• @[email protected]OP
    link
    fedilink
    English
    16
    edit-2
    1 year ago

    An app should not be able to access stuff the user did not consent to letting access.

      • @[email protected]OP
        link
        fedilink
        English
        2
        edit-2
        1 year ago

        The file picker API is there to allow apps to access and save files with the user’s consent, while bot having any filesystem access. So a properly sandboxed app would be able to open, edit, and save files wherever the user wants, while not having access to any other irrelevant files, such as your .bashrc or memes folder.

      • @SuperIce
        link
        English
        121 year ago

        Even if I trust the app, it may have security bugs. Still better to have it sandboxed.

      • @[email protected]OP
        link
        fedilink
        English
        3
        edit-2
        1 year ago

        Well, no matter how I trust my photo editing app, it has no business accessing my thesis documents. Proper filesystem sandboxing does security properly.

      • @mdurell
        link
        11 year ago

        I would argue this is only for apps you CAN trust. Bad actors gonna act badly.