Hacker News new | past | comments | ask | show | jobs | submit login

macOS clearly has file system isolation though. Sandboxes apps can’t write/read anything outside without an explicit permission.



For some programs sandboxing can work perfectly fine, but for others it can result in anything between noticable UX degradation and a major PITA, because there are enough workflows out there that can't really be sensibly made to work with an "every file access must go through an official 'File open'/'File save' dialogue (or something comparable, like drag-and-drop, or launching a certain program with a certain file)" model.


Sure but it's still possible to install non-sandboxed software. What Chrome would need is protection from _other_ software, not limits on itself.

It's true that as MacOS continues to discourage non-sandboxed software, Chrome can make sideloading more cumbersome to match.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: