logoalt Hacker News

arijuntoday at 12:35 AM1 replyview on HN

It seems like running with sandbox-exec should remove pretty much all the potential for an app to cause harm… is there a reason why it’s not the default, especially for these certificate-less apps?


Replies

1e1atoday at 7:09 AM

I believe that at least app-store apps are already ran in some sort of sandbox.