Forwarded from 一平 陈
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from ɹoʇɔᴉΛ
Twitter
林肯法球
iOS 11 的日常 😑
Forwarded from Deleted Account
复现步骤:
进入 App A
点击 App B 的通知
划掉 App A
回到 App B 点左上角
进入 App A
点击 App B 的通知
划掉 App A
回到 App B 点左上角
Forwarded from Coke 🥤
苹果又陷数据安全门?macOS应用窃取用户记录.
https://m.cnbeta.com/view/765601.htm
https://m.cnbeta.com/view/765601.htm
Coke 🥤
苹果又陷数据安全门?macOS应用窃取用户记录. https://m.cnbeta.com/view/765601.htm
傻逼媒体标题党,啥时候他们关注下 BAT 那几个应用收集了多少用户信息
Forwarded from Richard Yu
我有疑问的是,不是说 Mac App Store 的应用也会运行在沙盒中吗?为什么还能窃取浏览器数据?
这次事件我觉得不是沙盒机制本身的问题,但是沙盒本身就有很多种绕过的方法:
- 配置 ennoscriptment(需要 MAS 审核,但是安全软件的话扫描文件看起来挺合理的)
- 应用通过弹出系统打开对话框并欺骗用户点击打开按钮来永久获得该文件夹及其子文件夹和文件的访问权限
- 一些其它辅助功能权限
这些东西 macOS 上没有明确的风险提醒(当然可能也做不了),所以其实很容易欺骗用户来完成这些操作
- 配置 ennoscriptment(需要 MAS 审核,但是安全软件的话扫描文件看起来挺合理的)
- 应用通过弹出系统打开对话框并欺骗用户点击打开按钮来永久获得该文件夹及其子文件夹和文件的访问权限
- 一些其它辅助功能权限
这些东西 macOS 上没有明确的风险提醒(当然可能也做不了),所以其实很容易欺骗用户来完成这些操作
Daring Fireball 的说法证实了我之前的猜测:
Contrary to some reports, Adware Doctor didn’t find some sort of hole in the sandbox that prevents apps downloaded from the Mac App Store from being able to access the entire file system. The app asked permission from the user, which is the only way Utilities like this can work.
Contrary to some reports, Adware Doctor didn’t find some sort of hole in the sandbox that prevents apps downloaded from the Mac App Store from being able to access the entire file system. The app asked permission from the user, which is the only way Utilities like this can work.