Apple and a hacker's future
stratechery.com
stratechery.com
If you give full-disk access to Meta software running on your main computer, Meta is not going to respect your privacy.
> Friday’s [full-disk access] announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.
https://arstechnica.com/security/2026/10/apple-changes-full-...
If you want to know why Apple is suddenly not happy about the way the full-disk access permission is being abused, look no further.
https://pxlnv.com/blog/macos-full-disk-access-restrictions/
> ...the uses of Full Disk Access go well beyond the category of backup apps, and it is worrisome to see Apple give it such a limited frame. I have given that permission to disk management utilities, Sketch, Terminal, and other apps I do not want to be throwing permissions requests as I move around my drives. Is Apple suggesting this capability could be limited in the future to backup applications alone? I do not like that.
If Full Disk Access were, in future, to be something that I could not grant to (for instance) the Terminal, because it is not a backup app, that would severely limit my ability to do work on a Mac, both as hobbyist and as computer professional.
I agree that the agent situation is a fairly serious concern; I just don't want to see Apple throw the baby out with the proverbial bathwater.
They want unsophisticated users to understand that they would be granting unlimited access to all of their personal data if they grant software that permission.
> We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.
Microsoft attempted to lock Windows to their app store twice, with both Windows RT and Windows S, but the market rejected both of those attempts.
Apple hasn't done that, despite claims that it's coming any day now for at least a decade.
xattr -d com.apple.quarantine /path/to/file
because https://xkcd.com/979/This brought to mind Neal Stephenson's essay "Unix - The Hole Hawg of Operating Systems" from back in the day (1999):
> I myself used a Hole Hawg to drill many holes through studs, which it did as a blender chops cabbage. I also used it to cut a few six-inch-diameter holes through an old lath-and-plaster ceiling. I chucked in a new hole saw, went up to the second story, reached down between the newly installed floor joists, and began to cut through the first-floor ceiling below. Where my homeowner's drill had labored and whined to spin the huge bit around, and had stalled at the slightest obstruction, the Hole Hawg rotated with the stupid consistency of a spinning planet. When the hole saw seized up, the Hole Hawg spun itself and me around, and crushed one of my hands between the steel pipe handle and a joist, producing a few lacerations, each surrounded by a wide corona of deeply bruised flesh. It also bent the hole saw itself, though not so badly that I couldn't use it. After a few such run-ins, when I got ready to use the Hole Hawg my heart actually began to pound with atavistic terror.
> But I never blamed the Hole Hawg; I blamed myself. The Hole Hawg is dangerous because it does exactly what you tell it to. It is not bound by the physical limitations that are inherent in a cheap drill, and neither is it limited by safety interlocks that might be built into a homeowner's product by a liability-conscious manufacturer. The danger lies not in the machine itself but in the user's failure to envision the full consequences of the instructions he gives to it.
I do not want to hand my child a Hole Hog, I want to hand them a residential power drill with the torque settings locked to a safe level. I need a fucking Hole Hog for the work I do.
There is a time and a place for every tool, and sometimes the hands holding the tool influence this more than an expert would care to admit, who instead say things like “you’re doing it wrong!” to admonish users who didn’t even know there was a difference between the tool they held and the one they needed.
rm -rf / would like a word.
To your point though, not everything in Mac can be solved via root user privilege. SIP is annoying to toggle, the main issue being discussed also demonstrates why Mac OS is not the proverbial Hole Hawg as well.
macOS in its default configuration may not be the HH, but if SIP removes those limitations it is still available.
As someone who (a) does some tech support for family, but also (b) uses a MacBook for sysadmining Linux servers, but kind of happy with the current balance. I don't think I've run into SIP limitations, so perhaps I'm not an 'advanced' enough user of macOS (MacPorts generally works for the 'extras' I need on top of base macOS).
So I rescind “needing” a hole hawg and correct it to “strongly prefer or desire” a hole hawg. Mainly because I shouldn’t have to rip apart a magic keyboard to embed a touch ID module into a 3D printed case for a standalone fingerprint reader module.
(Bruce Sterling was the weird hippie who kept feeding interesting things into the machine to see what colors they made - without him, Cyberpunk would’ve died on the vine.)
I really dislike this point of view.
1 - we're all going to suffer because meta are scum. It's not "all application developers", it's "exactly who you assumed it would be", and also too, "exactly the same scum who've spent the last 10 years working around privacy controls any possible way they can and deliberately obfuscating the choices people make around their privacy." The people who made pervert glasses and did covert web-to-app tracking by opening local ports [1] and bought sketchy spyware to track everything you did and scurried away from the light the second someone asked about it [2], [3]. And on and on and on.
Spotify has long asked for it and... they use it to copy my local mp3s onto my phone so I can listen to them away from my computer. It's awesome.
This doesn't mean that Apple isn't champing at the bit to use Meta as an excuse to screw all software developers. If Apple cared about their users, they'd do something like revoke Meta's software keys and leave responsible developers alone. Alas, Apple will obviously exploit this too :(
[1] https://localmess.github.io/
[2] https://en.wikipedia.org/wiki/Onavo
[3] https://uk.practicallaw.thomsonreuters.com/w-040-4130?transi...
Apple considers a user deliberately delegating access to their data to any program not controlled by Apple to be a serious problem that must be corrected.
Application developers are not making the user experience worse, Apple is.
Apple stopped adding protected file-system domains for some reason, and have only expanded TCC to entail more vague and nonsense monikers. Sandboxed apps of importance like Messages, Notes, Reminders, and so on, all just end up under the "Full Disk Access" umbrella because they all store their databases in ~/Library/Containers, and FDA is really the only thing gating access to that. Apple should just start pushing the permissions one level down into that folder. Do I want to give an agent access to my Safari history, but not my messages? Too fuckin bad! No way to slice that right now, it gets full disk access and can access anything.
So, for example, if your backup software is a CLI, you have to give Full Disk Access permissions to your Terminal, not the backup software. And subsequently every other process you start from your terminal will also have Full Disk Access.
Enforcing it per executable down the process hierarchy isn't helpful either: you'll eventually grant it to an interpreter (zsh, python3) and create a hole.
TCC's security model is fundamentally wrong.
Unix solved this decades ago: agents should be their own user. What's missing is the tooling to make disposable users practical, and perhaps cross-platform filesystem ACLs.
That’s a hand waving if I’ve ever seen one.
How is that going to help?
If the Agent gets launched with is own user is will not have access to ANY of the files that are only read by the user.
Of course, as a user, you need some way to easily modify ACLs to do this, but that’s just a front end concern on top of a solid security model that every OS supports.
This is what dedicated higher-level APIs (like ScreenCaptureKit on mac or XDG portals on linux) are made for.
There's a program that lets you use it from the terminal here:
https://github.com/AprilNEA/disclaim
I think Apple don't expose it as public API because TCC is meant to map user permission prompts to things the user understands logically as applications, which means things they started. If apps can have the user be prompted to grant permissions to sub-components of themselves it can get very confusing quite rapidly.
The supported way to do this is therefore to just make a proper Mac app with its own bundle ID, sign it, and ask Launch Services to start it up - potentially via XPC. It will get its own TCC permissions set along with its own icon and so on. You can, if necessary, embed this app inside another one, although of course the thing the user sees as the app being given permission will be the identity of the embedded app so that reintroduces the potential for confusion.
I don't know if the amount of machinery is such a big deal now, an LLM can produce the needed code quite quickly. Those sub-processes shouldn't be disclaimed anyway because they'd end up without a proper code signing/bundle identity and get weird permission restrictions that can't be elevated. Claude App makes this mistake, IIRC.
There was a time I had their FB app and messenger on the phone. Then it was found out that their crappy engineering couldn't hide the fact their apps were constantly watching users and other apps on entire phone, causing >15% additional battery drain, even when they were not opened.
I've removed all of them, never needed them on phone (or at all) and can't complain at all. Don't expect privacy form meta, any, ever.
Overall the limits to AI productivity can be summarized in one word: discipline. If you're undisciplined in your security, your design constraints, your automated test coverage, your separation of the deterministic and indeterministic, you will be quite productive ... for a time. Until quite suddenly, you aren't, possibly due to catastrophe.
Similar to the early era of computers on the Internet, with lax security, we have a window where we can get away with this, but it will close quicker than many realize. Some things do seem to need to be learned the hard way.
Apple is trying to do the bare minimum here - not even introducing a new security model - and people are already freaking out. But a disciplined agent sandbox model is exactly what we need to get to.
In 2019, my SSN was used to purchase 4 iPhones, open 2 credit cards, and used to buy perfume in another state.
In 2026, almost mainstream messaging app monitors your private messages (yes, even Whatsapp now [0]).
Society decided that to be in it, you must give up your privacy along time ago.
[0] - https://engineering.fb.com/2026/08/12/security/how-were-buil...
Look at the Equifax breach - most of the US SSN's, addresses, & more released, and they get a little slap on the wrist and continue doing business. I was in there, I never signed up for equifax, I signed up for companies that signed up with equifax.
That said, it is still a slippery slope argument, just because there will be more data breaches, doesn't mean we should give everything out freely and just give up.
This is a stupid nihilistic take. Gmail hasn't been breached that many times. Your original credentials from the first breach were passed around from black market to other black market and were repackaged. They didn't get your newest password 39 different times. The black markets are a lot like middle quality data brokers -- they don't actually care if their data is the most accurate or up-to-date.
If your credit profile was completely hovered, that's another story. Credit bureaus are simply a knowledge database and are a massive liability. But my credit hasn't been similarly destroyed so there is likely another major variable between our risk profiles. Maybe your physical mailbox has been breached multiple times.
Security hygiene is a lot like physical hygiene. You just need a few rules and you are mostly good. Don't sleep around too much, choose your partners wisely, and use protection when you do find a new partner until you both trust each other enough.
As it pertains to Meta, nobody should trust this company after what they did with iOS contacts on the original Facebook app.
And nobody needs to use Muse. You aren't opting out of society on a Unabomber level if you choose not to use this one AI agent app by a less than trustworthy company.
Yeah, it was neat that Claude found this, but Thompson showed an almost criminal lack of security awareness by having VNC/ARD open to the internet
And, all of that said, Apple hasn't said anything about not letting people have full access to their disks. Just that you're going to have to be very intentional, click through a very scary warning, to do so. Happy to do that to prevent my mom or dad from accidentally opening up their machine to every hacker in Belarus or worse yet Facebook
Correct. This is why gun safety is taught. Try and bring up banning shotguns in the US and see what happens.
b) there are plenty of options for completely open computing platforms. Apple has every right to build the platform they want to build, and you as a consumer have every right to go buy a Framework laptop and install Debian on it instead if you don't like it
For now.
Younger folks are skipping computers entirely and doing their work on mobile devices. Computer literacy is falling. Demand for computers is going to continue falling as those kids grow up. They won't need to touch a computer unless their future job requires it. Not even school would need it - many already use their phone/tablet or a Chromebook to do school work.
Nobody is taking away our computers but, overall, they are being replaced with closed platforms. It is just a question of how much of them can actually be replaced and will it be a big enough market to keep developing desktop Windows/macOS/Linux?
that said, we've never been closer to Linux on the Desktop (TM) than we are right now, even if it's through dumb stuff like Omarchy. There's no risk today that you won't be able to, in 10 years, buy an x86 or ARM laptop and put some flavor of Linux on it for personal use
Is it because of most of virus/malware target Windows OS due to its sheer size, or because MacOS security system is more superior than Windows ?
I also less likely to get hack if i open url link on templeOS
God doesn't believe in the networking stack so you're good
Then take away cars as someone could crash and kill themselves with them. What kind of babyified logic is that?
If you don't like System Integrity Protection on your Mac, you can turn it off and YOLO to your heart's content.
When my mother in law switched from (XP-era) Windows to OS X, she expressed a profound sense of relief that she didn't have to worry so much about accidentally breaking it. She has absolutely no desire to learn computers well enough to understand a system that gives her more control. In her experience it never enabled her to do anything particularly relevant to her own interests, and mostly accomplished the complete opposite by leaving her slightly afraid to do anything. My own efforts to try and explain her computer problems and how to avoid them in the future did not help; they only served to communicate to her that the computer was indeed complicated and scary.
Limitations ARE a liberating force. No limitations is having skyscrapers with doors opening to outside, because people should have the choice to step out among the birds and the clouds.
The Vision Pro could (in terms of hardware) be the Mac successor. Just the virtual Mac screen feature alone is great ... but the rest is "It's an iPad! But in 3D!" Ugh.
Don't underestimate the power of Apple's dream of locking everything down.
Apple's priorities (as Daring Fireball notes), are Apple, customers, something, something, something, ...., developers and suppliers.
I think Tim Cook missed his chance to leave a Steve Jobs like mark on Apple when he championed a next generation graphical interface on next generation hardware, but only for toy apps and media.
And for those that think "what could 3D/spacial really do for interfaces?", don't think exciting, just think about the simple perks that grow into usefulness, like your entire environment being (Mac-level capable) screens as you work. Consider how much of the real world and its activities, problems and structure are in 3D. And how people adapted to 2D graphical interfaces not because "wow!", but because many mundane things, like editing a table and writing a letter, got easier. And a lot of new mundane things became possible/practical.
That won't happen on a Vision "Pro" limited to being a toy app platform, media kiosk, and Apple iCloud services recurring revenue store front.
The software limitations are why it isn't worth the price, not the hardware.
The negativity here climbs up out of my deep love for my Vision Pro.
If you want to be responsible for your own compute security, you can run Linux.
IMO this is a good balance: hobbyist or professionals who know what they’re doing have an OS, and people who don’t care can go to Best Buy. Everyone wins
"If you are protected by a steel door, but you don't have the key, you are not safe -- you are imprisoned."
So I totally agree with you. This is exactly why you need to protect users from themselves. There will always be bugs in software and you should minimize the risk from them by taking some security measures.
That said, I disagree on Apple: while the UI can be perfect, it has always imperfectly been trying to do the right thing technically in concert with developers and users, which puts it in the position of imposing constraints that developers and users can relax to varying degrees: wearable and home devices (not at all), iOS (somewhat), macOS (mostly).
wrt a hacker's future: I'm still traumatized both by decades of windows reboots and virus scanning, and by decades of squeezing into Linux (just don't sleep, avoid these displays...). I'm glad Apple stuff mostly just works and ordinary people still have access to unlocked, general-purpose computers, but that might not last. Cheap AI coding might remove any financial incentive to support users programming on their own, and we'd be left with locked devices as consumers or work-only access to programmable computers (at least for the latest hardware of note). If a 40% premium for mac hardware is the price we pay for continued access, so be it.
It really sucks because Windows at the kernel and OS level is a real gem. The Win32 API is great. But I find myself having to migrate F&F off of it because of the attack vectors. Ubuntu and Fedora will have to do going forward.
Then there is the whole issue of Chrome/Google not allowing ABP and other blockers to run anymore which is just a fuck-you to every human who just wants to use the Web.
Apart from whole post feeling like a PR, but thats not that uncommon here
I think he was burying the lede but glad he finally posed the question.
I think it's a bigger risk factor for Apple than is generally assumed. If consumers get used to the freedom but endemic spying of products like Muse, Apple may have a hard time sticking to their privacy and security mandate.
> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.
As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.
The risk of having human assistant can be mitigated by background check, insurance and legal recourse. We have none of these for AI agents.
This "you are entering the wilderness, I will not be able to protect you anymore if you proceed" framing reminds me of the alternative AppStore case, where Apple (and Google) applied scare-tactics in the UI to discourage users from giving permissions to alternative stores.
Which happens to be the only way to disable the TCC permission dialogs OP complains about. Guess the warnings worked well enough that no one knows that anymore.
Before System Integrity Protection, the root user had no permission restrictions, so it could access any system folder or app on your Mac. Software obtained root-level access when you entered your administrator name and password to install the software. That allowed the software to modify or overwrite any system file
This is the only weapon they have when governments have forced them to open their doors to the scary world outside.
This is not going to end well for everyone involved - especially for the user.
But that's the case on all platforms with any LLM agent being given full access.
There will be an adjustment period where users will learn of the risks - hopefully without much harm occurring.
So as always, for the sake of "privacy" Apple needs to take action to protect the users from "themselves", and make it undesirable to grant others the same access Apple has...
Observationally, I would argue we've all been expecting this for this for a long time. Every year Apple has raised the price of allegiance and every year we've paid it, waiting for products like the framework laptop or certain linux distros to become mature. We're still not there yet, but how much longer until there is real competition in the personal computer market?
So did this initiative within Apple just start and we could be looking at this change coming in Mac 28?
I don't remember another time of an announcement like this from Apple of a major change with so little information, though I could be wrong or hint of when.
Regarding the concern, while I do hope that there is still a way to grant actual full disk access to some applications. Even Apple called out a non controversial need for something like that, backup software. I can also think of security scanning software, a lot of businesses have those deployed to corporate Mac's. I do also think that better controls around it, especially in this age of vibe coded apps that never actually think about security or actively hostile companies like meta.
Doesn’t that already exist? If I give Terminal.app access to the entire disk, CLI tools started by the app (indirectly: Terminal.app runs a shell, and the shell runs the tools) have that access, too.
And I don’t think that’s because Apple gives Terminal.app preferential access. Google tells me that works for iTerm, too.
Or would it mean agents need to do some special thing to launch tools?
Why would anyone open up random ports (or even all ports) to the internet?
> The problem is that for my particular use case — a headless, always-on Mac Mini that I primarily access from other computers and my phone through the ChatGPT and Claude apps — macOS is incredibly hostile
> As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting.
> Obviously I should have — and will be — using a VPN going forward (the foundation of my entire approach to security is Tailscale); what I will note, however, is that TCC basically leaves me no choice but to have screen sharing enabled if I want to actually use my Mac Mini in the way I want to use it. I use screen-sharing constantly — including from my phone — and almost every time it’s to click “OK” on a stupid prompt that I’ve long since stopped taking seriously.
That's my takeaway from the article. I have trouble understanding how the author managed to extrapolate all these things about Apple from an obvious oversight on their part. I would never write a 3,000-word article about how bad someone else is because of an issue I caused for myself.
Software WILL have bugs and vulnerabilities, regardless of whether it's an OS or user application, whether it's from Apple or another company, or the update frequency/mechanism. If you can't even follow the most basic security practice on your part, you simply don't have any authority to discuss security otherwise.
Welcome to hacker news!
Apple's remote access feature, that you would make remotely accessible for obvious reasons, apparently had a critical authentication bug.
Apple did not ship a security patch for this, allowing the vulnerability to be exploited a week later despite "automatically install security updates" being on.
Yes, OP could have prevented this by putting an additional VPN authentication layer in front of the Mac's built-in remote access.
That doesn't excuse the mistakes on Apple's part.
Let's first establish that Apple definitely has a stake in this.
How long they can come up with a fix and then distribute them, that's a question. You can't expect any company to fix a vulnerability within 5min. Whether one week is too long or their delivery mechanism is good, I can't tell, and I don't think there is a standard in the entire industry.
That doesn't mean it's useful to write an article about "I didn't do my part BUT you are too slow". Even if Apple somehow fixes this within an hour of the disclosure and delivers the update, with the bad configuration, the machine is still vulnerable within that window. Does that change the nature of the narrative?
But I find it egregious that they didn't roll it out as a security update at all, which is why it was not automatically installed in OP's case, even though the fix was already available.
I mean, what else requires a hotfix via security update if not a fatal flaw in your remote access authentication leading to full root access, that is actively being exploited in the wild?
Also, it's not really on the user to gate remote access behind an additional firewall and authentication layer. This is something that just has to work securely.
If it doesn't, that's understandable, but still hardly the user's fault.
> Also, it's not really on the user to gate remote access behind an additional firewall and authentication layer. This is something that just has to work securely.
About that, I have a bridge to sell.
An actively and easily exploited (just a port scan), and high-impact root RCE needs faster patching than one week.
When there was a more user visible bug (2017, empty root password gives you root, CVE-2017-13872), Apple managed to remotely patch this across all supported macOS versions in about 26 hours + next macOS online, end to end, without user intervention or manual updates.
And that was a decade ago before Apple built “rapid response security updates”
For Ex, the best practice is to use VPN, so you only open port for VPN, and you assume whatever VPN protocol/software does not have any bugs.
You can use tailscale so you dont have to open port, but after all, tailscale is also software.
Even though this was a valid critical bug [1], you need to enable screen sharing and allow connections to and from port 5900 on your router for a remote person to be able to exploit this.
Any security conscious person would probably be using a VPN (Wireguard or Tailscale) to prevent something like this, in the first place.
> almost every time it’s to click “OK” on a stupid prompt that I’ve long since stopped taking seriously.
The line above tells you how seriously this person takes security prompts.
I mean, every time ISPs, NAT, or IPv6 is mentioned you have a LOT of people who are really angry they can't just netcat a random port on their friends' machine to send files to it.
We’ve known that improperly secured ports and non-firewalled machines get popped. When will people learn?
I know let’s put our power plants and water treatment out there with open ports too. Why should endusers have all the fun?
I got confused for a second how Claude Code and agents are related to this piece. Of course they aren't. Anyone with a half brain about securing their system would never run into any of this in the first place. Hiring Claude Code to do scanning every half an hour is such a waste of tokens.
I'm not sure why a writer needs swarms of agents in the first place.
The 'built a server that's going to run linux' line confused me. gOiNg tO? This boy didn't have 20 minutes to write a usb, shred the disks in live boot and install?
He has decent business takes on tech, the podcast/articles are worth paying attention to. The actual tech takes are probably too dumb for the hn audience, but you aren't the target audience.
1. 5900 was always known to be an extra unsafe port to have open
2. all ports should be assumed unsafe without explicit vetting
I'm assuming the argument being made is (2), but it really is a sad safe of affairs because use cases from time to time do involve having ports hot.
Or should things be taken one step further to *always* use a vpn or similar?
If he is roaming freely, he had no business leaving port 5900 world accessible.
Yes. The vast majority of software is not hardened enough to be exposed to malicious actors. Any kind of control panel, device management interface, NAS/file sharing protocol, remote desktop protocols, and anything else that isn't explicitly designed to be a public service should be protected with a hardened outer layer like a VPN, SSH tunnel, or mutual TLS/client certificate authentication.
> Hopefully Apple has in mind a solution to this situation that will still enable knowledgeable power users to confirm agreement to a sufficiently scary warning and put their Macs in a state similar to what we have today. I worry. What alleviates my worst fears is the knowledge that every technical user at Apple itself needs to use their Mac as the powerful Unix workstation OS that it is. Some of us need dangerously powerful tools. Most Mac users, however, do not — and don’t realize they’re using a dangerously powerful Unix workstation with a very friendly (literal) face.
What Gruber didn't realize is that Apple gives its engineers special internal tools that can bypass the restrictions we on the outside have to suffer.
I'm sure it's also the case that internal development macOS builds are compiled differently than public release builds. They basically have to be for Apple engineers to modify them during development.
We can disable SIP with a reboot to recovery and a single command. That doesn't seem like too high a bridge to cross and probably as good as any internal tool, if that isn't what they get in the first place.
But this eliminates all SIP protections, for example, as discussed in the article, preventing Meta Muse from reading your Messages db.
Muse doesn't need Full Disk Access if SIP is disabled.
And OP had SIP enabled, but his system still got compromised with a remote exploit.
> that's why Muse could get it even with SIP.
Both of these assumptions are mistaken.
I care more about the integrity of my personal privacy than I do about the integrity of the "system". The point of the system is to serve me.
> And OP had SIP enabled, but his system still got compromised with a remote exploit.
Nobody said that SIP magically prevents macOS bugs and security vulnerabilities.
No. The confusion here is that the Stratechery post combines multiple stories. There was a macOS screen sharing vulnerability, now fixed. The vulnerability existed even with SIP enabled, and that vulnerability is how Ben Thompson's Mac was hacked.
The question was, why did Thompson's Mac have the screen sharing port open to the internet, and that's when Thompson explained that the Mac was running an agent.
Coincidentally, Apple published a developer note on Friday about upcoming changes to Full Disk Access, which mentioned AI agents. Apple did not give any specific reason for this change, but presumably the inspiration was a very recent public controversy initiated by a journalist whose Messages database on macOS was read and uploaded by the Meta Muse app. Muse and similar AI apps request Full Disk Access to access all of the user's information. Without SIP, these apps would be able to suck up all of your data without permission.
Sandboxing full disk reads is orthogonal to what SIP actually provides. It's entirely possible for an unsandboxed binary to slurp your private data even with SIP enabled.
No? I'm not.
SIP is of course not a universal defense against every possible kind of attack, but did anyone ever expect it to be?
> Sandboxing full disk reads is orthogonal to what SIP actually provides.
No, because again, as I already said, disabling SIP also disables some TCC privacy protections.
> It's entirely possible for an unsandboxed binary to slurp your private data even with SIP enabled.
Not the data protected by TCC.
- Per-install boot security policies
- Custom kernel boot (kmutil configure-boot)
- Raw-image boot mode
- XNU source releases
- Disabling SIP
- Disabling the Signed System Volume
- Third-party kernel extensions
- Developer ID distribution and notarisation
- Gatekeeper "Open Anyway" override
- Hypervisor.framework
- Virtualization.framework
- Rosetta for Linux VMs
- Nested virtualisation
- macOS guest provisioning
- DiskImageKit
- Custom Virtio devices
- Containerization framework
I don't understand the purpose of your reply?
One of your examples is "Disabling SIP", but you're replying to a thread that has already been discussing this very topic, so it makes no sense to ask us "what about" that.
> - Third-party kernel extensions
Deprecated: https://developer.apple.com/support/kernel-extensions/
The issue is really the difficulty of using macOS as an expert user, and this has become significantly more difficult over the years. You mention "Developer ID distribution and notarisation", but both of those are actually restrictions that were added later to a previously open system. Notarization in particular has become a major pain for developers. Also "Gatekeeper Open Anyway override" has become significantly more difficult for users over the years.
to illustrate, counter to the HN narrative, they've actually done a lot to keep the platform open to hackers and hobbyists.
Sure, remove disabling SIP from the list, the others still stand and are quite compelling IMO.
Fair enough on the kernel extensions.
I take your point(s) but the doom about the Mac turning into iOS and the terminal being taken away is unfounded.
My comment that you replied to was not about the HN narrative. Thus, I still don't understand the purpose of your reply.
I have a PiKVM on my Mac Mini for this reason, and I bet the author would be well served by one as well.
> this setting does not in fact apply to most security updates. CVE fixes almost always arrive in point releases; in fact, the most recent point release was about fixing this bug
So yes, Apple is very bad at security, borderline malicious even.
If the burglar breaks in through the cat door but she wakes you to let you know, did the cat make you more safe?
If there’s some protections that prevent it from happening via localhost, it feels like the next step is to proxy through another host on the LAN.
Heck, I wonder if someone’s already written an app that’ll connect to VNC, look for any permission prompts, and approve. His agent software could just poke it anytime it thinks it’s blocked.
But I’m worried because of this and other guardrails all of that will be impossible or much harder in the future.
This was the most interesting part to me. I wonder what this divide looks like in the real world. I have a hard time believing this is true for everyone:
> I don’t want a different UI per app, when I have at my disposal true UI — the Universal Interface for everything digital.
There is no Linux that will run on anyhing newer than M4 and even that is incomplete.
Better design in terms of resource isolation and control, too.
I use krunai. It is not quite as flexible as some people probably want (strongly linked to a specific non-systemd version of Debian 13), but there are many other options as well, such as Lume, Virtualization.framework, etc.
Much better than wrangling server code via Apple nonsense, and there are no real downsides after you've done the integration/deployment work once, assuming you are not building on some closed source thing that only runs on macOS.
It's insane what people will put up with to avoid just doing it properly on a real OS.
It's the software that matters here, not the hardware.
I don't get this reaction to Apple making Full Disk Access more explicit. Whether they're "happy" or "sad" about agents doesn't seem responsive at all.
Kinda seems like whenever you spend 10 seconds thinking about the average user, social media gets angry. The quoted justification by Apple seems reasonable.
But I'm sure the day of the iOS-based iMac will come, and pandora's box will be opened. Businesses will love it, especially those with Kiosk use-cases, and not before long we will read everywhere (including here) how superior the security is to a Mac for everyday use...
But to back into it…. OpenClaw amd Muse and stuff give people a real reason to buy a Mac but Apple doesn’t like it.
Yeah, because a year down the road they might give the same people a reason to upgrade to another box, not from Apple.
Apple needs to ensure that they stand in the middle of every supplier relationship their customers have.
That's quite difficult when they don't provide direct value to both, so the natural conclusion is for Apple to present itself as a care-taker, the only one who prevents the user from taking any harm...
It does, it's called the MacBook Neo.
iPad sales have been rather stagnant in the last few years, while they made bank with their low-cost laptop. On a purely conceptual level I don't think they're gonna merge the two anytime soon, even if they will probably start sharing the very same logic board from their next revision.
Get out! Desktop are not mobile devices and there is still need for them. Microsoft learnt this the hard way.
I think the barriers that exist depend on path dependence and other accidents of development. The laptop has a hinge and a trackpad that help you when you are flying on a plane. 2-in-1s drove stewardesses crazy because they couldn’t figure out if you had to stow them for takeoff. For that matter battery sizes are limited because of the needs of that industry which might seem justified if you live in NYC and can fly to London for what it less to costs to fly from my small town to NYC. Maybe if they’d invest in my community I’d care what they think but I think it’s unjust.
All the time I use a cheap plastic clip and a cheap Bluetooth mouse and keyboard and RDP into a monster computer from my tablet. If I have a real desk or table it’s fine, if you really have to put your laptop on your lap that hinge looks like genius. I’ll grant the 2-in-1 can be demoed at CES and the Bluetooth-based system can’t because they have too many devices in too small a space for Bluetooth to be reliable.
Even if I don’t have the mouse and keyboard I can still do a lot with the touchscreen.
The worst thing Win 8 revealed was that you could have the ‘windows’ keys on computer keyboards for almost 20 years and nobody noticed because…. It looks like an ad and people think anything that looks like an ad “just doesn’t work” (as opposed to “doesn’t just work”). If you were missing the start button you could just push that button but people treated that like putting their hand in the toilet.
(deleted submission)
https://inti-tidball.writeas.com/por-que-uso-y-recomiendo-dominios-xyz-numericos-para-self-hostingI think that's the unification route they are most likely to take, hopefully along with a thinner/smaller MacBook design and built-in cellular.
They've taken so many swings at the iPad Pro (both hardware and software), and it has never been as good as the MacBook.
I think the way this could work is by linking certain capabilities to MDM or a developer program membership. Organisations and people who really need it would still be able to get it but regular users would not.
businesses can already lock down your mac so you can't use it inappropriately.
I'm reminded of the guy who ran afoul of google, and all of a sudden all his google devices got forced software updates and started doing things.
it is sad, really.
https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2F...
Can you blame them? Their managers cannot code, so they need something else that is "useful" to do. And the one thing they find useful is to increase revenue.
- Per-install boot security policies
- Custom kernel boot (kmutil configure-boot)
- Raw-image boot mode
- XNU source releases
- Disabling SIP
- Disabling the Signed System Volume
- Third-party kernel extensions
- Developer ID distribution and notarisation
- Gatekeeper "Open Anyway" override
- Hypervisor.framework
- Virtualization.framework
- Rosetta for Linux VMs
- Nested virtualisation
- macOS guest provisioning
- DiskImageKit
- Custom Virtio devices
- Containerization framework
Not to take away from your point too much - this is a significant amount of work that shows their current stance towards maintaining the mac as a premium development platform. But I imagine they will start to split this - lower cost SKUs will get the iOS-ified OS while "Pro" SKUs will get (some of) the above and can still install homebrew, to prevent a full developer revolt.
Techies will figure out how to "jailbreak" the lower SKUs to unlock the full experience and the amount of people that follow through with that will round to 0%. Tech businesses will buy the >$3k Pros for their devs.
"Everyone" will be "happy".
In this case apple do this because Meta are abusing.
But as an end user, these are hollow words. As a consumer with Apple devices, I'm entrusting Apple to keep my computer protected from bad software, malicious or otherwise. You need to appreciate that you -- the software developer -- are not the good guy. We're not the same team. If you don't like your little sandbox, or if you resent having to ask for permission to go beyond it, that's a you problem, not a me problem.
As a software developer, I can see it from both sides. I wish more people did.
Exposing any port directly to the Internet is a huge risk these days—at minimum I'd put a very strong firewall in front, and unless it's serving the general public, switch to a non standard port. It's not much but would prevent the dumb automated scripts that operate on standard ports.
On the plus side, at least he didn't run the AI agent on the computer with all of his personal data.
However, this user made the choice to turn off the installation of system updates manually, based on a false assumption.
The entire iOS/MacOS schism already says enough.
They didn't renew Golden Gate's UNIX 03 certification this year:
Or... you are operating your computer at the wrong level of abstraction. It was made for use by a real intelligence.
So has macOS. It’s just a matter that the agents don’t bother to use the existing permission layers.
It’s not like a VPN is some arcane knowledge. I guarantee Claude would have told him or practically yelled at him if he asked how he could have secured his mac exposed to the open internet.
Glad he actually acknowledged it and is getting tailscale or similar.
- Guy writing to you from Windows 11 with multiple Macbook Pros next to him.
Updates to Full Disk Access in macOS
If the TCC prompts could be dismissable some other way (e.g. via CLI with root permission) presumably he wouldn't have resorted to such measures. I sort of see the point, the lesson from Vista is that if you put up annoying obstacles people are going to the easiest workaround, bulldozing over them rather than putting up with them. People will end up disabling SIP or poking more hole if they don't have an easy way to bypass TCC stuff.
I put things behind a conventional firewall and then use a VPN for remote access.
What's worse is that a big part of the discussion here is just worshipping closed-source from a merely consumer perspective ('...wow! what a cool shiny UI feature to manage SSH keys for only 0.99$'), as if we were on the Tom's Guide forums. And some active members here even purchase browsers and seem to be very proud about it...
You are on the wrong site if you think that HN was ever a bastion of the hyper OSS mindset.
This is a site powered by and run by one of the arms of a startup incubator/investor. It has always been clear on that.
Just because it has “hacker” in the name doesn’t mean what you think it means.
From 2010 ... https://news.ycombinator.com/front?day=2010-10-04 that still looks similar (though I find it amusing that Ask HN: So what's new in the world of A.I.? https://news.ycombinator.com/item?id=1754134 is on the front page "... My prediction (heh pun intended) is that you see enormous changes in the field when processing by GPU's becomes much more available. There are some algorithms that are simply difficult to research because labs don't have access to fast enough machines. ...")
There's certainly been some broification and the various reddit exoduses have been shifting the average user a bit.
I do believe you've got your top color set to ff007f rather than ff6600 if you're forgetting what the site looked like then.
I've certainly thrown together more software and automations over the last year than I have in the other ~15 years since I started programming.
It's never been so fun.