I think, we fundamentally lack a mechanism to enforce secure / privacy aware APIs without resorting to trusted inner-circle type of things. I am already not comfortable with Apple picking winners (such as giving Zoom special entitlement but not the VOIP apps you want to distribute by your own). Apple trusting their own apps more than other apps is another symptom of this and it is not helping their anti-trust situati…
Quicktime Player.app gets an entitlement called `com.apple.private.tcc.allow`, giving it unprompted access to the Camera, Microphone, and Screen Capture. An MDM administrator, managing a computer or device owned by an organization, cannot grant those permissions to anything without user consent. For good reason! So why the *fuck* does Apple think they're entitled to?
Now, replace ‘Apple’ with ‘malware author’. What’s the difference? Well, for one, a hacker has nothing to lose and everything to gain from snooping on your webcam. Meanwhile, if Apple mishandles this permission or used it to beam video data to HQ, there’s a high likelihood hundreds of millions of dollars of iPhone or Mac customers are lost, resulting in billions of dollars in stock value loss.