logoalt Hacker News

jeroenhd • yesterday at 8:12 AM • 2 replies • view on HN

Having had the (dis)pleasure of working with SELinux, it's clear that there are systems out there that can work to solve these problems. On Linux the problem is in the UI/UX layer (actually configuring SELinux rather than working around it is a massive pain) but Apple/Google/MS have the money to solve that.

I don't know if Apple has something like that. Surely they must do; Windows FACLs have been available since NT was part of the name, Linux has had them since Linux 2.5, and Apple invented a whole new filesystem relatively recently. They've also compartmentalised iOS apps since they were first released.

I'd be surprised if the currently available APIs aren't usable for applying effective restrictions just yet. Rather, I think Apple's choice is part of a process to move desktop applications towards the iOS model instead.


Replies

Someone • yesterday at 10:25 AM

> On Linux the problem is in the UI/UX layer (actually configuring SELinux rather than working around it is a massive pain) but Apple/Google/MS have the money to solve that.

That assumes it can be solved and even then it requires research, so you cannot know how much effort it takes to find a solution.

Also, and IMO highly likely, any solution will be unusable for mere mortals. i thin that’s why you are saying “(dis)pleasure” and “configuring SELinux […] is a real pain”