4 ms·
I've never tried to do this or similar in Windows (obviously easy in unix-like environments) but I'm going to bet it's far more trouble than it's worth for 99%
by finghin 5mo ago
I've never tried to do this or similar in Windows (obviously easy in unix-like environments) but I'm going to bet it's far more trouble than it's worth for 99% of users
- jon-wood 5mo agoOn macOS at least those 99% of users are probably installing from the App Store, where apps are sandboxed by default and need to explicitly ask for access to paths outside that sandbox. Even when not installed from the App Store a permission dialogue is popped if an application tries to read from sensitive paths like your photo library.
- silon42 5mo agoFor real security, operation should only be allowed after 24h of cooldown.
- SamBam 5mo agoUser should be required to explain the situation to an older and a younger family member, and get permission from both of them.
- embedding-shape 5mo agoDoes that help in this case though? I think the worry is that a rogue Obsidian plugin does bad stuff with your Obsidian vault, not just do stuff to the rest of the computer. But that vault/those notes live in the same sandbox as the (rogue) 3rd party plugin, which doesn't help with that, they really need to be isolated away from the notes themselves.
- zerkten 5mo agoAnything that reduces the blast radius helps. There should still be a focus on further hardening. Most value comes from exploits that enable pivots. Attackers will focus on other vectors that enable broader pivots because immediate high value notes only exist for a limited set of users.
- jon-wood 5mo agoIn this case, no, not really because the plugin is running within the same sandbox. I was addressing the more general point in the grandparent post.