logoalt Hacker News

0c3ca83 • today at 2:25 AM • 4 replies • view on HN

It really isn't; the program just needs to be able to declare what it expects it should be able to do, and what it expects its children should be able to do. The latter doesn't need to be a subset of the former.


Replies

comex • today at 5:37 AM

The latter does need to be a subset of the former, or else an attacker can trivially work around limitations on "what it should be able to do" by spawning a child instead of doing the thing directly.

But yes, it's unfortunate that macOS sandboxes cannot be nested.

➕ show 1 reply
mindwok • today at 7:13 AM

If the child could do different things to the parent malicious processes would spawn child processes to do stuff they shouldn’t be able to do, though

dcrazy • today at 2:54 AM

That “just” is doing a LOT of work.

➕ show 1 reply
saagarjha • today at 2:35 AM

This is really hard to do in general

➕ show 2 replies