Live data from Hacker News

Mac App Store apps must implement sandboxing as of March 2012

developer.apple.com

51–60 of 71 posts

Re: Mac App Store apps must implement sandboxing as of March 2012

#51
Will this have any effect in practice or will it just be the same as the different trust levels in .NET? The functionality for sandboxing is built in it's just that nobody uses it or knows how to test or enforce it. (with the exception of sysadmins).

In any case i welcome all sandboxing, this is even something i would consider switching from windows because of, given that it actually works out good. Let's take an example from yesterday, i want a simple pdf-merge program. As it is now i have to spend 20 minutes researching a program on forums and other sites before i even install it to see if it's safe and everything. Compared to just installing and see if the result works. This is also why web apps are so popular, you can try hundreds of them with 0 risk for your other data.

Re: Mac App Store apps must implement sandboxing as of March 2012

#52
If this means that I can be reasonably certain an application that I purchase from the App Store will be prevented from screwing up parts of my system without my permission - then, as a user, I'm all for it. One day, in the future, apps will run in a chrooted/isolated virtual environment, with some actual guarantees that they are _incapable_ of touching anything but their sandbox, regardless of developer intent. Until that day though, this seems like a reasonable evolution to that world.

Perhaps it speaks to my paranoia - but I've always been unnerved by the concept that an application can basically do anything to the OS that I can from from finder/shell. I have to believe that this sandboxing will reduce the potential for malware doing damage to the OS.

The question I have is - will I be able to give applications like "Backblaze" the ability to read (but not write) from my entire set of user folders? If so, then that's the best possible case. Puts the power to control damage that an application can do in my hands.

Re: Mac App Store apps must implement sandboxing as of March 2012

#53
post #43

Earlier quoted context omitted.

Seems so: "In Mac OS X v10.7 and later, placing your application in an app sandbox is a great way to minimize the potential damage caused by successful exploits" http://developer.apple.com/library/mac/#documentation/Genera...

Putting my applications in a sandbox doesn't really prevent my application from doing exploits because my applications are not malware to begin with. Well behaved applications that are not malware are already not malware. The real issue is what about malware, will this stop them. Well, obviously malware authors are not going to put their applications in a sandbox. They will continue releasing them as before. And so,…

Putting your applications in a sandbox prevents you application from being exploited. A bug in you chat software can't be used to get access to your private files anymore. It also prevents that chat software from installing malware on you mac.

Re: Mac App Store apps must implement sandboxing as of March 2012

#54
post #39
post #18

Earlier quoted context omitted.

I draw the line here too. I accept the control tradeoff on iOS because I view them as appliances, not computers, and there are upsides to the curated experience. But if I can't fully control my primary computing device, I'm out. (I'd be okay with the machine shipping in "grandma mode", so long as there's an official way to disable it completely.)

Huh? They're just talking about selling things in the Appstore. They're not stopping people who don't distribute this way.

For now. We're talking about a hypothetical future under 10.8+. I don't expect it to change, but neither would it surprise me much.

Re: Mac App Store apps must implement sandboxing as of March 2012

#55
The end of utility apps? What makes (used to make?) the Mac such a great platform is that apps integrate seamlessly. Making them work together in new ways that were not anticipated by the developer is incredibly powerful (Unix philosophy anyone?).

Sure, sandboxing will allow your app to talk to another app, but only if you request permission beforehand. But what if the app my app wants to intact with has not been written yet?

What about application launchers like QuickSilver, Launchbar, and all the hundreds of other utility apps?

Only allowing sandboxed apps will change the nature of apps that we will find in the app store from "utility" shifting to "just-do-one-thing".

And about the question about whether the Mac App Store will become the only way to install apps on the Mac: the question is not if, but when.

Re: Mac App Store apps must implement sandboxing as of March 2012

#56
post #10

Time to settle down, people. This is not the bad news you think it is. Please take the time to read what exactly is entailed in Sandboxing a Mac App before you presume this is a restriction on your freedom. You can start here: https://developer.apple.com/library/mac/#documentation/Secur... The vast majority of apps on the App store can be sandboxed without effecting their functionality in any way. Sandboxing on OS X…

"Sending Apple events to arbitrary apps With App Sandbox, you can receive Apple events and respond to Apple events, but you cannot send Apple events to arbitrary apps." "By using a temporary exception entitlement, you can enable the sending of Apple events to a list of specific apps that you specify..." The word at WWDC was temporary exceptions are temporary and just there to ease the transition to sandboxing. I.e. t…

[deleted]

Re: Mac App Store apps must implement sandboxing as of March 2012

#57
post #55

The end of utility apps? What makes (used to make?) the Mac such a great platform is that apps integrate seamlessly. Making them work together in new ways that were not anticipated by the developer is incredibly powerful (Unix philosophy anyone?). Sure, sandboxing will allow your app to talk to another app, but only if you request permission beforehand. But what if the app my app wants to intact with has not been wri…

This has already sort of happened. Apps are forced to have some sort of permanent presence now. In the past, you could be running many of these and still have a clean menu bar. Now, you have to have an icon for Growl, an icon for Quicksilver...

Re: Mac App Store apps must implement sandboxing as of March 2012

#58
post #10

Time to settle down, people. This is not the bad news you think it is. Please take the time to read what exactly is entailed in Sandboxing a Mac App before you presume this is a restriction on your freedom. You can start here: https://developer.apple.com/library/mac/#documentation/Secur... The vast majority of apps on the App store can be sandboxed without effecting their functionality in any way. Sandboxing on OS X…

> You can still access all your files. Your app just can't do it without asking.

Sort of. You can't access files across restarts of your app right now. So something that needs to maintain a database of files in the filesystem (say a music library) will be able to access them when the user adds the files, but then will stop working after you restart.

The only way around this is a "temporary" exception - they absolutely need a permanent solution for this situation.

Re: Mac App Store apps must implement sandboxing as of March 2012

#59
post #57
post #55

The end of utility apps? What makes (used to make?) the Mac such a great platform is that apps integrate seamlessly. Making them work together in new ways that were not anticipated by the developer is incredibly powerful (Unix philosophy anyone?). Sure, sandboxing will allow your app to talk to another app, but only if you request permission beforehand. But what if the app my app wants to intact with has not been wri…

This has already sort of happened. Apps are forced to have some sort of permanent presence now. In the past, you could be running many of these and still have a clean menu bar. Now, you have to have an icon for Growl, an icon for Quicksilver...

Sure, but that's not restricting functionality. Sandboxing on the other hand will simply mean that those apps won't get into the App Store in the first place.

Re: Mac App Store apps must implement sandboxing as of March 2012

#60
post #34
post #23

Earlier quoted context omitted.

Gain? 30% of all application sales, instead of 30% of 10%. I don't think they'll lock it down to the app store either, but there are plenty of essentially-reasonable reasons why they could/would.

If you believe that Apple is making a lot of money with their App Stores, sure. But they don’t. Even with the absolutely massive iOS App Store. The Mac App Store is tiny in comparison. It’s just not Apple’s business model.

Exactly the Mac App Store is tiny. Make it the only way to install apps and it suddenly becomes more popular.
Post reply on HN