3 ms·
I don't think that's necessarily true. All you need is default-on sandboxing that is "painfully obviously wrong" for the system owner to bypass. As a case in po
by roblabla 4y ago
I don't think that's necessarily true. All you need is default-on sandboxing that is "painfully obviously wrong" for the system owner to bypass. As a case in point, look at macOS. You can bypass almost every security feature in macOS by rebooting to recovery and disabling CSR, AMFI and whatnot. And even after disabling all this, touchID will still work, and I believe it will still be accepted as a platform authenticator.
I think something similar could be compatible with free software ethos.
- notpushkin 4y agoThis exactly. Bypassing sandbox should be like installing software from tarball as opposed to package managers: possible but pretty much discouraged, an “escape hatch” of sorts.