3 ms·
> If the ecosystem relies on app inspections that much it simply needs to be secured better. How do you secure something without inspection? We have health cod
by sixstringtheory 3y ago
> If the ecosystem relies on app inspections that much it simply needs to be secured better.
How do you secure something without inspection? We have health code inspections for restaurants, car safety and emissions inspections, IAEA inspectors visiting nuclear facilities… Should we throw all those out too? What replaces them, the goodwill and word of people?
- unethical_ban 3y agoThe ostrich is saying that the technical sandbox controls of the is will still be present.
- sixstringtheory 3y agoThose will never be good enough to overcome social engineering.
- unethical_ban 3y agoThe OP... The technical controls of the OS... Autocorrect and a lack of editing are a bad combo.
- thfuran 3y agoIn this analogy, getting to design the system on which the apps run is something like being able to alter the local laws of physics so that car exhaust simply can't contain pollution.
- wkat4242 3y agoWhat I mean is, the OS should not allow apps to do these things. Rather than inspecting the code and strictly banning any dynamic code (one of the reasons emulators are not allowed), the apps should just not be allowed to do things like call hidden APIs at OS level.
- danielheath 3y agoThey don’t read the code afaik; they prevent memory page being marked both write and execute (with an exception for javascriptcore specifically). W^X pages are one of the most widespread sources of RCE bugs, and banning them by default is a good idea.