4 ms·
It's tempting to be this reductive but it ignores context and specifically the implications of the word "plugin." The context of downloading and executing a fu
by mapgrep 13y ago
It's tempting to be this reductive but it ignores context and specifically the implications of the word "plugin."
The context of downloading and executing a full fledged app fits with your implication that the user should know she'll be "owned" by a mistake. (Despite this, Apple offers mitigations in terms of warnings and code signing, but I take your point.)
The implication of downloading and installing something that uses what Apple itself calls a "plugin" API is different. There is an implication of sandboxing, and while you can debate the limits, most reasonable people would NOT expect an iTunes app plugin gets access to naked Apple account credentials.
It's easy to now say "you should trust no sandbox." But practically speaking most of us need to do this all the time. Do we verify all the security of all the Javascript sandboxes we run, to ensure the millionth Chrome update didn't introduce a sandbox hole? No we do not. We trust if the sandbox has a hole someone will blow the whistle. Which is happily what is happening here.
- nknighthb 13y agoThere is no implication of sandboxing. Even sandboxing browser plugins is new. You should never assume a plugin in any application is sandboxed, because that has never been true about any application at all until the past few years, and is still not true about virtually everything except browsers. Sandboxing of plugins is the exception, not the rule.