My experience is on the contrary. Employer-lent laptop only needs to be _not lost_, especially in MNCs. Replacing an MNC laptop is relatively easy and free for the user - as long as it is not lost, by the way.
A missed opportunity though. If it’s USB-C powered, it could be even smaller and Apple could simplify its BOM by including a MacBook Pro charger with it.
Say that you're an official with the Chinese Communist Party (CCP). You have huge stacks of brochures of anti-CCP materials. You've got them scanned and hashed. Next you call Apple and say, "Please alert us if similar imageries appears in your customers' devices. My assistants will send you weekly updates of the required hashes." Apple would say, "Sure, we're just following your law..."
Hence when a Chinese photographs such brochure "in the wild" using an iPhone, someone from "the government" will knock the next day and "strongly enquire" about yesterday's photo. Likewise when a Chinese minor receives an iMessage containing such brochure.
This is just _one_ example case of "extension" of the CSAM database as seen fit by some regulatory body.
I haven’t tested the Finder case though. Nevertheless there is the `tell ‘Finder’ ... do shell script ... end tell` construct that _may_ be able to get the Finder to launch an arbitrary subprocess (and may inherit full disk access) just like how Terminal would.
However I’ve tested mounting a local snapshot using the Terminal having full disk access and found out that it is possible to mount a local snapshot and make the mounted copy ignore Unix file permissions.
(1) Create a snapshot of the entire file system;
(2) or find a recent Time Machine local snapshot; then
(3) mount the snapshot obtained in [1] or [2] without owners enabled, effectively granting Alice read-only access to other people's files without having administrative privileges.
... in this case it _does_, albeit in a roundabout way via Time Machine local snapshots. In short, the attacker can bypass Unix file permissions by mounting a local backup with owners disabled.
Alice finds a recent Time Machine local snapshot and mount that elsewhere with owners disabled. Then Alice can browse everyone else's (recent) files – without needing sudo access.
... fair enough, at one point he wrote most of the user-space utilities in Linux. Although he hasn't gotten around to the kernel, but half is better than nothing, and a free kernel is nothing without _free_ (as in _speech_) user-space utilities to accompany it.
PSA to developers: Notarization alone won't be sufficient. You'll need to staple that notarization ticket as well so that your users' Macs doesn't need to go online to validate whether your app has been tampered (among other things).
1. Nighongo.io Turn this into an offline app, should be a lot less in running costs. Otherwise use advertisements. Initially use Google Ads but try to arrange direct-placement advertisements from related businesses (e.g. Japanese language schools, travel agencies to Japan, etc).
2. Try to sell this to enterprises that uses Go and position it as a lint tool for their Go code base.
But if the above failed, move it to a free tier cloud platform (e.g. Heroku's free tier) and just use it as a portfolio to add in your résumé.
You shouldn't ask HN for these kind of questions as this isn't your primary target demographic. Ask MBA students whether they have LinkedIn profiles (and actively using it) and whether they find it easier to use their LinkedIn credentials to log in.