I wonder how the fix for that one will look like.
Yet another macOS privacy protections bypass
21–30 of 94 posts
Re: Yet another macOS privacy protections bypass
#22Re: Yet another macOS privacy protections bypass
#23> I chose the example of ~/Library/Safari/LocalStorage because Safari names the files in this directory according to the web sites that you visit! Also note that the output of long format ls -l contains the last modification date of the files. Thus, one possible privacy violation from this technique is to learn the user's web browsing history. Its a pretty serious issue if any random app can read your browsing histor…
If that is a serious issue, it says a lot about how goalposts have moved the last decades. We haven't been able to expect anything less than every program being able to read all your files.
Re: Yet another macOS privacy protections bypass
#24> I chose the example of ~/Library/Safari/LocalStorage because Safari names the files in this directory according to the web sites that you visit! Also note that the output of long format ls -l contains the last modification date of the files. Thus, one possible privacy violation from this technique is to learn the user's web browsing history. Its a pretty serious issue if any random app can read your browsing histor…
If that is a serious issue, it says a lot about how goalposts have moved the last decades. We haven't been able to expect anything less than every program being able to read all your files.
Ransomware (enabled by bitcoin payments to anonymous recipients) really changed the game on desktop in the last few years. Apple stepped up, but there's crickets on the matter in Windows- and Linux-land, aside from the people who have been containerizing their desktop apps[1].
[1]: https://github.com/jessfraz/dockerfiles/blob/master/chrome/s...
Re: Yet another macOS privacy protections bypass
#25What can I, as a reader, do? Is there someone to forward this to? Is there a person in Apple to email? Or are we hoping for a tweet storm to stir the water?
Re: Yet another macOS privacy protections bypass
#26Okay, this is a serious issue and I want this to be taken seriously by Apple. What can I, as a reader, do? Is there someone to forward this to? Is there a person in Apple to email? Or are we hoping for a tweet storm to stir the water?
Re: Yet another macOS privacy protections bypass
#27Earlier quoted context omitted.
At least in this case, the lack of reaction from Apple shows that his accusations are not baseless. Don't blame it on the messenger.
These security features are only nominally about protecting the user. Apple implements them to protect their services and platforms from competition and sells them via the privacy argument. Does it happen to improve the security situation? Yes, for many people it does. Is it worth the cost? That's debatable, especially because of Apple's apparent apathy (and occasional hostility) towards the community.
Stallman[1] and others[2] have talked about just this issue for over a decade now.
Re: Yet another macOS privacy protections bypass
#28Okay, this is a serious issue and I want this to be taken seriously by Apple. What can I, as a reader, do? Is there someone to forward this to? Is there a person in Apple to email? Or are we hoping for a tweet storm to stir the water?
Re: Yet another macOS privacy protections bypass
#29Earlier quoted context omitted.
It's not flippant, read through the author's history: https://lapcatsoftware.com/articles/index.html This is a serious stance of his, with a lot of serious data and arguments to back it up, from a serious engineer who has written an impressive list of Mac software both for Apple and for Apple's customers.
You did use the word serious enough to make it compelling. But the author’s biography doesn’t mean that his comment wasn’t flippant. He’s proved that an well-behaved, codesigned app can list file metadata about files in restricted directories. He hasn’t proven the sandbox compromised. You claim he has so much serious evidence, link us there. Don’t just string adjectives together. I have great respect for Jeff, but he…
Re: Yet another macOS privacy protections bypass
#30Okay, this is a serious issue and I want this to be taken seriously by Apple. What can I, as a reader, do? Is there someone to forward this to? Is there a person in Apple to email? Or are we hoping for a tweet storm to stir the water?