|
|
|
|
|
by simonw
279 days ago
|
|
sandbox-exec is so frustrating. It could be a genuinely excellent solution to a whole bunch of sandboxing problems, except... 1. Documentation is virtually nonexistent. I think that is inexcusable for a security tool! 2. The man page says that it's deprecated, and has done for around a decade. No news on when they will actually remove it, maybe they never will? Hard to recommend it with that axe hanging over it though. |
|
>Hard to recommend it with that axe hanging over it though.
Given the alternative being no way to limit untrusted tooling at all today, it seems worthwhile using it despite these problems?
There's also a (very slim) chance that if it became central to the security of developers on macOS that Apple would give slightly more consideration to it