since the discussion was about iPhones that both have a tighter security model and where every app has to go through the App Store, I fail to see the relevance.
The difference is that on the iPhone, when they see a class of bad actors or a real threat model that they didn’t see before, they can tighten the sandbox much easier than they can on the Mac. The zoom fiasco could be prevented on Mac entirely just by clicking on an option that restricts apps from running in the background.
I’m not saying that the tool shouldn’t exist. I’m saying that the tool isn’t enough. I If Russia found the same hypothetical security hole and released the app to the store and Apple found out that a non privileged app could track your location without you giving it permission, it should fix the hole.
Comments
But that’s still after the fact and after the damage has been done. I’m not aware of any time that Apple has a removed an app from devices instead of removing it from the App Store v
https://www.theverge.com/2019/7/10/20689644/apple-zoom-web-s...
https://www.theverge.com/2019/7/16/20696529/apple-mac-silent...
Well, since the discussion was about iPhones that both have a tighter security model and where every app has to go through the App Store, I fail to see the relevance.
That’s a distinction without a difference.
The iPhone has the same mechanism.
The references demonstrate that they would use it if they needed to.
The difference is that on the iPhone, when they see a class of bad actors or a real threat model that they didn’t see before, they can tighten the sandbox much easier than they can on the Mac. The zoom fiasco could be prevented on Mac entirely just by clicking on an option that restricts apps from running in the background.
So what? - nobody has yet created an unassailable sandbox, and so these tools are needed.
Saying ‘it’s Apple’s responsibility to make the sandbox secure, is magical thinking’, which is why they need these tools.
As to the Zoom fiasco - who should have clicked on that option?
I’m not saying that the tool shouldn’t exist. I’m saying that the tool isn’t enough. I If Russia found the same hypothetical security hole and released the app to the store and Apple found out that a non privileged app could track your location without you giving it permission, it should fix the hole.
Of course it should. So what? We know that won’t make it unassailable, so they still need the other tools.