3 ms·
> For example, I don't see side loaded NES emulators being allowed to have a JIT. Why not? If third-party browsers are allowed to have a JIT, why couldn't an e
by cglong 3y ago
> For example, I don't see side loaded NES emulators being allowed to have a JIT.
Why not? If third-party browsers are allowed to have a JIT, why couldn't an emulator?
- theluketaylor 3y agoApple has a slam dunk case to place a ton of barriers on browser vendors being allowed to JIT code due to the risk to the rest of the platform and the user's data. Little emulators for NES and Sega Genesis are not going to meet those barriers and Apple will have a pretty easy time excluding them under the security provision. Dev environments like VS Code will be more interesting. I suspect Apple will choose to build a VM layer to execute complied code inside an even deeper sandbox rather than allowing execution directly inside the iOS layer, thereby severely limiting what a binary complied on device is able to interact with. This would almost certainly be hidden behind an entitlement that Apple will be try to be allowed to gatekeep under the DMA requirement to maintain platform security.
- Rinzler89 3y agoSamsung already offers virtualizations and containerization via KNOX for you to run apps you don't fully trust safely without disk and shared memory access, on their midrange phones. Surely Apple being wealthier and selling higher priced phones, with even more powerful SoCs can definitely offer similar security functionality for non-IOS appstores. The reason they aren't is they want to push the security boogieman scaremongering to defend their monopoly.
- nox101 3y agoBy every measure (go read and told up the CVEs), Chrome has a better security track record than Safari. That means by not allowing users to use Chrome (or a Chromium variant), Apple is forcing users to use a less secure browser and a less secure JavaScript and less secure JIT.