https://www.inc.com/jason-aten/metas-new-muse-ai-agent-read-...
The Messages database is protected by macOS TCC. If Aten were correct, there would exist a macOS zero day vulnerability.
The vastly more likely explanation is that Aten mindlessly gave Full Disk Access to Muse. And that appears to be Apple's assumption, based on Apple's newly published developer note.
Meta's claim that Muse would not read your messages without explicit permission was meaningless.
But it was true and you still haven't refuted that Aten mindless clicked through and allowed Muse full disk access and/or the messages connector setting in the Muse app.
> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.
> > Some developers are using Full Disk Access in ways that could put users at risk
In other words, Muse did have Full Disk Access. Jason Aten did grant Full Disk Access to Muse, despite his claims otherwise.
If Aten did not grant Full Disk Access to Muse, then why would Apple even be talking about Full Disk Access?
The point is that Aten apparently granted Full Disk Access absent-mindedly, so absent-mindedly that he won't even admit that he did it. This is why Apple is making changes to Full Disk Access to make it more obvious what's happening.
Perhaps you should do some reading on the matter?
> Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges. One is full-disk access, a macOS system-level permission. The other is to enable a Messages connector setting in Muse.
“The Messages integration in the Muse Mac app is opt in,” Singleton said. “Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.”
Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame.
https://arstechnica.com/security/2026/10/apple-changes-full-...
Meta has a long history of not respecting boundaries once something is technically possible.
Perhaps you should: https://lapcatsoftware.com/articles/2026/10/2.html
> Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame.
Indeed, and it looks like Aten absent-mindedly did all of this!
> Meta has a long history of not respecting boundaries once something is technically possible.
It's not technically possible for Muse to read the Messages db without Full Disk Access. Aten denies having given FDA to Muse. Thus, Aten is simply wrong, misremembering or something. And if he misremembers about FDA, he likely also misremembers about granting app-level permissions to Muse.
Again, literally nobody has reproduced Aten's experience. Show me one other person.
In fairness, Aten behaved just like many other users would, mindlessly granting permissions that an app requests. That's certainly a problem. Unfortunately, Aten stubbornly refuses to admit this, instead confusing the problem by suggesting technical impossibilities. Aten doesn't want to take any responsibility for his own actions.
Since Aten has clearly said he did not grant Muse the permission to read his messages (inside Muse), I'm not accepting your version of the events.
In this case, Meta explicitly promises that Muse will not read your messages even after you grant it disk permissions.
There's no reason to doubt this claim. The only person in the world who has claimed that Muse disrespects its own internal setting is the same person who claimed that he didn't grant Full Disk Access to Muse.
Ironically, Aten's own screenshot appears to show that he toggled the internal setting from "Off" to "Read only". In my own testing, it's "Off" by default, and the only way to change the internal setting is to enable Full Disk Access first.
Thus, the likeliest scenario is that Aten unthinkingly granted Full Disk Access to Muse, granted the Messages app permission, then had a change of heart, disabled Full Disk Access, and then forgot what he had done. Later, when he noticed that Muse had some of his messages, he went back and checked, and saw the FDA was disabled, forgetting that he had toggled it on and off.
Moreover, my "opinionated" blog post also included a screen recording of the Muse first run experience, so everyone can see for themselves what it's like. And if you don't trust my screen recording, then you can perform the exact same experiment yourself. Nothing I did was unique.
When an actor has shown it self to be this malicious, we should be allowed to assume all the worst thing about it. And we should at the very least resist and complaint whenever it shows it self able to cause even more harm to humanity.
Trump is stripping the White House for copper and selling it!! Well, actually he’s not, but since we know he’s corrupt, isn’t it safe to just assume he might also be doing this other bad thing?
If your decision is to avoid Muse due to Meta’s poor track record, that’s absolutely your prerogative (and a reasonable one!). But specific claims must be evaluated based on their evidence. This article fails that. There’s no story here.
Off course there is space between the worst and the best case. But given Meta’s history it is safest (and the most rational) to assume the worst.
Why though? The comment you're replying to is explaining how the accusations of poor privacy are nonsense and you've just replied "I disagree because they have poor privacy".
I mean I'm not going to hand over any data to Facebook if I can help it but it doesn't seem like there are any specific issues here.