Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Apple developers are smart enough to sandbox a browser and have the installer processes secured enough, there are so many ways to do it.


The point is that every layer helps. It's bad security practice to build a single layer of defense and call it a day. People always find a way through.


Who said only 1 layer ?

You sandbox the browser

you put the installer on a different user

you make the installer always open a popup

you ask for the password/pin

If a JS script can bypass all of this then you have a bigger problem, the malware developers can easily already have a dummpy app already in the app-store that is signed by Apple, the installer signature is the last thing you should worry about in this case (better disable JS now)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: