6 ms·
Many of the arguments provided by the article are straw men and ignore a provision that Apple offers (and encourages the use of!) – custom sandbox entitlements.
by ryannielsen 14y ago
Many of the arguments provided by the article are straw men and ignore a provision that Apple offers (and encourages the use of!) – custom sandbox entitlements. Apple has repeatedly stated that custom entitlements can and will be granted for apps that need access not granted by existing sandbox entitlements. Certainly not all exception requests will be granted, but for some of the ones he listed – Growl, file read access for Omnifocus – those are perfectly legitimate exception requests.
Apple is working hard to provide a secure and still fully functional system. Some things will break, undoubtedly. Some apps will be abandoned, either because of legitimate technical limitations Apple refuses to address, or because of political stances taken by the apps' developer. Things aren't perfect right now, and Apple still needs to continue refining and enhancing the OS X sandbox.
Is it as clear-cut as Rentzsch makes it out to be, though? Absolutely not. In fact, I think he takes a very biased stance in this article. For the vast majority of users, sandboxing is an enormous step forward for the safety and security of their data and system. For that reason alone, I encourage everyone to purchase apps via the App Store. It's a safe and trusted distribution vector that is now helping improve OS X's platform security. That's an enormous benefit to almost all consumers.
(And I say all of this as a developer who's having to wrangle with the sandbox right now.)
- irons 14y agoI'd agree with you that sandbox entitlements offer a path to the future, if their proper name wasn't "Temporary Exception Entitlements": https://developer.apple.com/library/ios/#documentation/Miscellaneous/Reference/EntitlementKeyReference/AppSandboxTemporaryExceptionEntitlements/AppSandboxTemporaryExceptionEntitlements.html https://developer.apple.com/library/ios/#documentation/Misce... Assuming that they'll be available indefinitely strikes me as a willful mistake.
- talentdeficit 14y agoThey are temporary because they are granted for situations where Apple has not yet implemented an API or formalized an entitlement. Apple bends over backwards to be developer friendly, they are not going to pull the rug out just for the hell of it.
- duaneb 14y ago> Apple bends over backwards to be developer friendly, You clearly haven't heard about this new 'iOS'...
- ryannielsen 14y agoThe new 'iOS' which is still surprisingly developer friendly, despite the attitude it receives on forums such as HN. iOS, for all of it's failings and deficiencies, still offers one of the finest – if not the finest – development and distribution platforms in the world. Yes, it's not open. Yes, it's restrictive. Yes, it's censored. But, perhaps, those qualities are some qualities that make it the most successful software sales vector we've ever seen. I agree it's not perfect. But to say it's not developer friendly is quite disingenuous. The iOS development toolchain is actually quite powerful and flexible (though still faulty), the distribution mechanism is broad and simple (though restrictive and censoring), and I can't think of a single other platform, including the web, that has been as developer friendly. At least for developers who wish to make an income. (Something about which I admit, without any bit of judgement, some developers aren't concerned.)
- WayneDB 14y agoOh yes, I get all warm and fuzzy every time I think of how friendly Apple is to developers... ummm, are you crazy? How friendly is a company that uses secret APIs to compete with you? How friendly is a company that rips off your software and then kicks you out of their app store? Gimme a break...
- duaneb 14y agoI'm sorry, but making people pay $100 to develop on systems they own is not developer-friendly. I would much rather they had NO apis and we were allowed to access the hardware we bought.
- ken 14y agoI'm not convinced the Mac sandbox adds much security at all yet, for one big reason: do you know what entitlements a sandboxed app has? There is a command-line tool to list an app's entitlements, but it's not at all easy to use, or even find. I haven't found a way to determine the entitlements of an App Store app without installing it (and hence, paying for it, if it's not free). I expect that basically no users will ever look at this. It's a bit like the device in Dr. Strangelove: the whole point is that you're supposed to tell people! In a perfect world, Apple wouldn't approve an app for the App Store which did something nasty (like upload the user's address book to a spammer), but it's impossible for them to catch everything even if they never made a mistake. Besides, every entitlement has legitimate uses. Security is helped by transparency. It would be great if users could see what sandboxed apps are allowed to do. They can't, and at worst this makes users feel safer without actually being safer.