Hacker News new | ask | show | jobs
by mikeash 4498 days ago
All new App Store apps require sandboxing now, so as long as Apple's sandbox is tight (not a given, but it's supposed to be) then you can't do anything harmful. Apple won't sign anything you give the that isn't sandboxed.

The updater for Apple's own stuff obviously doesn't have this constraint, but it should involve a different signing key than the one used for third-party apps.