The full disk access permission is something you give to backup software.
If you give full-disk access to Meta software running on your main computer, Meta is not going to respect your privacy.
> Friday’s [full-disk access] announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.
> ...the uses of Full Disk Access go well beyond the category of backup apps, and it is worrisome to see Apple give it such a limited frame. I have given that permission to disk management utilities, Sketch, Terminal, and other apps I do not want to be throwing permissions requests as I move around my drives. Is Apple suggesting this capability could be limited in the future to backup applications alone? I do not like that.
If Full Disk Access were, in future, to be something that I could not grant to (for instance) the Terminal, because it is not a backup app, that would severely limit my ability to do work on a Mac, both as hobbyist and as computer professional.
I agree that the agent situation is a fairly serious concern; I just don't want to see Apple throw the baby out with the proverbial bathwater.
From Apple's statement, there doesn't seem to be any plan to remove the full disk access permission.
They want unsophisticated users to understand that they would be granting unlimited access to all of their personal data if they grant software that permission.
> We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.
... for now. Anytime I download an unsigned binary I need to go through this song and dance of figuring out again what command I need to run to strip the quarantine tag because none of the UIs that are supposed to allow me to trust this binary work.
Apple can’t see a future where Mac isn’t like iPhone. They need a 30% cut of all software revenue, want a 30% cut of any AI tokens you use, and will steal 30% of your time as a software developer developing for your own account any way you can.
I have a Macmini purposely for Codex to do whatever. Nothing personal on it. It’s been a productivity boost 1000x for me. I screen share in, give it some tasks, tell it to install software, run brew whatever, use QGIS and other complex software and email me screenshots. Astonishing.
But I’m worried because of this and other guardrails all of that will be impossible or much harder in the future.
> The question, however, is whether what they are designed for is the future I am barreling towards, one where agentic abstraction both renders traditional interfaces relics
I think he was burying the lede but glad he finally posed the question.
I think it's a bigger risk factor for Apple than is generally assumed. If consumers get used to the freedom but endemic spying of products like Muse, Apple may have a hard time sticking to their privacy and security mandate.
From Apple's statement, they want to be sure users understand that they are handing Meta access to all of their personal data if they grant Muse (or other AI agents) the full-disk access permission.
> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.
As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.
> This system is annoying but manageable on your primary Mac; it’s a disaster on a headless Mac running agents, for two reasons. First, agents write new programs all of the time, and in my case, those programs need access to devices on my network (SMB shares, for example, trigger a TCC warning). What I need is a permission layer for agents, not the programs they create; TCC is operating at the wrong level of abstraction.
Doesn’t that already exist? If I give Terminal.app access to the entire disk, CLI tools started by the app (indirectly: Terminal.app runs a shell, and the shell runs the tools) have that access, too.
And I don’t think that’s because Apple gives Terminal.app preferential access. Google tells me that works for iTerm, too.
Or would it mean agents need to do some special thing to launch tools?
I think some standards org needs to define comprehensive agent permissions model first before the OS raises the abstraction to agent level authorization.
Might be that you'll need LLMs to define the model, as LLMs will immediately drive a truck through any hole the standard left in by accident. They're really good at this.
Is the conclusion of this that Apple shouldn't add robust and hard to automate around privacy guards because we should all just do as he does - use a dedicated Mac mini for agents with no personal files on for privacy?
I assume any computer connected to my LAN is also a dedicated attack vector for everything on my LAN in case of compromise.
Exposing any port directly to the Internet is a huge risk these days—at minimum I'd put a very strong firewall in front, and unless it's serving the general public, switch to a non standard port. It's not much but would prevent the dumb automated scripts that operate on standard ports.
If the main to run Apple computers is their hardware, why not to run it with Linux. Aside from better filesystems (Theo tests were shocking to me, how bad FS you guys have), you would get better compartmenalization and I believe better security. What's missing?
The sole fact that products from Apple and many other proprietary manufacturers receive so much attention on the discussion board called "Hacker News" is utterly ridiculous. A good example is the thread named "Turn off Apple Intelligence on macOS 27 and get its disk space back" with 600+ points and 400+ comments on the main page today.
What's worse is that a big part of the discussion here is just worshipping closed-source from a merely consumer perspective ('...wow! what a cool shiny UI feature to manage SSH keys for only 0.99$'), as if we were on the Tom's Guide forums. And some active members here even purchase browsers and seem to be very proud about it...
it's a vnc port, it'd also require the router to have it opened. Reading the article I think the user opened it themselves.
It does get opened automagically on the mac side when screen sharing is turned on.
> The problem is that for my particular use case — a headless, always-on Mac Mini that I primarily access from other computers and my phone through the ChatGPT and Claude apps — macOS is incredibly hostile
> As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting.
> Obviously I should have — and will be — using a VPN going forward (the foundation of my entire approach to security is Tailscale); what I will note, however, is that TCC basically leaves me no choice but to have screen sharing enabled if I want to actually use my Mac Mini in the way I want to use it. I use screen-sharing constantly — including from my phone — and almost every time it’s to click “OK” on a stupid prompt that I’ve long since stopped taking seriously.
I don't get this reaction to Apple making Full Disk Access more explicit. Whether they're "happy" or "sad" about agents doesn't seem responsive at all.
Kinda seems like whenever you spend 10 seconds thinking about the average user, social media gets angry. The quoted justification by Apple seems reasonable.
Being happy or not has nothing to do with it, in my understanding as well. Removing full system access from non-deterministic tools prone to prompt injections seems like the most obvious thing to do. There's a reason I run all my projects in rootless isolated containers these days. There has never really been "trust" in software, but the lack of trust is a lot more obvious these days.
It is not about emotion; it is about platform control. Apple limits background autonomy under the label of security, while ensuring only their first-party system frameworks get unfettered ambient access. Standard playbook.
This seems like sysadmin 101 to me. Controlling local access and who to trust was always the way. Platform vendors always enjoyed this privilege. Overriding the platform vendors software tools was done with variations kept in /usr/local/ and symlinked to over ride the vendors choices.
Full disk access is a permission you can grant to software on you Mac, that is not reserved just for Apple, and nothing Apple has said implies they have any intention of removing that class of permission. All they said is that they want users to be fully aware of the implications when granting it.
If you give full-disk access to Meta software running on your main computer, Meta is not going to respect your privacy.
> Friday’s [full-disk access] announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.
https://arstechnica.com/security/2026/10/apple-changes-full-...
If you want to know why Apple is suddenly not happy about the way the full-disk access permission is being abused, look no further.
https://pxlnv.com/blog/macos-full-disk-access-restrictions/
> ...the uses of Full Disk Access go well beyond the category of backup apps, and it is worrisome to see Apple give it such a limited frame. I have given that permission to disk management utilities, Sketch, Terminal, and other apps I do not want to be throwing permissions requests as I move around my drives. Is Apple suggesting this capability could be limited in the future to backup applications alone? I do not like that.
If Full Disk Access were, in future, to be something that I could not grant to (for instance) the Terminal, because it is not a backup app, that would severely limit my ability to do work on a Mac, both as hobbyist and as computer professional.
I agree that the agent situation is a fairly serious concern; I just don't want to see Apple throw the baby out with the proverbial bathwater.
They want unsophisticated users to understand that they would be granting unlimited access to all of their personal data if they grant software that permission.
> We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.
But I’m worried because of this and other guardrails all of that will be impossible or much harder in the future.
I think he was burying the lede but glad he finally posed the question.
I think it's a bigger risk factor for Apple than is generally assumed. If consumers get used to the freedom but endemic spying of products like Muse, Apple may have a hard time sticking to their privacy and security mandate.
> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.
As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.
Doesn’t that already exist? If I give Terminal.app access to the entire disk, CLI tools started by the app (indirectly: Terminal.app runs a shell, and the shell runs the tools) have that access, too.
And I don’t think that’s because Apple gives Terminal.app preferential access. Google tells me that works for iTerm, too.
Or would it mean agents need to do some special thing to launch tools?
Exposing any port directly to the Internet is a huge risk these days—at minimum I'd put a very strong firewall in front, and unless it's serving the general public, switch to a non standard port. It's not much but would prevent the dumb automated scripts that operate on standard ports.
There is no Linux that will run on anyhing newer than M4 and even that is incomplete.
What's worse is that a big part of the discussion here is just worshipping closed-source from a merely consumer perspective ('...wow! what a cool shiny UI feature to manage SSH keys for only 0.99$'), as if we were on the Tom's Guide forums. And some active members here even purchase browsers and seem to be very proud about it...
You are on the wrong site if you think that HN was ever a bastion of the hyper OSS mindset.
This is a site powered by and run by one of the arms of a startup incubator/investor. It has always been clear on that.
Just because it has “hacker” in the name doesn’t mean what you think it means.
On the plus side, at least he didn't run the AI agent on the computer with all of his personal data.
Why would anyone open up random ports (or even all ports) to the internet?
> The problem is that for my particular use case — a headless, always-on Mac Mini that I primarily access from other computers and my phone through the ChatGPT and Claude apps — macOS is incredibly hostile
> As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting.
> Obviously I should have — and will be — using a VPN going forward (the foundation of my entire approach to security is Tailscale); what I will note, however, is that TCC basically leaves me no choice but to have screen sharing enabled if I want to actually use my Mac Mini in the way I want to use it. I use screen-sharing constantly — including from my phone — and almost every time it’s to click “OK” on a stupid prompt that I’ve long since stopped taking seriously.
I don't get this reaction to Apple making Full Disk Access more explicit. Whether they're "happy" or "sad" about agents doesn't seem responsive at all.
Kinda seems like whenever you spend 10 seconds thinking about the average user, social media gets angry. The quoted justification by Apple seems reasonable.
Or... you are operating your computer at the wrong level of abstraction. It was made for use by a real intelligence.
So has macOS. It’s just a matter that the agents don’t bother to use the existing permission layers.