3 ms·
Wait, that's actually never legit. If the password popup comes from the OS on behalf of the vendor, that's OK; the third-party party never has access to your pa
by KerrAvon 1y ago
Wait, that's actually never legit. If the password popup comes from the OS on behalf of the vendor, that's OK; the third-party party never has access to your password, just a time-limited auth token to allow it to do something privileged.
- mvdtnz 1y agoOk? I don't know if it's the OS on behalf of the app or not. It's a password prompt that doesn't even have an affordance for biometrics, unlike other MacOS admin prompts. It's commonplace in MacOS applications. This is an example of what I'm talking about https://www.reddit.com/r/Slack/comments/1geva4f/how_do_i_stop_this_on_end_user_accounts_admin/ https://www.reddit.com/r/Slack/comments/1geva4f/how_do_i_sto...
- afandian 1y agoThis is good for security becuase you're giving temporary access for a helper binary to do privileged stuff in a limited scope. From the UX perspective, yes, it is triggered from the app. It's been a long time since I used the Core Foundation API but you trigger a request, and then get back a token from the OS that grants you permission to do stuff. I don't know if this is current or not: https://developer.apple.com/library/archive/documentation/Security/Conceptual/authorization_concepts/03authtasks/authtasks.html#//apple_ref/doc/uid/TP30000995-CH206-TPXREF16 https://developer.apple.com/library/archive/documentation/Se...
- deleted 1y ago[deleted]