Mandatory Sandboxing to Beef up Mac Security, But Could Ruin Some Apps
November 4, 2011 10:35 AM
For small apps changes aren't any big deal, but for big apps Apple's new mandatory sandboxing could be game over
Great American statesman Benjamin Franklin once wrote, "They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety."
While he certainly wasn't talking about personal computers, that's exactly the dilemma PC makers find themselves in today. After all, allowing apps full system liberties opens a world of intriguing new possibilities -- but also new dangers.
I. Apple Backs Mandatory Sandboxing on the Personal Computer
Some are voicing support for sandboxing, the idea of preventing apps from "talking" to each other, accessing folders outside their own, executing shell commands, or using the attached hardware (without explicit permissions). So far only one company has
embraced such an approach
for its personal computer -- Google Inc. (
), makers of Chrome OS. But sandboxing is about to get a big new proponent as Apple, Inc. (
third largest maker of PCs
in the U.S., is about to roll out the feature on March 1.
For apps that are distributed in retail form or over the internet, developers -- for now -- won't have to comply with the sandboxing restrictions. But sandboxing will be mandatory to all new apps in
the Mac App Store
. Developers will also have to change their existing Mac App Store apps to sandboxed form if they want to post an update.
Under Apple's new sandboxing system apps will be able to request "entitlements", such as access to a web camera, access to USB devices, access to special folders (music, downloads, etc.). While this is similar to how sandboxing is handled in Google's Android operating system, Apple will take things a step further and decide whether the requested entitlements are appropriate as part of the applications submission process.
The new security features will help prevent malware, like the recent wave of trojans sweeping Apple's computers [
Apple wrote developers "the default sandbox environment is as simple as checking [the right] checkbox" in their development environment. For simple apps, that indeed may be all the intervention that is needed in order to assume compliance with the new restrictions. But for power apps, deep debugging, testing, and recoding may be required.
II. Developers Aren't Happy
Developers are upset because they fear that customers won't understand the changes and will simply blame them from removing features which can no longer be implemented under the sandboxing regime.
Some developers are also frustrated at the timing of Apple's decision. They are used to dealing with changes when there's an operating system release, but aren't used to having to make big changes mid-cycle. The latest version of OS X, OS X 10.7 "Lion",
launched back in July
Describes Gus Mueller founder of
Flying Meat Software
, a Mac software company, in
, "It’s being introduced in the middle of an OS cycle. I could see Apple turning it on with the release of 10.8, but forcing the sandbox on developers with a 10.7.x update? That’s crazy."
The changes have some developers considering rebellion -- abandoning the Mac App Store. Even Mr. Mueller a firm App Store proponent acknowledges that the changes "force me to remove one of my applications", the screenshot app FlySketch.
That's troubling because the Mac App Store has already had some struggles to succeed, in the face of
problems like piracy
. Still, it's important not to overstate the reaction -- most developers who use the App Store would be unwilling to turn their back on this
lucrative means of mass distribution
unless they had.
In the end sandboxing should beef up Mac security, although limiting the kinds of apps that can run on Macs in some cases. Developers may enjoy several unhappy months thanks to the decision, but they will likely adapt. After all, iOS -- Apple's operating system for the iPad, iPhone, and iPod Touch -- already implements strict mandatory sandboxing for all apps.
"I want people to see my movies in the best formats possible. For [Paramount] to deny people who have Blu-ray sucks!" -- Movie Director Michael Bay
"Devil Robber" Trojan Infects Macs, Leeches Their GPUs for Bitcoin Profit
November 1, 2011, 10:59 AM
Apple Unleashes Lion, Revamped MacBook Airs; Plastic MacBook Gets the Axe
July 20, 2011, 8:45 AM
Analysts: Apple Now Has More Than 10 Percent of the U.S. PC Market
July 14, 2011, 1:52 PM
Apple Tries to Roll Out Trojan Protection, Only to See New Variety Pop Up
June 2, 2011, 9:00 AM
As Apple Boasts of One Million Downloads for Mac App Store, Piracy Already a Problem
January 7, 2011, 11:00 AM
More Security Issues for Yahoo
February 16, 2017, 7:45 AM
Android Instant Tethering Only Works for Pixel and Nexus Handsets
February 13, 2017, 7:30 AM
WhatsUp with WhatsApp?
August 29, 2016, 5:23 AM
Fuchsia – Google’s New Open Source Operating System
August 17, 2016, 6:30 AM
Windows 10: End of an Era & A New Beginning
August 1, 2016, 9:59 AM
Free Windows 10 offer ends July 29th, 2016: 10 Reasons to Upgrade Immediately
July 22, 2016, 9:19 PM
Most Popular Articles
Samsung Galaxy S8, Rumored Launch Date!
March 18, 2017, 6:45 AM
Lenovo MIIX 510 – Excellent 2-In-One Tablet with Unique Watchband Hinge
March 17, 2017, 7:50 AM
Gigabyte GA-Z170X-Gaming G1 – Intel Thunderbolt 3 Certified Motherboard
March 9, 2017, 6:25 AM
Lenovo ThinkPad T460 - Ultra-Thin and Feather-light
March 3, 2017, 6:00 AM
Nokia has ditched this camera technology in its new smartphones
March 7, 2017, 8:45 AM
Latest Blog Posts
Apple buys an automation app called Workflow. The deal was completed today and brings the app along with its developers.
Mar 23, 2017, 7:35 AM
Apple Announces new color for iPhones and iPads
Mar 22, 2017, 7:45 AM
Instagram: You Can Now Save Live Videos For Later
Mar 21, 2017, 7:49 AM
Samsung Galaxy S8 to Get New Color Scheme
Mar 20, 2017, 7:45 AM
What else to worry about?
Mar 17, 2017, 6:45 AM
Icon of the Day: Intel/ NVIDIA or Mobileye
Mar 16, 2017, 6:15 AM
JUST IN - Twitter Hijacked : High-Profile Account Accesses
Mar 15, 2017, 7:07 AM
Mar 14, 2017, 7:30 AM
News and Tips
Mar 13, 2017, 6:30 AM
iPhone 8 – May Not Get Curved Screen
Mar 11, 2017, 8:00 AM
California paves way to self-driving car tests without humans
Mar 11, 2017, 7:18 AM
Smart Machines V hackers
Mar 10, 2017, 7:00 AM
Uber Can Resume Autonomous Car Testing in California
Mar 9, 2017, 6:50 AM
Mar 8, 2017, 7:09 AM
Mar 7, 2017, 8:45 AM
World news 3-6
Mar 6, 2017, 5:40 AM
Mar 4, 2017, 7:40 AM
Mixed News of the Day
Mar 4, 2017, 6:32 AM
Jaguar Land Rover invests in ride-sharing
Mar 3, 2017, 7:00 AM
Mixed News of The World:
Mar 2, 2017, 7:02 AM
World New 3-1
Mar 1, 2017, 6:30 AM
Gaming News of The Day
Feb 28, 2017, 6:56 AM
More Blog Posts
Copyright 2017 DailyTech LLC. -
Terms, Conditions & Privacy Information