Apple and a Hacker's Future

(stratechery.com)

71 points | by maguay 2 hours ago

17 comments

  • GeekyBear 1 hour ago
    The full disk access permission is something you give to backup software.

    If you give full-disk access to Meta software running on your main computer, Meta is not going to respect your privacy.

    > Friday’s [full-disk access] announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.

    https://arstechnica.com/security/2026/10/apple-changes-full-...

    If you want to know why Apple is suddenly not happy about the way the full-disk access permission is being abused, look no further.

    • danaris 59 minutes ago
      Counterpoint:

      https://pxlnv.com/blog/macos-full-disk-access-restrictions/

      > ...the uses of Full Disk Access go well beyond the category of backup apps, and it is worrisome to see Apple give it such a limited frame. I have given that permission to disk management utilities, Sketch, Terminal, and other apps I do not want to be throwing permissions requests as I move around my drives. Is Apple suggesting this capability could be limited in the future to backup applications alone? I do not like that.

      If Full Disk Access were, in future, to be something that I could not grant to (for instance) the Terminal, because it is not a backup app, that would severely limit my ability to do work on a Mac, both as hobbyist and as computer professional.

      I agree that the agent situation is a fairly serious concern; I just don't want to see Apple throw the baby out with the proverbial bathwater.

      • GeekyBear 47 minutes ago
        From Apple's statement, there doesn't seem to be any plan to remove the full disk access permission.

        They want unsophisticated users to understand that they would be granting unlimited access to all of their personal data if they grant software that permission.

        > We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.

        • andreareina 1 minute ago
          ... for now. Anytime I download an unsigned binary I need to go through this song and dance of figuring out again what command I need to run to strip the quarantine tag because none of the UIs that are supposed to allow me to trust this binary work.
  • PaulHoule 27 minutes ago
    Apple can’t see a future where Mac isn’t like iPhone. They need a 30% cut of all software revenue, want a 30% cut of any AI tokens you use, and will steal 30% of your time as a software developer developing for your own account any way you can.
  • iphonecorridor 19 minutes ago
    I have a Macmini purposely for Codex to do whatever. Nothing personal on it. It’s been a productivity boost 1000x for me. I screen share in, give it some tasks, tell it to install software, run brew whatever, use QGIS and other complex software and email me screenshots. Astonishing.

    But I’m worried because of this and other guardrails all of that will be impossible or much harder in the future.

  • intrasight 1 hour ago
    > The question, however, is whether what they are designed for is the future I am barreling towards, one where agentic abstraction both renders traditional interfaces relics

    I think he was burying the lede but glad he finally posed the question.

    I think it's a bigger risk factor for Apple than is generally assumed. If consumers get used to the freedom but endemic spying of products like Muse, Apple may have a hard time sticking to their privacy and security mandate.

    • GeekyBear 55 minutes ago
      From Apple's statement, they want to be sure users understand that they are handing Meta access to all of their personal data if they grant Muse (or other AI agents) the full-disk access permission.

      > Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.

      As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.

  • Someone 1 hour ago
    > This system is annoying but manageable on your primary Mac; it’s a disaster on a headless Mac running agents, for two reasons. First, agents write new programs all of the time, and in my case, those programs need access to devices on my network (SMB shares, for example, trigger a TCC warning). What I need is a permission layer for agents, not the programs they create; TCC is operating at the wrong level of abstraction.

    Doesn’t that already exist? If I give Terminal.app access to the entire disk, CLI tools started by the app (indirectly: Terminal.app runs a shell, and the shell runs the tools) have that access, too.

    And I don’t think that’s because Apple gives Terminal.app preferential access. Google tells me that works for iTerm, too.

    Or would it mean agents need to do some special thing to launch tools?

    • lenkite 56 minutes ago
      I think some standards org needs to define comprehensive agent permissions model first before the OS raises the abstraction to agent level authorization.
      • TeMPOraL 46 minutes ago
        Might be that you'll need LLMs to define the model, as LLMs will immediately drive a truck through any hole the standard left in by accident. They're really good at this.
  • hennell 49 minutes ago
    Is the conclusion of this that Apple shouldn't add robust and hard to automate around privacy guards because we should all just do as he does - use a dedicated Mac mini for agents with no personal files on for privacy?
    • geerlingguy 4 minutes ago
      I assume any computer connected to my LAN is also a dedicated attack vector for everything on my LAN in case of compromise.

      Exposing any port directly to the Internet is a huge risk these days—at minimum I'd put a very strong firewall in front, and unless it's serving the general public, switch to a non standard port. It's not much but would prevent the dumb automated scripts that operate on standard ports.

  • jeremyjh 1 hour ago
    Couldn’t you give agents access to the screen sharing software to see the TCC prompts?
  • mcepl 1 hour ago
    If the main to run Apple computers is their hardware, why not to run it with Linux. Aside from better filesystems (Theo tests were shocking to me, how bad FS you guys have), you would get better compartmenalization and I believe better security. What's missing?
    • pasc1878 17 minutes ago
      Linux.

      There is no Linux that will run on anyhing newer than M4 and even that is incomplete.

  • wowanapple 17 minutes ago
    The sole fact that products from Apple and many other proprietary manufacturers receive so much attention on the discussion board called "Hacker News" is utterly ridiculous. A good example is the thread named "Turn off Apple Intelligence on macOS 27 and get its disk space back" with 600+ points and 400+ comments on the main page today.

    What's worse is that a big part of the discussion here is just worshipping closed-source from a merely consumer perspective ('...wow! what a cool shiny UI feature to manage SSH keys for only 0.99$'), as if we were on the Tom's Guide forums. And some active members here even purchase browsers and seem to be very proud about it...

    • Klonoar 1 minute ago
      I will never understand comments like this.

      You are on the wrong site if you think that HN was ever a bastion of the hyper OSS mindset.

      This is a site powered by and run by one of the arms of a startup incubator/investor. It has always been clear on that.

      Just because it has “hacker” in the name doesn’t mean what you think it means.

  • nixosbestos 1 hour ago
    I feel like this article was all over the place. Also, this person was really running a macOS box raw on the Internet, no firewall, nothing? :/
    • GeekyBear 1 hour ago
      He also had that computer configured to download system updates automatically, but not to install them.

      On the plus side, at least he didn't run the AI agent on the computer with all of his personal data.

    • mold_aid 1 hour ago
      "Thank god the causes told me about the effects!"
  • Vvector 1 hour ago
    The vuln required "port 5900 was accessible from the Internet"

    Why would anyone open up random ports (or even all ports) to the internet?

    • DuncanCoffee 1 hour ago
      it's a vnc port, it'd also require the router to have it opened. Reading the article I think the user opened it themselves. It does get opened automagically on the mac side when screen sharing is turned on.

      > The problem is that for my particular use case — a headless, always-on Mac Mini that I primarily access from other computers and my phone through the ChatGPT and Claude apps — macOS is incredibly hostile

      > As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting.

      > Obviously I should have — and will be — using a VPN going forward (the foundation of my entire approach to security is Tailscale); what I will note, however, is that TCC basically leaves me no choice but to have screen sharing enabled if I want to actually use my Mac Mini in the way I want to use it. I use screen-sharing constantly — including from my phone — and almost every time it’s to click “OK” on a stupid prompt that I’ve long since stopped taking seriously.

    • LoganDark 1 hour ago
      I opened my SSH port to the internet back in the day because I could tunnel my internet through it to avoid network blocks. (sshuttle my beloved)
  • hombre_fatal 2 hours ago
    > Apple doesn’t seem too happy about agents

    I don't get this reaction to Apple making Full Disk Access more explicit. Whether they're "happy" or "sad" about agents doesn't seem responsive at all.

    Kinda seems like whenever you spend 10 seconds thinking about the average user, social media gets angry. The quoted justification by Apple seems reasonable.

    • askonomm 2 hours ago
      Being happy or not has nothing to do with it, in my understanding as well. Removing full system access from non-deterministic tools prone to prompt injections seems like the most obvious thing to do. There's a reason I run all my projects in rootless isolated containers these days. There has never really been "trust" in software, but the lack of trust is a lot more obvious these days.
  • chrisjj 42 minutes ago
    > What I need is a permission layer for agents, not the programs they create; TCC is operating at the wrong level of abstraction.

    Or... you are operating your computer at the wrong level of abstraction. It was made for use by a real intelligence.

    • trollbridge 21 minutes ago
      We already have all these permission layers too. SELinux and Windows NT have existed for a long time.

      So has macOS. It’s just a matter that the agents don’t bother to use the existing permission layers.

  • impure-aqua 51 minutes ago
    [dead]
  • mertbio 1 hour ago
    [dead]
  • soltanov 1 hour ago
    It is not about emotion; it is about platform control. Apple limits background autonomy under the label of security, while ensuring only their first-party system frameworks get unfettered ambient access. Standard playbook.
    • detourdog 1 hour ago
      This seems like sysadmin 101 to me. Controlling local access and who to trust was always the way. Platform vendors always enjoyed this privilege. Overriding the platform vendors software tools was done with variations kept in /usr/local/ and symlinked to over ride the vendors choices.
      • BirAdam 1 hour ago
        Well, you don't even really need symlinks. You can just adjust the order of locations in $PATH
    • simonh 34 minutes ago
      Full disk access is a permission you can grant to software on you Mac, that is not reserved just for Apple, and nothing Apple has said implies they have any intention of removing that class of permission. All they said is that they want users to be fully aware of the implications when granting it.
      • trollbridge 20 minutes ago
        My expectations aren’t high when we’re talking about opening up VNC to the public Internet.
    • rimliu 1 hour ago
      maybe there is a reason they are called... system frameworks?