OpenSSH no longer sandboxed on macOS

(twitter.com)

1 points | by newman314 2 hours ago

1 comments

  • altairprime 1 hour ago
    The API they were using was the Seatbelt kSBXProfilePureComputation policy, which was marked deprecated in macOS 10.8 with at least one old bug reported to OpenSSH when the deprecation notice was added.

    HN talked about this deprecation last year, where someone pointed out that apps have been able to sign their precompiled binaries with the appropriate sandbox entitlements (no permission required from Apple!).

    > UNIX hackers tend to be attracted to sandbox-exec because it looks simple even though it's not, and because doing it Apple's way requires learning a lot of Apple specific tech. Whereas the SBPL is deceptively UNIXy and simple looking.

    https://news.ycombinator.com/item?id=44287740

    I suspect OpenBSD has to decide whether that is of interest to them or not, if they haven’t already. Perhaps they’re unaware? Seems unlikely, but who knows with weird Apple stuff.