http://lacquer.fi/pauli/blog/2011/11/why-the-mac-app-sandbox...
(HN discussion link: http://news.ycombinator.com/item?id=3191021)