62 points dkobia 59 minutes ago 11 comments
ParanoidShroom 33 minutes ago | parent
daishi55 25 minutes ago | parent
ryandrake 23 minutes ago | parent
This used to work when you could trust the software you ran on your system to have access to everything you have access to on your computer. I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.
Best solution is to simply not run software made by blatantly untrustworthy developers. Second best solution would be to run such software as a severely sandboxed user who basically doesn't have access to anything important on your system.
graemep 12 minutes ago | parent
> I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.
Agreed, but what can you do about your OS vendor?
VCFundedGenYer 31 minutes ago | parent
I’d argue this is a five alarm fire for macOS and Meta simply exploited it.
PaulHoule 10 minutes ago | parent
dec0dedab0de 4 minutes ago | parent
jkingsman 31 minutes ago | parent
Permissionless action is about to skyrocket as an issue, but this particular scenario strikes me as incredibly unlikely. Would be interested to know if Muse can provide more meaningful data provenance/logs.
Scanning iMessage dbs as a passive part of full disk access (and not a messages grant), if true, is a little sketchy, regardless.
bethekidyouwant 29 minutes ago | parent
lapcat 12 minutes ago | parent
This is absolutely untrue, and impossible.
I haven't spoken directly with Aten, but I have second-hand information from someone who has spoken directly with Aten, and it turns out that he has two Macs and may have allowed Full Disk Access to Muse on one of them.
iamacyborg 4 minutes ago | parent