Comment Not on macOS (Score 1) 46
A combination of desktop-grade mandatory access controls mediated by launch services through TCC, built-in restrictions with the quartz compositor and the ubiquitous use of hardened runtime means the expectation on macOS is that an application generally does not have access to everything. No cross-application memory access, logs with private information scrubbed even locally, keylogging restricted to a small subset of apps you choose to have the capability, screen scraping limited to the app itself and the global menu bar along the top, etc. In Golden Gate, they're even blocking access to application data directories per-app, starting off with a blacklist approach with the later goal in future versions to make everything fully isolated using whitelisting.
Different OS, different security model to the UNIX tradition the moment GUI apps are used.
Different OS, different security model to the UNIX tradition the moment GUI apps are used.