I think macOS 27 has already shipped a version of this. I remember seeing a prompt for Firefox requesting access to Google Chrome data (presumably to import bookmarks/history?) recently.
If that's the direction things are moving in, I welcome the change. Fine-grained folder access controls (rather than only full iOS-like sandboxing or full disk access) make me much less hesitant to try new apps or have agents access more parts of my system.
But they really need to solve the issue of low-level utilities triggering dozens of permission prompts when walking $HOME. Having to approve or decline Documents, Downloads, Google Drive etc. directory access, all separately, is extremely annoying.
How do you mean? The sandboxes of both iOS and Android have been a resounding success; bugs exist and malware is not impossible, but orders of magnitudes more complex to deploy than on traditional unsandboxed desktop OSes.
The android one isn’t all that great. iOS sandboxing, to a great extent is a 2 step system - the app store and entitlements limit the attack surface long before the sandbox gets tested. That is not necessarily a bad thing. The sandbox on iOS would be forced to be a lot more secure if people were allowed to use the whole ABI of the kernel.
lxgr · · focus · HN ↗
If that's the direction things are moving in, I welcome the change. Fine-grained folder access controls (rather than only full iOS-like sandboxing or full disk access) make me much less hesitant to try new apps or have agents access more parts of my system.
But they really need to solve the issue of low-level utilities triggering dozens of permission prompts when walking $HOME. Having to approve or decline Documents, Downloads, Google Drive etc. directory access, all separately, is extremely annoying.
eptcyka · · focus · HN ↗
lxgr · · focus · HN ↗
eptcyka · · focus · HN ↗