logoalt Hacker News

0c3ca83 • yesterday at 2:25 AM • 4 replies • view on HN

It really isn't; the program just needs to be able to declare what it expects it should be able to do, and what it expects its children should be able to do. The latter doesn't need to be a subset of the former.


Replies

comex • yesterday at 5:37 AM

The latter does need to be a subset of the former, or else an attacker can trivially work around limitations on "what it should be able to do" by spawning a child instead of doing the thing directly.

But yes, it's unfortunate that macOS sandboxes cannot be nested.

➕ show 1 reply
dcrazy • yesterday at 2:54 AM

That “just” is doing a LOT of work.

➕ show 1 reply
mindwok • yesterday at 7:13 AM

If the child could do different things to the parent malicious processes would spawn child processes to do stuff they shouldn’t be able to do, though

saagarjha • yesterday at 2:35 AM

This is really hard to do in general

➕ show 2 replies