Mandatory Sandboxing to Beef up Mac Security, But Could Ruin Some Apps
November 4, 2011 10:35 AM
comment(s) - last by
For small apps changes aren't any big deal, but for big apps Apple's new mandatory sandboxing could be game over
Great American statesman Benjamin Franklin once wrote, "They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety."
While he certainly wasn't talking about personal computers, that's exactly the dilemma PC makers find themselves in today. After all, allowing apps full system liberties opens a world of intriguing new possibilities -- but also new dangers.
I. Apple Backs Mandatory Sandboxing on the Personal Computer
Some are voicing support for sandboxing, the idea of preventing apps from "talking" to each other, accessing folders outside their own, executing shell commands, or using the attached hardware (without explicit permissions). So far only one company has
embraced such an approach
for its personal computer -- Google Inc. (
), makers of Chrome OS. But sandboxing is about to get a big new proponent as Apple, Inc. (
third largest maker of PCs
in the U.S., is about to roll out the feature on March 1.
For apps that are distributed in retail form or over the internet, developers -- for now -- won't have to comply with the sandboxing restrictions. But sandboxing will be mandatory to all new apps in
the Mac App Store
. Developers will also have to change their existing Mac App Store apps to sandboxed form if they want to post an update.
Under Apple's new sandboxing system apps will be able to request "entitlements", such as access to a web camera, access to USB devices, access to special folders (music, downloads, etc.). While this is similar to how sandboxing is handled in Google's Android operating system, Apple will take things a step further and decide whether the requested entitlements are appropriate as part of the applications submission process.
The new security features will help prevent malware, like the recent wave of trojans sweeping Apple's computers [
Apple wrote developers "the default sandbox environment is as simple as checking [the right] checkbox" in their development environment. For simple apps, that indeed may be all the intervention that is needed in order to assume compliance with the new restrictions. But for power apps, deep debugging, testing, and recoding may be required.
II. Developers Aren't Happy
Developers are upset because they fear that customers won't understand the changes and will simply blame them from removing features which can no longer be implemented under the sandboxing regime.
Some developers are also frustrated at the timing of Apple's decision. They are used to dealing with changes when there's an operating system release, but aren't used to having to make big changes mid-cycle. The latest version of OS X, OS X 10.7 "Lion",
launched back in July
Describes Gus Mueller founder of
Flying Meat Software
, a Mac software company, in
, "It’s being introduced in the middle of an OS cycle. I could see Apple turning it on with the release of 10.8, but forcing the sandbox on developers with a 10.7.x update? That’s crazy."
The changes have some developers considering rebellion -- abandoning the Mac App Store. Even Mr. Mueller a firm App Store proponent acknowledges that the changes "force me to remove one of my applications", the screenshot app FlySketch.
That's troubling because the Mac App Store has already had some struggles to succeed, in the face of
problems like piracy
. Still, it's important not to overstate the reaction -- most developers who use the App Store would be unwilling to turn their back on this
lucrative means of mass distribution
unless they had.
In the end sandboxing should beef up Mac security, although limiting the kinds of apps that can run on Macs in some cases. Developers may enjoy several unhappy months thanks to the decision, but they will likely adapt. After all, iOS -- Apple's operating system for the iPad, iPhone, and iPod Touch -- already implements strict mandatory sandboxing for all apps.
This article is over a month old, voting and posting comments is disabled
RE: Ahoy matey!
11/4/2011 11:54:17 AM
Comodo firewall as had that feature for way longer.
"Paying an extra $500 for a computer in this environment -- same piece of hardware -- paying $500 more to get a logo on it? I think that's a more challenging proposition for the average person than it used to be." -- Steve Ballmer
"Devil Robber" Trojan Infects Macs, Leeches Their GPUs for Bitcoin Profit
November 1, 2011, 10:59 AM
Apple Unleashes Lion, Revamped MacBook Airs; Plastic MacBook Gets the Axe
July 20, 2011, 8:45 AM
Analysts: Apple Now Has More Than 10 Percent of the U.S. PC Market
July 14, 2011, 1:52 PM
Apple Tries to Roll Out Trojan Protection, Only to See New Variety Pop Up
June 2, 2011, 9:00 AM
As Apple Boasts of One Million Downloads for Mac App Store, Piracy Already a Problem
January 7, 2011, 11:00 AM
Quick Note: Microsoft Windows 10 Gives Users the Finger (Literally)
May 4, 2015, 12:04 PM
AMD CEO: Windows 10 Will Launch at "The End of July"
April 20, 2015, 7:24 PM
Testers Trolled by Promise of Uninstallable Windows 10 Preview Build 10061
April 16, 2015, 2:52 PM
Rumors Heat up About 2016 Windows 10.1 (Windows "Redstone") Release
April 8, 2015, 9:26 PM
Report: Windows 10 Successor is Codenamed "Redstone" After Minecraft Item
April 7, 2015, 2:03 PM
Windows 10 Build 10049 Installation May Take Hours, Will Fail if You Have < 8 GB
March 31, 2015, 2:59 PM
Most Popular Articles
Windows 10 Build 10061: A Quick Review
April 27, 2015, 10:57 AM
Microsoft "Welcomes Developers" to Its New "Edge Browser" (Codename: Spartan)
April 29, 2015, 7:25 PM
Worst Kept Secret -- $35 Million Anonymous Sharing App Startup Shuts Down
April 30, 2015, 7:33 AM
Leather-Bound LG G4 Shuffles Out, "Specially Designed" Snapdragon 808 SoC
April 28, 2015, 4:00 PM
Report: Apple Pulls the Plug on Apple Watch Store Launch
April 16, 2015, 3:18 PM
Latest Blog Posts
Sceptre Airs 27", 120 Hz. 1080p Monitor/HDTV w/ 5 ms Response Time for $220
Dec 3, 2014, 10:32 PM
Costco Gives Employees Thanksgiving Off; Wal-Mart Leads "Black Thursday" Charge
Oct 29, 2014, 9:57 PM
"Bear Selfies" Fad Could Turn Deadly, Warn Nevada Wildlife Officials
Oct 28, 2014, 12:00 PM
The Surface Mini That Was Never Released Gets "Hands On" Treatment
Sep 26, 2014, 8:22 AM
ISIS Imposes Ban on Teaching Evolution in Iraq
Sep 17, 2014, 5:22 PM
More Blog Posts
Copyright 2015 DailyTech LLC. -
Terms, Conditions & Privacy Information