Apple and a Hacker's Future

(stratechery.com)

45 points | by maguay 1 hour ago

10 comments

  • GeekyBear 32 minutes ago
    The full disk access permission is something you give to backup software.

    If you give full-disk access to Meta software running on your main computer, Meta is not going to respect your privacy.

    > Friday’s [full-disk access] announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.

    https://arstechnica.com/security/2026/10/apple-changes-full-...

    If you want to know why Apple is suddenly not happy about the way the full-disk access permission is being abused, look no further.

  • mcepl 1 minute ago
    If the main to run Apple computers is their hardware, why not to run it with Linux. Aside from better filesystems (Theo tests were shocking to me, how bad FS you guys have), you would get better compartmenalization and I believe better security. What's missing?
  • intrasight 49 minutes ago
    > The question, however, is whether what they are designed for is the future I am barreling towards, one where agentic abstraction both renders traditional interfaces relics

    I think he was burying the lede but glad he finally posed the question.

    I think it's a bigger risk factor for Apple than is generally assumed. If consumers get used to the freedom but endemic spying of products like Muse, Apple may have a hard time sticking to their privacy and security mandate.

  • Someone 25 minutes ago
    > This system is annoying but manageable on your primary Mac; it’s a disaster on a headless Mac running agents, for two reasons. First, agents write new programs all of the time, and in my case, those programs need access to devices on my network (SMB shares, for example, trigger a TCC warning). What I need is a permission layer for agents, not the programs they create; TCC is operating at the wrong level of abstraction.

    Doesn’t that already exist? If I give Terminal.app access to the entire disk, CLI tools started by the app (indirectly: Terminal.app runs a shell, and the shell runs the tools) have that access, too.

    And I don’t think that’s because Apple gives Terminal.app preferential access. Google tells me that works for iTerm, too.

    Or would it mean agents need to do some special thing to launch tools?

  • jeremyjh 48 minutes ago
    Couldn’t you give agents access to the screen sharing software to see the TCC prompts?
  • Vvector 26 minutes ago
    The vuln required "port 5900 was accessible from the Internet"

    Why would anyone open up random ports (or even all ports) to the internet?

    • DuncanCoffee 11 minutes ago
      it's a vnc port, it'd also require the router to have it opened. Reading the article I think the user opened it themselves. It does get opened automagically on the mac side when screen sharing is turned on.

      > The problem is that for my particular use case — a headless, always-on Mac Mini that I primarily access from other computers and my phone through the ChatGPT and Claude apps — macOS is incredibly hostile

      > As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting.

      > Obviously I should have — and will be — using a VPN going forward (the foundation of my entire approach to security is Tailscale); what I will note, however, is that TCC basically leaves me no choice but to have screen sharing enabled if I want to actually use my Mac Mini in the way I want to use it. I use screen-sharing constantly — including from my phone — and almost every time it’s to click “OK” on a stupid prompt that I’ve long since stopped taking seriously.

    • LoganDark 20 minutes ago
      I opened my SSH port to the internet back in the day because I could tunnel my internet through it to avoid network blocks. (sshuttle my beloved)
  • hombre_fatal 1 hour ago
    > Apple doesn’t seem too happy about agents

    I don't get this reaction to Apple making Full Disk Access more explicit. Whether they're "happy" or "sad" about agents doesn't seem responsive at all.

    Kinda seems like whenever you spend 10 seconds thinking about the average user, social media gets angry. The quoted justification by Apple seems reasonable.

    • askonomm 59 minutes ago
      Being happy or not has nothing to do with it, in my understanding as well. Removing full system access from non-deterministic tools prone to prompt injections seems like the most obvious thing to do. There's a reason I run all my projects in rootless isolated containers these days. There has never really been "trust" in software, but the lack of trust is a lot more obvious these days.
  • nixosbestos 26 minutes ago
    I feel like this article was all over the place. Also, this person was really running a macOS box raw on the Internet, no firewall, nothing? :/
    • GeekyBear 20 minutes ago
      He also had that computer configured to download system updates automatically, but not to install them.

      On the plus side, at least he didn't run the AI agent on the computer with all of his personal data.

    • mold_aid 5 minutes ago
      "Thank god the causes told me about the effects!"
  • mertbio 27 minutes ago
    [dead]
  • soltanov 58 minutes ago
    It is not about emotion; it is about platform control. Apple limits background autonomy under the label of security, while ensuring only their first-party system frameworks get unfettered ambient access. Standard playbook.
    • detourdog 34 minutes ago
      This seems like sysadmin 101 to me. Controlling local access and who to trust was always the way. Platform vendors always enjoyed this privilege. Overriding the platform vendors software tools was done with variations kept in /usr/local/ and symlinked to over ride the vendors choices.
      • BirAdam 14 minutes ago
        Well, you don't even really need symlinks. You can just adjust the order of locations in $PATH
    • rimliu 46 minutes ago
      maybe there is a reason they are called... system frameworks?