I think, we fundamentally lack a mechanism to enforce secure / privacy aware APIs without resorting to trusted inner-circle type of things. I am already not comfortable with Apple picking winners (such as giving Zoom special entitlement but not the VOIP apps you want to distribute by your own). Apple trusting their own apps more than other apps is another symptom of this and it is not helping their anti-trust situati…
Quicktime Player.app gets an entitlement called `com.apple.private.tcc.allow`, giving it unprompted access to the Camera, Microphone, and Screen Capture. An MDM administrator, managing a computer or device owned by an organization, cannot grant those permissions to anything without user consent. For good reason! So why the *fuck* does Apple think they're entitled to?
Because they manufactured the device, and you bought it?
And honestly, I support them. Because starting QuickTime is a user action, and it only records when I want it to. QuickTime is an app I trust.
I don't trust an organization admin not to record me without my consent. As we've heard the horror stories of schools spying on students with school laptops while they're in their own homes, their own bedrooms.
I trust Apple a whole lot more than I trust an org admin.