5 ms·
An iOS-like approach seems natural. -download from App Store; app runs normally -function in app hits boundary - OS: "app Example has request access to <file
by theWatcher37 10y ago
An iOS-like approach seems natural.
-download from App Store; app runs normally
-function in app hits boundary
- OS: "app Example has request access to <files: all/this directory/this folder> this time/always/not now/never"
Would solve this problem pretty quick right?
I don't want handbrake to have access to my photos, I'd love Native fine-tuned permissions like this.
- gberger 10y agoThe problem is that permissions only work for the most basic things.
- function_seven 10y agoWhat complicated things would a permissions system not be able to handle?
- AtheistOfFail 10y agoBasic Internet Access. How often will you read the dialog for Chrome before you just go "Screw it, set to Always"?
- function_seven 10y agoJust once, the first time the application runs into a particular sandbox boundary. The application can decide for itself what granularity it wants to request, then I accept or decline. For example, the first time I use Chrome to visit a website, it would trigger a dialog requesting permission to “Connect to websites” (i.e. initiate outbound TCP connections toward ports 80 and 443). The first time I tried to use WebRTC, the dialog would appear for that.
- geofft 10y agoHere's an analogy: HTTPS Everywhere wants to, quote, "Read and change all your data on the websites you visit." I mean, yes, that's what it's doing. But a permission system that allowed it to say "Rewrite URL references for a, img, style, video, etc. tags, modifying the protocol, except where you also need to modify other things like s|^http://(\w{2})\.wikipedia\.org/wiki|https://secure.wikimedia.org/wikipedia/$1/wiki/|" http://(\w{2})\.wikipedia\.org/wiki|https://secure.wikimedia... would essentially be presenting me with the source code for HTTPS Everywhere to approve. And I certainly don't want it prompting on each website, which would be the natural way to implement a permission dialog system. Remember in the late '90s when web browsers would ask you for every cookie, or prompt you when going from HTTP to HTTPS? Meanwhile, if a remote-code-execution bug is ever found in HTTPS Everywhere, it will have access to literally everything I do on the web. So it's not clear the permission system is really helping anything.
- function_seven 10y agoI don’t think the prompt should continually appear. It would just appear the first time an app needs to do something that’s currently out-of-bounds for its sandbox. You then accept it or decline it. Much how the iOS system works.
- geofft 10y agoBut what is "something"? Is saying "yes, you can modify google.com" permission to modify news.ycombinator.com too? If so, then you're giving every extension permission to mess with every website, which defeats the point of a permission scheme. If no, HTTPS Everywhere is prompting on each new website, which is unbearable.
- function_seven 10y agoIt doesn’t defeat it. I expect a browser extension—whose job it is to rewrite URLs—to be able to rewrite URLs. But I don’t expect HTTPS Everywhere to want access to my camera, or to my filesystem, or to the microphone. So I allow the first one, and get very worried if I’m ever even asked about any of the others. Another browser extension might want to automatically save images I come across to a directory. That one would prompt for access to my Documents folder. It wouldn’t request URL rewrite privileges, or camera, etc. EDIT: So to answer your question, what is “something”? In this case, that would be: “HTTPS Everywhere wants to be able to edit the web addresses you visit”. Or something like that.
- cortesoft 10y agoSomething like "Read and change all your data on the websites you visit." It can't just be the web addresses you visit, since it needs to change embedded tags inside the page to request https urls.
- loop22 10y agoThis would be great! Little Snitch, but for file access.
- xrisk 10y agoThis sounds like a great thing to implement in a desktop OS, if you could do it in a sensible manner with sane defaults. Unfortunately, with the state of the macOS dev team at Apple (merged into iOS?) chances for a feature like this are kinda slim.
- ams6110 10y agoHaven't we learned that users will click "yes" on any dialogs that get in the way of what they want to do? If you put an exit door on a sandbox and give the user the key, it isn't a sandbox anymore.
- baddox 10y agoHave we learned that? I don't have any data, but my impression is that granular permission dialogs in iOS (and Android) are considered good things, at least in the tech community.
- geofft 10y agoiOS's permission dialogs are great, but they're not very granular; it's just stuff like "Foo wants to use your camera", "Foo wants access to your calendar", etc. It doesn't ask you about individual files, and the questions are very clear. But this sort of thing is universally considered a bad idea: https://i.imgur.com/H0uVqFe.jpg https://i.imgur.com/H0uVqFe.jpg
- gurkendoktor 10y agoThe image you've linked to doesn't really imply that iOS' dialogs are a bad idea because, as you said, Apple's dialogs ask very clear questions. They don't intimidate the user with tech voodoo. http://nshipster.s3.amazonaws.com/core-location-always-authorization.png http://nshipster.s3.amazonaws.com/core-location-always-autho... Anecdotally, my tech-adverse friends choose Don't Allow when in doubt.
- BaronSamedi 10y agoYou don't have granular control over these permissions. You can either accept or refuse, you can't select which ones to grant or not. I think this is a terrible way to do permissions and poor security. I'd like to see true user-level granular permissions down to the level of being able to specify what hosts the app is allowed to connect with (if any).
- pfg 10y agoThis is roughly what Little Flocker[1] does on macOS. [1]: https://www.littleflocker.com/ https://www.littleflocker.com/
- kartickv 10y agoThat's too granular, as others have pointed out. It will lead to too many prompts. Access /foo? Access /bar? Access /baz? But you have the seed of a great idea, which is that the app developer should explicitly request permission, so that they can request it once in a way that covers all the folders they need, rather than one by one. Like: if requestAccess("~/Documents") == ALLOWED { // Do the work. } else { print "Sorry, the app needs access to your documents" } The key thing is that all apps start with zero permissions, and escalate their access only when needed, rather than starting with full permissions, as happens today, which is insecure.