108 points maguay 4 hours ago 93 comments
hombre_fatal 3 hours ago | parent
I don't get this reaction to Apple making Full Disk Access more explicit. Whether they're "happy" or "sad" about agents doesn't seem responsive at all.
Kinda seems like whenever you spend 10 seconds thinking about the average user, social media gets angry. The quoted justification by Apple seems reasonable.
askonomm 3 hours ago | parent
soltanov 3 hours ago | parent
rimliu 3 hours ago | parent
detourdog 3 hours ago | parent
BirAdam 2 hours ago | parent
simonh 2 hours ago | parent
trollbridge 2 hours ago | parent
intrasight 3 hours ago | parent
I think he was burying the lede but glad he finally posed the question.
I think it's a bigger risk factor for Apple than is generally assumed. If consumers get used to the freedom but endemic spying of products like Muse, Apple may have a hard time sticking to their privacy and security mandate.
GeekyBear 2 hours ago | parent
> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.
As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.
j16sdiz 1 hour ago | parent
The risk of having human assistant can be mitigated by background check, insurance and legal recourse. We have none of these for AI agents.
rickdeckard 1 hour ago | parent
This "you are entering the wilderness, I will not be able to protect you anymore if you proceed" framing reminds me of the alternative AppStore case, where Apple (and Google) applied scare-tactics in the UI to discourage users from giving permissions to alternative stores.
brigade 1 hour ago | parent
Which happens to be the only way to disable the TCC permission dialogs OP complains about. Guess the warnings worked well enough that no one knows that anymore.
coastalpuma 1 hour ago | parent
rickdeckard 1 hour ago | parent
So as always, for the sake of "privacy" Apple needs to take action to protect the users from "themselves", and make it undesirable to grant others the same access Apple has...
jeremyjh 3 hours ago | parent
wpm 37 minutes ago | parent
jeremyjh 30 minutes ago | parent
GeekyBear 3 hours ago | parent
If you give full-disk access to Meta software running on your main computer, Meta is not going to respect your privacy.
> Friday’s [full-disk access] announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.
https://arstechnica.com/security/2026/10/apple-changes-full-...
If you want to know why Apple is suddenly not happy about the way the full-disk access permission is being abused, look no further.
danaris 2 hours ago | parent
https://pxlnv.com/blog/macos-full-disk-access-restrictions/
> ...the uses of Full Disk Access go well beyond the category of backup apps, and it is worrisome to see Apple give it such a limited frame. I have given that permission to disk management utilities, Sketch, Terminal, and other apps I do not want to be throwing permissions requests as I move around my drives. Is Apple suggesting this capability could be limited in the future to backup applications alone? I do not like that.
If Full Disk Access were, in future, to be something that I could not grant to (for instance) the Terminal, because it is not a backup app, that would severely limit my ability to do work on a Mac, both as hobbyist and as computer professional.
I agree that the agent situation is a fairly serious concern; I just don't want to see Apple throw the baby out with the proverbial bathwater.
GeekyBear 2 hours ago | parent
They want unsophisticated users to understand that they would be granting unlimited access to all of their personal data if they grant software that permission.
> We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.
andreareina 1 hour ago | parent
GeekyBear 1 hour ago | parent
Microsoft attempted to lock Windows to their app store twice, with both Windows RT and Windows S, but the market rejected both of those attempts.
Apple hasn't done that, despite claims that it's coming any day now for at least a decade.
snazz 1 hour ago | parent
throw0101a 1 hour ago | parent
This brought to mind Neal Stephenson's essay "Unix - The Hole Hawg of Operating Systems" from back in the day (1999):
> I myself used a Hole Hawg to drill many holes through studs, which it did as a blender chops cabbage. I also used it to cut a few six-inch-diameter holes through an old lath-and-plaster ceiling. I chucked in a new hole saw, went up to the second story, reached down between the newly installed floor joists, and began to cut through the first-floor ceiling below. Where my homeowner's drill had labored and whined to spin the huge bit around, and had stalled at the slightest obstruction, the Hole Hawg rotated with the stupid consistency of a spinning planet. When the hole saw seized up, the Hole Hawg spun itself and me around, and crushed one of my hands between the steel pipe handle and a joist, producing a few lacerations, each surrounded by a wide corona of deeply bruised flesh. It also bent the hole saw itself, though not so badly that I couldn't use it. After a few such run-ins, when I got ready to use the Hole Hawg my heart actually began to pound with atavistic terror.
> But I never blamed the Hole Hawg; I blamed myself. The Hole Hawg is dangerous because it does exactly what you tell it to. It is not bound by the physical limitations that are inherent in a cheap drill, and neither is it limited by safety interlocks that might be built into a homeowner's product by a liability-conscious manufacturer. The danger lies not in the machine itself but in the user's failure to envision the full consequences of the instructions he gives to it.
natpalmer1776 1 hour ago | parent
I do not want to hand my child a Hole Hog, I want to hand them a residential power drill with the torque settings locked to a safe level. I need a fucking Hole Hog for the work I do.
There is a time and a place for every tool, and sometimes the hands holding the tool influence this more than an expert would care to admit, who instead say things like “you’re doing it wrong!” to admonish users who didn’t even know there was a difference between the tool they held and the one they needed.
GeekyBear 1 hour ago | parent
rm -rf / would like a word.
natpalmer1776 57 minutes ago | parent
someonebaggy 43 minutes ago | parent
natpalmer1776 38 minutes ago | parent
To your point though, not everything in Mac can be solved via root user privilege. SIP is annoying to toggle, the main issue being discussed also demonstrates why Mac OS is not the proverbial Hole Hawg as well.
throw0101a 16 minutes ago | parent
macOS in its default configuration may not be the HH, but if SIP removes those limitations it is still available.
As someone who (a) does some tech support for family, but also (b) uses a MacBook for sysadmining Linux servers, but kind of happy with the current balance. I don't think I've run into SIP limitations, so perhaps I'm not an 'advanced' enough user of macOS (MacPorts generally works for the 'extras' I need on top of base macOS).
natpalmer1776 4 minutes ago | parent
So I rescind “needing” a hole hawg and correct it to “strongly prefer or desire” a hole hawg. Mainly because I shouldn’t have to rip apart a magic keyboard to embed a touch ID module into a 3D printed case for a standalone fingerprint reader module.
swader999 4 minutes ago | parent
Vvector 3 hours ago | parent
Why would anyone open up random ports (or even all ports) to the internet?
LoganDark 3 hours ago | parent
DuncanCoffee 2 hours ago | parent
> The problem is that for my particular use case — a headless, always-on Mac Mini that I primarily access from other computers and my phone through the ChatGPT and Claude apps — macOS is incredibly hostile
> As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting.
> Obviously I should have — and will be — using a VPN going forward (the foundation of my entire approach to security is Tailscale); what I will note, however, is that TCC basically leaves me no choice but to have screen sharing enabled if I want to actually use my Mac Mini in the way I want to use it. I use screen-sharing constantly — including from my phone — and almost every time it’s to click “OK” on a stupid prompt that I’ve long since stopped taking seriously.
fg137 1 hour ago | parent
That's my takeaway from the article. I have trouble understanding how the author managed to extrapolate all these things about Apple from an obvious oversight on their part. I would never write a 3,000-word article about how bad someone else is because of an issue I caused for myself.
Software WILL have bugs and vulnerabilities, regardless of whether it's an OS or user application, whether it's from Apple or another company, or the update frequency/mechanism. If you can't even follow the most basic security practice on your part, you simply don't have any authority to discuss security otherwise.
nixosbestos 3 hours ago | parent
GeekyBear 3 hours ago | parent
On the plus side, at least he didn't run the AI agent on the computer with all of his personal data.
mold_aid 2 hours ago | parent
Someone 3 hours ago | parent
Doesn’t that already exist? If I give Terminal.app access to the entire disk, CLI tools started by the app (indirectly: Terminal.app runs a shell, and the shell runs the tools) have that access, too.
And I don’t think that’s because Apple gives Terminal.app preferential access. Google tells me that works for iTerm, too.
Or would it mean agents need to do some special thing to launch tools?
lenkite 2 hours ago | parent
TeMPOraL 2 hours ago | parent
mcepl 2 hours ago | parent
pasc1878 2 hours ago | parent
There is no Linux that will run on anyhing newer than M4 and even that is incomplete.
datagazing 1 hour ago | parent
Better design in terms of resource isolation and control, too.
I use krunai. It is not quite as flexible as some people probably want (strongly linked to a specific non-systemd version of Debian 13), but there are many other options as well, such as Lume, Virtualization.framework, etc.
Much better than wrangling server code via Apple nonsense, and there are no real downsides after you've done the integration/deployment work once, assuming you are not building on some closed source thing that only runs on macOS.
tucosan 1 hour ago | parent
hennell 2 hours ago | parent
geerlingguy 1 hour ago | parent
Exposing any port directly to the Internet is a huge risk these days—at minimum I'd put a very strong firewall in front, and unless it's serving the general public, switch to a non standard port. It's not much but would prevent the dumb automated scripts that operate on standard ports.
chrisjj 2 hours ago | parent
Or... you are operating your computer at the wrong level of abstraction. It was made for use by a real intelligence.
trollbridge 2 hours ago | parent
So has macOS. It’s just a matter that the agents don’t bother to use the existing permission layers.
PaulHoule 2 hours ago | parent
rickdeckard 1 hour ago | parent
But I'm sure the day of the iOS-based iMac will come, and pandora's box will be opened. Businesses will love it, especially those with Kiosk use-cases, and not before long we will read everywhere (including here) how superior the security is to a Mac for everyday use...
PaulHoule 1 hour ago | parent
But to back into it…. OpenClaw amd Muse and stuff give people a real reason to buy a Mac but Apple doesn’t like it.
rickdeckard 1 hour ago | parent
Yeah, because a year down the road they might give the same people a reason to upgrade to another box, not from Apple.
Apple needs to ensure that they stand in the middle of every supplier relationship their customers have.
That's quite difficult when they don't provide direct value to both, so the natural conclusion is for Apple to present itself as a care-taker, the only one who prevents the user from taking any harm...
brookst 13 minutes ago | parent
easyThrowaway 1 hour ago | parent
It does, it's called the MacBook Neo.
iPad sales have been rather stagnant in the last few years, while they made bank with their low-cost laptop. On a purely conceptual level I don't think they're gonna merge the two anytime soon, even if they will probably start sharing the very same logic board from their next revision.
PaulHoule 52 minutes ago | parent
fauigerzigerk 1 hour ago | parent
I think the way this could work is by linking certain capabilities to MDM or a developer program membership. Organisations and people who really need it would still be able to get it but regular users would not.
swozey 1 hour ago | parent
Did anyone hit the bat signal on yet do we just move into a no hardware society? Next laptops gonna cost $5k? My 2021 m1 max 64gb was $3500 and I couldn't believe I spent that, now it's I think $5900 or so. Before that every 3 years I bought. $2k pc laptop and put maybe $1000 into a desktop build.
How many kids even own computers today? The young genz I know do work on their iphones. Like, literally write college papers on an iphone. I can't imagine.
Starting to feel like the entire computer industry is going to get ai slopped. Who needs a technical server operating system when a CEO can stick a reboot, write code or backup database button on an omarchy kiosk, fire your entire SWE org.
amelius 6 minutes ago | parent
Can you blame them? Their managers cannot code, so they need something else that is "useful" to do. And the one thing they find useful is to increase revenue.
iphonecorridor 2 hours ago | parent
But I’m worried because of this and other guardrails all of that will be impossible or much harder in the future.
wowanapple 2 hours ago | parent
What's worse is that a big part of the discussion here is just worshipping closed-source from a merely consumer perspective ('...wow! what a cool shiny UI feature to manage SSH keys for only 0.99$'), as if we were on the Tom's Guide forums. And some active members here even purchase browsers and seem to be very proud about it...
Klonoar 1 hour ago | parent
You are on the wrong site if you think that HN was ever a bastion of the hyper OSS mindset.
This is a site powered by and run by one of the arms of a startup incubator/investor. It has always been clear on that.
Just because it has “hacker” in the name doesn’t mean what you think it means.
Citizen_Lame 1 hour ago | parent
shagie 43 minutes ago | parent
From 2010 ... https://news.ycombinator.com/front?day=2010-10-04 that still looks similar (though I find it amusing that Ask HN: So what's new in the world of A.I.? https://news.ycombinator.com/item?id=1754134 is on the front page "... My prediction (heh pun intended) is that you see enormous changes in the field when processing by GPU's becomes much more available. There are some algorithms that are simply difficult to research because labs don't have access to fast enough machines. ...")
There's certainly been some broification and the various reddit exoduses have been shifting the average user a bit.
I do believe you've got your top color set to ff007f rather than ff6600 if you're forgetting what the site looked like then.
AJRF 1 hour ago | parent
ravenstine 1 minute ago | parent
amelius 1 hour ago | parent
The entire iOS/MacOS schism already says enough.
throw0101a 1 hour ago | parent
> Hopefully Apple has in mind a solution to this situation that will still enable knowledgeable power users to confirm agreement to a sufficiently scary warning and put their Macs in a state similar to what we have today. I worry. What alleviates my worst fears is the knowledge that every technical user at Apple itself needs to use their Mac as the powerful Unix workstation OS that it is. Some of us need dangerously powerful tools. Most Mac users, however, do not — and don’t realize they’re using a dangerously powerful Unix workstation with a very friendly (literal) face.
lapcat 1 hour ago | parent
What Gruber didn't realize is that Apple gives its engineers special internal tools that can bypass the restrictions we on the outside have to suffer.
I'm sure it's also the case that internal development macOS builds are compiled differently than public release builds. They basically have to be for Apple engineers to modify them during development.
wpm 38 minutes ago | parent
eddieroger 36 minutes ago | parent
We can disable SIP with a reboot to recovery and a single command. That doesn't seem like too high a bridge to cross and probably as good as any internal tool, if that isn't what they get in the first place.
lapcat 16 minutes ago | parent
But this eliminates all SIP protections, for example, as discussed in the article, preventing Meta Muse from reading your Messages db.
Muse doesn't need Full Disk Access if SIP is disabled.
john_alan 1 hour ago | parent
They didn't renew Golden Gate's UNIX 03 certification this year:
7r33 1 hour ago | parent
fg137 1 hour ago | parent
I got confused for a second how Claude Code and agents are related to this piece. Of course they aren't. Anyone with a half brain about securing their system would never run into any of this in the first place. Hiring Claude Code to do scanning every half an hour is such a waste of tokens.
swozey 1 hour ago | parent
nerdjon 1 hour ago | parent
So did this initiative within Apple just start and we could be looking at this change coming in Mac 28?
I don't remember another time of an announcement like this from Apple of a major change with so little information, though I could be wrong or hint of when.
Regarding the concern, while I do hope that there is still a way to grant actual full disk access to some applications. Even Apple called out a non controversial need for something like that, backup software. I can also think of security scanning software, a lot of businesses have those deployed to corporate Mac's. I do also think that better controls around it, especially in this age of vibe coded apps that never actually think about security or actively hostile companies like meta.
spoonsies 1 hour ago | parent
It’s not like a VPN is some arcane knowledge. I guarantee Claude would have told him or practically yelled at him if he asked how he could have secured his mac exposed to the open internet.
Glad he actually acknowledged it and is getting tailscale or similar.
sharts 58 minutes ago | parent
mixdup 54 minutes ago | parent
Yeah, it was neat that Claude found this, but Thompson showed an almost criminal lack of security awareness by having VNC/ARD open to the internet
terminalbraid 3 minutes ago | parent
m-s-y 38 minutes ago | parent
We’ve known that improperly secured ports and non-firewalled machines get popped. When will people learn?
I know let’s put our power plants and water treatment out there with open ports too. Why should endusers have all the fun?
adolfox 24 minutes ago | parent
ChrisArchitect 9 minutes ago | parent
Updates to Full Disk Access in macOS
herf 4 minutes ago | parent