Re: [SailfishDevel] community thoughts on app security

2013-12-02 Thread Marcin M.
But an important thing must be done: you can run a script, create a start-up script and not mess with any security frameworks (like chaning mac on Harmattan) -- Marcin 2013/12/1 AL13N > > 2) Sandboxes are limiting, but matter. It is way more difficult to freeze > > to death or misuse iPhone tha

Re: [SailfishDevel] community thoughts on app security

2013-12-01 Thread AL13N
> 2) Sandboxes are limiting, but matter. It is way more difficult to freeze > to death or misuse iPhone than Android. That probably goes against > Mer/Sailfish philosophy though. IMHO: Sandboxing is something that helps for security and QA, and if it's done structurely, it might even help develop

Re: [SailfishDevel] community thoughts on app security

2013-12-01 Thread Marcin M.
Or maybe just leave it to the user, whether to use a sandbox or not? (set the default behavior and make override rules) -- Marcin 2013/12/1 Sven Putze > > >> > >> 2) Sandboxes are limiting, but matter. It is way more difficult to > freeze to death or misuse iPhone than Android. That probably g

Re: [SailfishDevel] community thoughts on app security

2013-12-01 Thread Sven Putze
>> >> 2) Sandboxes are limiting, but matter. It is way more difficult to freeze to >> death or misuse iPhone than Android. That probably goes against Mer/Sailfish >> philosophy though. > Yeah, I would say properly tested applications & community feedback are > enough and no artificial limitat

Re: [SailfishDevel] community thoughts on app security

2013-12-01 Thread Sven Putze
Hi all, there is also the question how to handle rogue apps? Yes, there is a paragraph in the harbour rules that says something like "don't do bad things" but what if an app does? Maybe after some time or triggered from an external server? Users should be at least informed, revoking such apps li

Re: [SailfishDevel] community thoughts on app security

2013-12-01 Thread Martin Kolman
rs, Artem. *From: *AL13N *Sent: *Sunday, December 1, 2013 01:12 *To: *devel@lists.sailfishos.org *Reply To: *Sailfish OS Developers *Subject: *[SailfishDevel] community thoughts on app security plz see the thoughts of 'users' on app security (compiled from IRC #jolla) to be found here: (on

Re: [SailfishDevel] community thoughts on app security

2013-12-01 Thread Sven Putze
Hi Artem and all, > > 2) Sandboxes are limiting, but matter. It is way more difficult to freeze to > death or misuse iPhone than Android. That probably goes against Mer/Sailfish > philosophy though. > But a sandbox must not be a bad thing per se. We could learn a lot from the app bundle file

Re: [SailfishDevel] community thoughts on app security

2013-12-01 Thread artem . marchenko
A couple of points from an experienced of developing several small Symbuan-Meego apps and managing development of iOS apps. Just notes of somebody who likes development yet prefers thinking about the user rather than superior hacker-user.

[SailfishDevel] community thoughts on app security

2013-11-30 Thread AL13N
plz see the thoughts of 'users' on app security (compiled from IRC #jolla) to be found here: (on section of same name) http://elinux.org/Jolla additionally, there's also stuff on jolla hardware there, and some thoughts on defined services on apps(system) for other apps (maybe dbus stuff?) i don