‹ BackHN Continuity

Thread

Updates to Full Disk Access in macOS

309 points · 219 comments · notfirstpost

  1. hn-ai-podcasts · · focus · HN ↗
    Above all, we need a true privilege separation API at the application level. Why is the only way to sandbox my code editor to run it in a Linux VM on the Mac? And that’s solely to mitigate supply-chain attacks.

    The simple root/user separation has long since ceased to be secure because, on a desktop machine, all sensitive information is, by definition, accessible to the user; having root privileges ultimately offers little advantage when it comes to exfiltrating data.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.