Toot

Written by bdash on 2024-12-02 at 04:24

I've recently been working to understand what triggers certain TCC prompts on macOS. During this investigation I noticed something that many prior analyses of TCC overlook: TCC prompts can be triggered not only by system frameworks, but by the Sandbox kernel extension in response to rules defined by the platform sandbox policy.

My latest blog post documents the sandbox features behind this and provides examples of some of the responsible sandbox policies.

https://bdash.net.nz/posts/tcc-and-the-platform-sandbox-policy/

=> More informations about this toot | View the thread | More toots from mrowe@bdash.net.nz

Mentions

Tags

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113581324588826085
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
221.958412 milliseconds
Gemini-to-HTML Time
0.768004 milliseconds

This content has been proxied by September (ba2dc).