Rendered at 11:47:32 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
GeekyBear 1 days ago [-]
The full disk access permission is something you give to backup software.
If you give full-disk access to Meta software running on your main computer, Meta is not going to respect your privacy.
> Friday’s [full-disk access] announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.
If you want to know why Apple is suddenly not happy about the way the full-disk access permission is being abused, look no further.
drdexebtjl 10 hours ago [-]
The problem is that Apple only enforces TCC permissions on the root of the process tree.
So, for example, if your backup software is a CLI, you have to give Full Disk Access permissions to your Terminal, not the backup software. And subsequently every other process you start from your terminal will also have Full Disk Access.
Enforcing it per executable down the process hierarchy isn't helpful either: you'll eventually grant it to an interpreter (zsh, python3) and create a hole.
TCC's security model is fundamentally wrong.
Unix solved this decades ago: agents should be their own user. What's missing is the tooling to make disposable users practical, and perhaps cross-platform filesystem ACLs.
mike_hearn 3 hours ago [-]
There actually is a private API that lets you disclaim responsibility for a subprocess: responsibility_spawnattrs_setdisclaim. It's used by things like LLDB and Launch Services, but a few other programs like Chrome use it too.
There's a program that lets you use it from the terminal here:
I think Apple don't expose it as public API because TCC is meant to map user permission prompts to things the user understands logically as applications, which means things they started. If apps can have the user be prompted to grant permissions to sub-components of themselves it can get very confusing quite rapidly.
The supported way to do this is therefore to just make a proper Mac app with its own bundle ID, sign it, and ask Launch Services to start it up - potentially via XPC. It will get its own TCC permissions set along with its own icon and so on. You can, if necessary, embed this app inside another one, although of course the thing the user sees as the app being given permission will be the identity of the embedded app so that reintroduces the potential for confusion.
itsmemyan 2 hours ago [-]
Shipping a native Mac app here (a Rust code editor), and this matches what I see daily. My app spawns language servers, terminals, and debug adapters as subprocesses — TCC treats the whole tree as one principal, so one signed bundle means one permission set. Convenient, until you think about it: any of those subprocess binaries, if compromised, runs with my app's TCC identity. Signing and notarization buy you the bundle identity but don't solve the confused-deputy problem for the tools you shell out to. XPC services with their own bundle IDs are the cleaner answer, but that's a lot of machinery for a small team to build and maintain.
mike_hearn 2 hours ago [-]
If you want to sandbox something like a language server then Seatbelt does exist, but using XPC helpers is definitely the supported approach.
I don't know if the amount of machinery is such a big deal now, an LLM can produce the needed code quite quickly. Those sub-processes shouldn't be disclaimed anyway because they'd end up without a proper code signing/bundle identity and get weird permission restrictions that can't be elevated. Claude App makes this mistake, IIRC.
mycall 9 hours ago [-]
Apple containers help here in some regard, no?
parasubvert 7 hours ago [-]
Docker has an interesting approach lately with their sandboxes which are firewalled, proxied, and file system restricted microVMs (you can bind mount outside) with a docker daemon inside of it.
noncoml 8 hours ago [-]
> Unix solved this decades ago: agents should be their own user
That’s a hand waving if I’ve ever seen one.
How is that going to help?
If the Agent gets launched with is own user is will not have access to ANY of the files that are only read by the user.
drdexebtjl 7 hours ago [-]
Yes, and the user can explicitly grant access to the agent users using filesystem ACLs. Too many agents with the same permissions? Make a group, give permissions to the group, and add your agents to the group.
Of course, as a user, you need some way to easily modify ACLs to do this, but that’s just a front end concern on top of a solid security model that every OS supports.
throw0101a 23 hours ago [-]
> Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.
This brought to mind Neal Stephenson's essay "Unix - The Hole Hawg of Operating Systems" from back in the day (1999):
> I myself used a Hole Hawg to drill many holes through studs, which it did as a blender chops cabbage. I also used it to cut a few six-inch-diameter holes through an old lath-and-plaster ceiling. I chucked in a new hole saw, went up to the second story, reached down between the newly installed floor joists, and began to cut through the first-floor ceiling below. Where my homeowner's drill had labored and whined to spin the huge bit around, and had stalled at the slightest obstruction, the Hole Hawg rotated with the stupid consistency of a spinning planet. When the hole saw seized up, the Hole Hawg spun itself and me around, and crushed one of my hands between the steel pipe handle and a joist, producing a few lacerations, each surrounded by a wide corona of deeply bruised flesh. It also bent the hole saw itself, though not so badly that I couldn't use it. After a few such run-ins, when I got ready to use the Hole Hawg my heart actually began to pound with atavistic terror.
> But I never blamed the Hole Hawg; I blamed myself. The Hole Hawg is dangerous because it does exactly what you tell it to. It is not bound by the physical limitations that are inherent in a cheap drill, and neither is it limited by safety interlocks that might be built into a homeowner's product by a liability-conscious manufacturer. The danger lies not in the machine itself but in the user's failure to envision the full consequences of the instructions he gives to it.
Which is why I wish Apple would support Linux out of the box on their M-series hardware.
I do not want to hand my child a Hole Hog, I want to hand them a residential power drill with the torque settings locked to a safe level. I need a fucking Hole Hog for the work I do.
There is a time and a place for every tool, and sometimes the hands holding the tool influence this more than an expert would care to admit, who instead say things like “you’re doing it wrong!” to admonish users who didn’t even know there was a difference between the tool they held and the one they needed.
GeekyBear 22 hours ago [-]
> I do not want to hand my child a Hole Hog, I want to hand them a residential power drill with the torque settings locked to a safe level.
rm -rf / would like a word.
natpalmer1776 22 hours ago [-]
You forgot sudo and an admin entitled user’s password.
someonebaggy 22 hours ago [-]
If it's really a Hole Hawg, you run as root, or at least passwordless sudo.
natpalmer1776 22 hours ago [-]
I thought they were calling the residential drill a hole hawg.
To your point though, not everything in Mac can be solved via root user privilege. SIP is annoying to toggle, the main issue being discussed also demonstrates why Mac OS is not the proverbial Hole Hawg as well.
throw0101a 22 hours ago [-]
> SIP is annoying to toggle, the main issue being discussed also demonstrates why Mac OS is not the proverbial Hole Hawg as well.
macOS in its default configuration may not be the HH, but if SIP removes those limitations it is still available.
As someone who (a) does some tech support for family, but also (b) uses a MacBook for sysadmining Linux servers, but kind of happy with the current balance. I don't think I've run into SIP limitations, so perhaps I'm not an 'advanced' enough user of macOS (MacPorts generally works for the 'extras' I need on top of base macOS).
21 hours ago [-]
natpalmer1776 21 hours ago [-]
Well shit, I went to verify my litany of QoL complaints that couldn’t be resolved via disabling SIP and turns out there has since been a solution for for the main one (Gatekeeper) and the remaining issues boil down to personal particularities.
So I rescind “needing” a hole hawg and correct it to “strongly prefer or desire” a hole hawg. Mainly because I shouldn’t have to rip apart a magic keyboard to embed a touch ID module into a 3D printed case for a standalone fingerprint reader module.
detourdog 14 hours ago [-]
What about an off the shelf fingerprint reader.
natpalmer1776 11 hours ago [-]
Doesn’t work with touch ID.
microtonal 6 hours ago [-]
macOS supports smart cards for unlock. And the YubiKey Bio has fingerprint authentication. So I think you can do your own kinda Touch ID with the multiprotocol YubiKey Bio version.
someonebaggy 19 hours ago [-]
What's stopping you from reverse engineering that module?
saagarjha 9 hours ago [-]
Yeah sure dude they’re going to do nation-state level silicon attacks against the key material in that sensor
natpalmer1776 18 hours ago [-]
Same thing that’s stopping me from building my own computer chips using a home lithography setup and clean room.
swader999 21 hours ago [-]
That's a drilling rig
someguyiguess 21 hours ago [-]
I'd feel about 100x safer with my child using MacOS than any Linux distro. Linux comes with much more footgun built in than any commercial OS.
curt15 53 minutes ago [-]
If it's their own computer, what better way for them to learn than by making mistakes? And if it's a shared computer, Linux container tools (e.g. https://github.com/containers/toolbox) would let them "sudo rm -rf /" in their own environment without jeopardizing the base system or other users.
PorciiVorbesc 12 hours ago [-]
How so? In what way would some immutable distro with GNOME be less safe than MacOS?
natpalmer1776 21 hours ago [-]
Yeah, that’s why you hand them the residential drill (Mac)
gruez 19 hours ago [-]
Where the analogy fails is that the relationship between doing the thing (ie. using a Hole Hawg or granting agents access to your data) and the consequences (ie. ruining your house or getting pwned) is far less obvious in the case of AI, especially if it approximately works most of the time and the failures are seemingly random.
montagg 19 hours ago [-]
And the folks productizing this are actively working against noticing its power by making it cutesy. It's a good product choice IFF it matches the capabilities, and it absolutely positively does not.
roughly 13 hours ago [-]
If you don’t understand the consequences, the Hole Hawg is not for you, and neither is the AI.
roughly 13 hours ago [-]
Jesus, that’s a great essay. Gibson and Stephenson are seen as the twin prophets of Cyberpunk - Gibson wrote about society, Stephenson wrote about technology. That man understands the technium better than anyone else out there.
(Bruce Sterling was the weird hippie who kept feeding interesting things into the machine to see what colors they made - without him, Cyberpunk would’ve died on the vine.)
kakacik 5 minutes ago [-]
Why is anybody surprised with meta ? Seriously, you guys ignore all the news about that company and privacy for last 2 decades? Privacy for them is an obstacle to engineer around and nothing more, and this is baked to the core of their philosophy, not some rogue fringe team pursuing results at all costs for past 3 months.
There was a time I had their FB app and messenger on the phone. Then it was found out that their crappy engineering couldn't hide the fact their apps were constantly watching users and other apps on entire phone, causing >15% additional battery drain, even when they were not opened.
I've removed all of them, never needed them on phone (or at all) and can't complain at all. Don't expect privacy form meta, any, ever.
wpm 20 hours ago [-]
FDA is in fact not required for backup software nor should it be. For example, Bombich is granted the com.apple.security.files.all entitlement for Carbon Copy Cloner, because backup software needs to just work without the user chancing a miss on the TCC prompt when they first set it up only to find out the app didn't backup their photos after losing all their data.
Apple stopped adding protected file-system domains for some reason, and have only expanded TCC to entail more vague and nonsense monikers. Sandboxed apps of importance like Messages, Notes, Reminders, and so on, all just end up under the "Full Disk Access" umbrella because they all store their databases in ~/Library/Containers, and FDA is really the only thing gating access to that. Apple should just start pushing the permissions one level down into that folder. Do I want to give an agent access to my Safari history, but not my messages? Too fuckin bad! No way to slice that right now, it gets full disk access and can access anything.
kylec 21 hours ago [-]
I think that was the initial concept of what "Full Disk Access" was supposed to be, but I've run into needing to give some of my own apps full disk access for very innocuous reasons. Recently, I wanted to build a little app to give me a Time Machine on/off switch by calling "tmutil enable/disable". A single on/off command with no need to access any of my data, but its use was gated behind needing Full Disk Access. Hopefully if Apple is rethinking Full Disk Access permissions they will rethink better ways to provide these sort of permissions.
daft_pink 19 hours ago [-]
The problem I have is that when I ssh into my mac, I want to be able to control software from the command line and having a popup authorization window that just halts the software being controlled is not good for me. I'm okay with having the authorization, but they need to make it visible to ssh users when ssh'ing in.
ryanascend 16 hours ago [-]
I hit this from the headless side. I run everything on a Mac mini over SSH, and TCC prompts are invisible there too. Agents spin up new binaries that trip fresh permission prompts with no way to pre-approve them, so you either babysit screen sharing to click OK or leave screen sharing on, which is exactly the exposure that got the author here. The permission model assumes a person sitting at the keyboard, and it falls apart the moment the Mac is a server.
mochizou 9 minutes ago [-]
[flagged]
ryandrake 21 hours ago [-]
Another case of "This is why we can't have nice things." Application developers who feel entitled to accessing everything they can on the user's computer, without obtaining consent from the user. So, now we have to have these consent walls everywhere. Way to go, application developers.
jwitthuhn 11 hours ago [-]
Full disk access requires explicit consent from the user, and can only be given to an application using an obtuse workflow that is deliberately more complicated than just clicking accept.
Apple considers a user deliberately delegating access to their data to any program not controlled by Apple to be a serious problem that must be corrected.
Application developers are not making the user experience worse, Apple is.
x0x0 15 hours ago [-]
> Way to go, application developers.
I really dislike this point of view.
1 - we're all going to suffer because meta are scum. It's not "all application developers", it's "exactly who you assumed it would be", and also too, "exactly the same scum who've spent the last 10 years working around privacy controls any possible way they can and deliberately obfuscating the choices people make around their privacy." The people who made pervert glasses and did covert web-to-app tracking by opening local ports [1] and bought sketchy spyware to track everything you did and scurried away from the light the second someone asked about it [2], [3]. And on and on and on.
Spotify has long asked for it and... they use it to copy my local mp3s onto my phone so I can listen to them away from my computer. It's awesome.
This doesn't mean that Apple isn't champing at the bit to use Meta as an excuse to screw all software developers. If Apple cared about their users, they'd do something like revoke Meta's software keys and leave responsible developers alone. Alas, Apple will obviously exploit this too :(
Meta maybe worse wrt privacy.
.. but they are NOT alone in disrespect of user consent. Microsoft have the UAC dialog before Mac. There are tons of blogs from the old msdn devblog on what app developer have been doing to work around them.
> ...the uses of Full Disk Access go well beyond the category of backup apps, and it is worrisome to see Apple give it such a limited frame. I have given that permission to disk management utilities, Sketch, Terminal, and other apps I do not want to be throwing permissions requests as I move around my drives. Is Apple suggesting this capability could be limited in the future to backup applications alone? I do not like that.
If Full Disk Access were, in future, to be something that I could not grant to (for instance) the Terminal, because it is not a backup app, that would severely limit my ability to do work on a Mac, both as hobbyist and as computer professional.
I agree that the agent situation is a fairly serious concern; I just don't want to see Apple throw the baby out with the proverbial bathwater.
GeekyBear 24 hours ago [-]
From Apple's statement, there doesn't seem to be any plan to remove the full disk access permission.
They want unsophisticated users to understand that they would be granting unlimited access to all of their personal data if they grant software that permission.
> We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.
andreareina 23 hours ago [-]
... for now. Anytime I download an unsigned binary I need to go through this song and dance of figuring out again what command I need to run to strip the quarantine tag because none of the UIs that are supposed to allow me to trust this binary work.
GeekyBear 23 hours ago [-]
The company making laptops locked to an app store is Google.
Microsoft attempted to lock Windows to their app store twice, with both Windows RT and Windows S, but the market rejected both of those attempts.
Apple hasn't done that, despite claims that it's coming any day now for at least a decade.
I hope what they offer is the ability to set more granular rules, like allowing my Borg backup script to access the whole disk, but not any random Git precommit hook (for example). Given that practically all of the existing restrictive security features on macOS (for example, SIP) can be disabled, I feel confident that Apple will make hobbyist and professional use cases still possible, just requiring some extra scary messages. I’m ok with that trade off.
aprilthird2021 6 hours ago [-]
Watch them advertise that Muse will soon be able to do phone backups for you to justify this permission usage
parasubvert 7 hours ago [-]
It strikes me that heavy AI agent users have an extraordinarily high risk tolerance for identity theft, privacy breaches and data loss vs. perceived productivity. Far beyond what any responsible medium to large size company would ever tolerate.
Overall the limits to AI productivity can be summarized in one word: discipline. If you're undisciplined in your security, your design constraints, your automated test coverage, your separation of the deterministic and indeterministic, you will be quite productive ... for a time. Until quite suddenly, you aren't, possibly due to catastrophe.
Similar to the early era of computers on the Internet, with lax security, we have a window where we can get away with this, but it will close quicker than many realize. Some things do seem to need to be learned the hard way.
Apple is trying to do the bare minimum here - not even introducing a new security model - and people are already freaking out. But a disciplined agent sandbox model is exactly what we need to get to.
itake 5 hours ago [-]
According to haveibeenpwnd, the email address I've used since gmail was invite-only is in at least 39 data breaches.
In 2019, my SSN was used to purchase 4 iPhones, open 2 credit cards, and used to buy perfume in another state.
In 2026, almost mainstream messaging app monitors your private messages (yes, even Whatsapp now [0]).
Society decided that to be in it, you must give up your privacy along time ago.
What is your point with this, are you saying it isn't a problem? It sounds like it ruined your life almost!
aprilthird2021 6 hours ago [-]
It's an exciting time to be in security...or offense
Schlagbohrer 2 hours ago [-]
And a completely insomniac time to be in defense.
mixdup 22 hours ago [-]
I would argue that someone who would open a remote access port to the internet with no filtering is exactly the kind of person that Apple needs to protect from themselves
Yeah, it was neat that Claude found this, but Thompson showed an almost criminal lack of security awareness by having VNC/ARD open to the internet
terminalbraid 21 hours ago [-]
Why does Apple need to protect anyone from themselves? This is the problem with commercial vendors creeping in computing freedom. It is exactly this mentality that people shouldn't be the ones responsible for the hardware and software they own and operate which erodes that freedom.
mixdup 21 hours ago [-]
Because people will shoot themselves in the foot if you give them a shotgun. A big part of why the Mac as a platform blossomed in the late 2000s forward was because it was much less likely you'd get hacked by clicking the wrong link or just opening an email than it was on a Windows machine (among other reasons)
And, all of that said, Apple hasn't said anything about not letting people have full access to their disks. Just that you're going to have to be very intentional, click through a very scary warning, to do so. Happy to do that to prevent my mom or dad from accidentally opening up their machine to every hacker in Belarus or worse yet Facebook
mrheosuper 8 hours ago [-]
> you'd get hacked by clicking the wrong link or just opening an email than it was on a Windows machine
Is it because of most of virus/malware target Windows OS due to its sheer size, or because MacOS security system is more superior than Windows ?
I also less likely to get hack if i open url link on templeOS
bcjdjsndon 1 hours ago [-]
> I also less likely to get hack if i open url link on templeOS
God doesn't believe in the networking stack so you're good
bcjdjsndon 1 hours ago [-]
> Because people will shoot themselves in the foot if you give them a shotgun.
Then take away cars as someone could crash and kill themselves with them. What kind of babyified logic is that?
alt227 55 minutes ago [-]
People are licensed and tested as capable to be able to drive cars. They are not to own mobile devices.
terminalbraid 20 hours ago [-]
> Because people will shoot themselves in the foot if you give them a shotgun.
Correct. This is why gun safety is taught. Try and bring up banning shotguns in the US and see what happens.
alt227 54 minutes ago [-]
Exactly. People are trained and licensed. If we trained people how to use mobile devices safely before allowing them one then none of this would be an issue, but we dont.
mixdup 20 hours ago [-]
I don't think "let's just stick with how things work in the actual firearms industry" is what I was going for or a sane position to take on just about anything
simondotau 10 hours ago [-]
Insecure computers are more dangerous than firearms.
Rohansi 11 hours ago [-]
It is a good example of ordinary people passionately defending their freedom. You don't need to agree with what they are fighting for to respect that. Computing freedom is dwindling away and most people don't seem to care or are actively encouraging it.
mixdup 9 hours ago [-]
a) I don't respect second amendment nutjobs. We don't have unlimited unfettered free speech rights, why are firearms special in that regard that they can't be regulated like my mouth can be?
b) there are plenty of options for completely open computing platforms. Apple has every right to build the platform they want to build, and you as a consumer have every right to go buy a Framework laptop and install Debian on it instead if you don't like it
doug_durham 17 hours ago [-]
Because people have lives to get on with. People need to use computers. People have better things to do with their time than spend weekends learning about the details of internet security. It is an elitist position to say that protections erode freedom. In my ICE car the engineers have specified the grade of oil that I need to use. Certainly if I knew the details of the engine, the weather it will be used in, and other factors I could choose alternate oil grades. Are my freedoms being eroded by grade of oil being mandated?
bunderbunder 13 hours ago [-]
The thing is, Apple customers typically don't want that kind of power and responsibility. They view the limitations as a liberating force.
When my mother in law switched from (XP-era) Windows to OS X, she expressed a profound sense of relief that she didn't have to worry so much about accidentally breaking it. She has absolutely no desire to learn computers well enough to understand a system that gives her more control. In her experience it never enabled her to do anything particularly relevant to her own interests, and mostly accomplished the complete opposite by leaving her slightly afraid to do anything. My own efforts to try and explain her computer problems and how to avoid them in the future did not help; they only served to communicate to her that the computer was indeed complicated and scary.
simondotau 10 hours ago [-]
> They view the limitations as a liberating force.
Limitations ARE a liberating force. No limitations is having skyscrapers with doors opening to outside, because people should have the choice to step out among the birds and the clouds.
jarjoura 11 hours ago [-]
Isn't this the same argument that opponents took in the early 2010s when iPhone photos were much more accessible, and celebrity nudes were constantly being harvested? I am not saying Apple should go nuclear on the mac and lock it down like iPad OS and I don't think it's headed in that direction either. As long as people can disable sandboxing and YOLO it, then this is definitely a step in the right direction.
Nevermark 8 hours ago [-]
> I am not saying Apple should go nuclear on the mac and lock it down like iPad OS and I don't think it's headed in that direction either.
The Vision Pro could (in terms of hardware) be the Mac successor. Just the virtual Mac screen feature alone is great ... but the rest is "It's an iPad! But in 3D!" Ugh.
Don't underestimate the power of Apple's dream of locking everything down.
Apple's priorities (as Daring Fireball notes), are Apple, customers, something, something, something, ...., developers and suppliers.
I think Tim Cook missed his chance to leave a Steve Jobs like mark on Apple when he championed a next generation graphical interface on next generation hardware, but only for toy apps and media.
And for those that think "what could 3D/spacial really do for interfaces?", don't think exciting, just think about the simple perks that grow into usefulness, like your entire environment being (Mac-level capable) screens as you work. Consider how much of the real world and its activities, problems and structure are in 3D. And how people adapted to 2D graphical interfaces not because "wow!", but because many mundane things, like editing a table and writing a letter, got easier. And a lot of new mundane things became possible/practical.
That won't happen on a Vision "Pro" limited to being a toy app platform, media kiosk, and Apple iCloud services recurring revenue store front.
The software limitations are why it isn't worth the price, not the hardware.
The negativity here climbs up out of my deep love for my Vision Pro.
sib 12 hours ago [-]
Unfortunately, it's often the case that the blast radius of the footgun (ouch, mixed weaponry metaphor) is bigger than the person who's holding the gun, and other users' security may be compromised...
GeekyBear 20 hours ago [-]
For the exact same reason Microsoft created Windows File Protection.
If you don't like System Integrity Protection on your Mac, you can turn it off and YOLO to your heart's content.
20 hours ago [-]
fsflover 6 hours ago [-]
> is exactly the kind of person that Apple needs to protect from themselves
"If you are protected by a steel door, but you don't have the key, you are not safe -- you are imprisoned."
w10-1 18 hours ago [-]
To read Ben is to glimpse the AI divide: he's honestly and emphatically choosing based on whether it makes it easier for him to use his AI agents, even if that means ditching Apple for the Zuckerberg's melee. It's that important to his personal productivity. AI-native product streams will separate from what came before, as will the people who master them.
That said, I disagree on Apple: while the UI can be perfect, it has always imperfectly been trying to do the right thing technically in concert with developers and users, which puts it in the position of imposing constraints that developers and users can relax to varying degrees: wearable and home devices (not at all), iOS (somewhat), macOS (mostly).
wrt a hacker's future: I'm still traumatized both by decades of windows reboots and virus scanning, and by decades of squeezing into Linux (just don't sleep, avoid these displays...). I'm glad Apple stuff mostly just works and ordinary people still have access to unlocked, general-purpose computers, but that might not last. Cheap AI coding might remove any financial incentive to support users programming on their own, and we'd be left with locked devices as consumers or work-only access to programmable computers (at least for the latest hardware of note). If a 40% premium for mac hardware is the price we pay for continued access, so be it.
binkHN 14 hours ago [-]
For all of Linux's warts, it's still better than the commercial crap coming from Microsoft and Apple that focuses on 99% of consumers. For many of us at HN, Linux is a blessing and it's only getting better.
17 hours ago [-]
intrasight 1 days ago [-]
> The question, however, is whether what they are designed for is the future I am barreling towards, one where agentic abstraction both renders traditional interfaces relics
I think he was burying the lede but glad he finally posed the question.
I think it's a bigger risk factor for Apple than is generally assumed. If consumers get used to the freedom but endemic spying of products like Muse, Apple may have a hard time sticking to their privacy and security mandate.
GeekyBear 1 days ago [-]
From Apple's statement, they want to be sure users understand that they are handing Meta access to all of their personal data if they grant Muse (or other AI agents) the full-disk access permission.
> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.
As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.
rickdeckard 23 hours ago [-]
> "We are committed to ensuring users clearly understand these risks before granting such access"
This "you are entering the wilderness, I will not be able to protect you anymore if you proceed" framing reminds me of the alternative AppStore case, where Apple (and Google) applied scare-tactics in the UI to discourage users from giving permissions to alternative stores.
brigade 23 hours ago [-]
Or the scary warnings today against disabling SIP, repeated by forum users anywhere it’s discussed.
Which happens to be the only way to disable the TCC permission dialogs OP complains about. Guess the warnings worked well enough that no one knows that anymore.
alt227 21 hours ago [-]
I know SIP as a telephony protocol, what are you referring to here?
GeekyBear 21 hours ago [-]
> System Integrity Protection is a security technology designed to help prevent potentially malicious software from modifying protected files and folders on your Mac. System Integrity Protection restricts the root user account and limits the actions that the root user can perform on protected parts of the Mac operating system.
Before System Integrity Protection, the root user had no permission restrictions, so it could access any system folder or app on your Mac. Software obtained root-level access when you entered your administrator name and password to install the software. That allowed the software to modify or overwrite any system file
Thank you. I see its an Apple thing which is why I guess I havent heard of it.
GeekyBear 20 hours ago [-]
Windows File Protection is in the same vein.
alt227 21 hours ago [-]
> scare-tactics in the UI
This is the only weapon they have when governments have forced them to open their doors to the scary world outside.
intrasight 20 hours ago [-]
> the risks associated with this level of access will grow substantially.
This is not going to end well for everyone involved - especially for the user.
But that's the case on all platforms with any LLM agent being given full access.
There will be an adjustment period where users will learn of the risks - hopefully without much harm occurring.
j16sdiz 23 hours ago [-]
There are no much user can do once they "clearly understand these risk".
The risk of having human assistant can be mitigated by background check, insurance and legal recourse. We have none of these for AI agents.
rickdeckard 23 hours ago [-]
It's the constant risk for Apple that its customer base voluntarily invites any company to interact with them directly, because it's Apple's prerogative to broker the access to its users.
So as always, for the sake of "privacy" Apple needs to take action to protect the users from "themselves", and make it undesirable to grant others the same access Apple has...
coastalpuma 23 hours ago [-]
In that case, it will be their own dang fault. Modern MacOS is a mess of update nags, unwanted notifications, and permissions prompts. We want sandboxing and security patches but the UX around it is abominable.
jppope 21 hours ago [-]
I think the observation Ben is making, is that Apple no longer has a grasp on the future purchases in the market. He makes it explicit with this quote: "I can, for the first time, envision a future where I don’t buy Apple by default." It used to be a given that we would refresh every 3-4 years, thats probably no longer guaranteed.
Observationally, I would argue we've all been expecting this for this for a long time. Every year Apple has raised the price of allegiance and every year we've paid it, waiting for products like the framework laptop or certain linux distros to become mature. We're still not there yet, but how much longer until there is real competition in the personal computer market?
bel8 14 hours ago [-]
My next laptop might be a Snapdragon Elite X2 if they get good Linux support. It's probably going to be comparable to macs in battery and CPU power.
If it doesn't support Linux well, I'm not buying it. It's that simple.
migueloller 11 hours ago [-]
Omarchy has been fun to play with and perhaps is a contender against macOS for some developers.
nerdjon 23 hours ago [-]
What I find most surprising, is that I don't think we got any sort of timeline from Apple on this change and its very vague (which just fuels articles like this).
So did this initiative within Apple just start and we could be looking at this change coming in Mac 28?
I don't remember another time of an announcement like this from Apple of a major change with so little information, though I could be wrong or hint of when.
Regarding the concern, while I do hope that there is still a way to grant actual full disk access to some applications. Even Apple called out a non controversial need for something like that, backup software. I can also think of security scanning software, a lot of businesses have those deployed to corporate Mac's. I do also think that better controls around it, especially in this age of vibe coded apps that never actually think about security or actively hostile companies like meta.
Someone 1 days ago [-]
> This system is annoying but manageable on your primary Mac; it’s a disaster on a headless Mac running agents, for two reasons. First, agents write new programs all of the time, and in my case, those programs need access to devices on my network (SMB shares, for example, trigger a TCC warning). What I need is a permission layer for agents, not the programs they create; TCC is operating at the wrong level of abstraction.
Doesn’t that already exist? If I give Terminal.app access to the entire disk, CLI tools started by the app (indirectly: Terminal.app runs a shell, and the shell runs the tools) have that access, too.
And I don’t think that’s because Apple gives Terminal.app preferential access. Google tells me that works for iTerm, too.
Or would it mean agents need to do some special thing to launch tools?
lenkite 1 days ago [-]
I think some standards org needs to define comprehensive agent permissions model first before the OS raises the abstraction to agent level authorization.
TeMPOraL 24 hours ago [-]
Might be that you'll need LLMs to define the model, as LLMs will immediately drive a truck through any hole the standard left in by accident. They're really good at this.
reenorap 21 hours ago [-]
Did the author have his Mac exposed to the internet and not behind a firewall? How did his screen sharing port 5900 get accessed if he was behind a physical firewall/home router?
__david__ 20 hours ago [-]
He port forwarded 5900 to his Mac.
isodev 3 hours ago [-]
(about the macOS setting to only allow security updates)
> this setting does not in fact apply to most security updates. CVE fixes almost always arrive in point releases; in fact, the most recent point release was about fixing this bug
So yes, Apple is very bad at security, borderline malicious even.
Vvector 1 days ago [-]
The vuln required "port 5900 was accessible from the Internet"
Why would anyone open up random ports (or even all ports) to the internet?
DuncanCoffee 1 days ago [-]
it's a vnc port, it'd also require the router to have it opened. Reading the article I think the user opened it themselves.
It does get opened automagically on the mac side when screen sharing is turned on.
> The problem is that for my particular use case — a headless, always-on Mac Mini that I primarily access from other computers and my phone through the ChatGPT and Claude apps — macOS is incredibly hostile
> As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting.
> Obviously I should have — and will be — using a VPN going forward (the foundation of my entire approach to security is Tailscale); what I will note, however, is that TCC basically leaves me no choice but to have screen sharing enabled if I want to actually use my Mac Mini in the way I want to use it. I use screen-sharing constantly — including from my phone — and almost every time it’s to click “OK” on a stupid prompt that I’ve long since stopped taking seriously.
fg137 23 hours ago [-]
> Obviously I should have — and will be — using a VPN going forward
That's my takeaway from the article. I have trouble understanding how the author managed to extrapolate all these things about Apple from an obvious oversight on their part. I would never write a 3,000-word article about how bad someone else is because of an issue I caused for myself.
Software WILL have bugs and vulnerabilities, regardless of whether it's an OS or user application, whether it's from Apple or another company, or the update frequency/mechanism. If you can't even follow the most basic security practice on your part, you simply don't have any authority to discuss security otherwise.
user43928 19 hours ago [-]
Disagree.
Apple's remote access feature, that you would make remotely accessible for obvious reasons, apparently had a critical authentication bug.
Apple did not ship a security patch for this, allowing the vulnerability to be exploited a week later despite "automatically install security updates" being on.
Yes, OP could have prevented this by putting an additional VPN authentication layer in front of the Mac's built-in remote access.
That doesn't excuse the mistakes on Apple's part.
fg137 18 hours ago [-]
> That doesn't excuse the mistakes on Apple's part.
Let's first establish that Apple definitely has a stake in this.
How long they can come up with a fix and then distribute them, that's a question. You can't expect any company to fix a vulnerability within 5min. Whether one week is too long or their delivery mechanism is good, I can't tell, and I don't think there is a standard in the entire industry.
That doesn't mean it's useful to write an article about "I didn't do my part BUT you are too slow". Even if Apple somehow fixes this within an hour of the disclosure and delivers the update, with the bad configuration, the machine is still vulnerable within that window. Does that change the nature of the narrative?
dannyw 5 hours ago [-]
Yes, the timeframe does matter.
An actively and easily exploited (just a port scan), and high-impact root RCE needs faster patching than one week.
When there was a more user visible bug (2017, empty root password gives you root, CVE-2017-13872), Apple managed to remotely patch this across all supported macOS versions in about 26 hours + next macOS online, end to end, without user intervention or manual updates.
And that was a decade ago before Apple built “rapid response security updates”
user43928 18 hours ago [-]
I don't think anyone criticized the timing of the patch.
But I find it egregious that they didn't roll it out as a security update at all, which is why it was not automatically installed in OP's case, even though the fix was already available.
I mean, what else requires a hotfix via security update if not a fatal flaw in your remote access authentication leading to full root access, that is actively being exploited in the wild?
Also, it's not really on the user to gate remote access behind an additional firewall and authentication layer. This is something that just has to work securely.
If it doesn't, that's understandable, but still hardly the user's fault.
fg137 14 hours ago [-]
> what else requires a hotfix via security update if not a fatal flaw in your remote access authentication leading to full root access, that is actively being exploited in the wild?
> Also, it's not really on the user to gate remote access behind an additional firewall and authentication layer. This is something that just has to work securely.
About that, I have a bridge to sell.
mrheosuper 8 hours ago [-]
Most of "basic security practice" assume that software does not have or have very few, hard-to-discover bugs.
For Ex, the best practice is to use VPN, so you only open port for VPN, and you assume whatever VPN protocol/software does not have any bugs.
You can use tailscale so you dont have to open port, but after all, tailscale is also software.
someguyiguess 21 hours ago [-]
> I would never write a 3,000-word article about how bad someone else is because of an issue I caused for myself.
Welcome to hacker news!
otterley 21 hours ago [-]
In this case, the author literally writes blog posts for a living. This just happened to be a free article, and, well, you get what you pay for.
themechanic 21 hours ago [-]
The thing is that many of these people think they know what they are doing and do not think about security, only how awesome LLMs and AI make their experience until something bad happens.
Even though this was a valid critical bug [1], you need to enable screen sharing and allow connections to and from port 5900 on your router for a remote person to be able to exploit this.
Any security conscious person would probably be using a VPN (Wireguard or Tailscale) to prevent something like this, in the first place.
> almost every time it’s to click “OK” on a stupid prompt that I’ve long since stopped taking seriously.
The line above tells you how seriously this person takes security prompts.
I opened my SSH port to the internet back in the day because I could tunnel my internet through it to avoid network blocks. (sshuttle my beloved)
kmeisthax 9 hours ago [-]
The average HN user?
I mean, every time ISPs, NAT, or IPv6 is mentioned you have a LOT of people who are really angry they can't just netcat a random port on their friends' machine to send files to it.
jonesy827 9 hours ago [-]
>These permission prompts are a part of a macOS subsystem called Transparency, Consent, and Control (TCC), although Apple doesn’t seem to use this name anymore.
I have a PiKVM on my Mac Mini for this reason, and I bet the author would be well served by one as well.
m-s-y 22 hours ago [-]
“this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet”
We’ve known that improperly secured ports and non-firewalled machines get popped. When will people learn?
I know let’s put our power plants and water treatment out there with open ports too. Why should endusers have all the fun?
throw0101a 23 hours ago [-]
Observation:
> Hopefully Apple has in mind a solution to this situation that will still enable knowledgeable power users to confirm agreement to a sufficiently scary warning and put their Macs in a state similar to what we have today. I worry. What alleviates my worst fears is the knowledge that every technical user at Apple itself needs to use their Mac as the powerful Unix workstation OS that it is. Some of us need dangerously powerful tools. Most Mac users, however, do not — and don’t realize they’re using a dangerously powerful Unix workstation with a very friendly (literal) face.
> What alleviates my worst fears is the knowledge that every technical user at Apple itself needs to use their Mac as the powerful Unix workstation OS that it is.
What Gruber didn't realize is that Apple gives its engineers special internal tools that can bypass the restrictions we on the outside have to suffer.
I'm sure it's also the case that internal development macOS builds are compiled differently than public release builds. They basically have to be for Apple engineers to modify them during development.
eddieroger 22 hours ago [-]
> restrictions we on the outside have to suffer
We can disable SIP with a reboot to recovery and a single command. That doesn't seem like too high a bridge to cross and probably as good as any internal tool, if that isn't what they get in the first place.
lapcat 22 hours ago [-]
> We can disable SIP
But this eliminates all SIP protections, for example, as discussed in the article, preventing Meta Muse from reading your Messages db.
Muse doesn't need Full Disk Access if SIP is disabled.
brigade 21 hours ago [-]
Which system integrity protection are you worried about missing? Muse being able to exfiltrate the contents of your messages db doesn’t compromise system integrity to begin with. It being able to write arguably does, but this whole conversation was about how to grant it full disk access in the future anyway.
And OP had SIP enabled, but his system still got compromised with a remote exploit.
throw0101a 21 hours ago [-]
AIUI, SIP protects "/" but not "/Users" (macOS' $HOME base). All your private data is in $HOME, so that's why Muse could get it even with SIP.
brigade 20 hours ago [-]
Sort of; SIP originally was simply meant to protect /System from root. But nowadays, it's more used for system attestation. Which in turn is used by the OS to decide how to ask for and enforce certain user permissions and sandbox profiles.
lapcat 19 hours ago [-]
> SIP protects "/" but not "/Users" (macOS' $HOME base).
> that's why Muse could get it even with SIP.
Both of these assumptions are mistaken.
lapcat 20 hours ago [-]
> Muse being able to exfiltrate the contents of your messages db doesn’t compromise system integrity to begin with.
I care more about the integrity of my personal privacy than I do about the integrity of the "system". The point of the system is to serve me.
> And OP had SIP enabled, but his system still got compromised with a remote exploit.
Nobody said that SIP magically prevents macOS bugs and security vulnerabilities.
brigade 19 hours ago [-]
Protection from the sort of malware OP was hit with is the most commonly cited dire warning against disabling SIP. I just assumed that was also the reason you were against disabling SIP in order to grant permissions to software you intentionally installed.
lapcat 19 hours ago [-]
> Protection from the sort of malware OP was hit with is the most commonly cited dire warning against disabling SIP. I just assumed that was also the reason you were against disabling SIP in order to grant permissions to software you intentionally installed.
No. The confusion here is that the Stratechery post combines multiple stories. There was a macOS screen sharing vulnerability, now fixed. The vulnerability existed even with SIP enabled, and that vulnerability is how Ben Thompson's Mac was hacked.
The question was, why did Thompson's Mac have the screen sharing port open to the internet, and that's when Thompson explained that the Mac was running an agent.
Coincidentally, Apple published a developer note on Friday about upcoming changes to Full Disk Access, which mentioned AI agents. Apple did not give any specific reason for this change, but presumably the inspiration was a very recent public controversy initiated by a journalist whose Messages database on macOS was read and uploaded by the Meta Muse app. Muse and similar AI apps request Full Disk Access to access all of the user's information. Without SIP, these apps would be able to suck up all of your data without permission.
brigade 19 hours ago [-]
If you're arguing that SIP isn't a useful defense against malware, I agree there.
Sandboxing full disk reads is orthogonal to what SIP actually provides. It's entirely possible for an unsandboxed binary to slurp your private data even with SIP enabled.
lapcat 18 hours ago [-]
> If you're arguing that SIP isn't a useful defense against malware
No? I'm not.
SIP is of course not a universal defense against every possible kind of attack, but did anyone ever expect it to be?
> Sandboxing full disk reads is orthogonal to what SIP actually provides.
No, because again, as I already said, disabling SIP also disables some TCC privacy protections.
> It's entirely possible for an unsandboxed binary to slurp your private data even with SIP enabled.
Not the data protected by TCC.
18 hours ago [-]
21 hours ago [-]
john_alan 19 hours ago [-]
What about all the stuff they've done to keep it open:
- Per-install boot security policies
- Custom kernel boot (kmutil configure-boot)
- Raw-image boot mode
- XNU source releases
- Disabling SIP
- Disabling the Signed System Volume
- Third-party kernel extensions
- Developer ID distribution and notarisation
- Gatekeeper "Open Anyway" override
- Hypervisor.framework
- Virtualization.framework
- Rosetta for Linux VMs
- Nested virtualisation
- macOS guest provisioning
- DiskImageKit
- Custom Virtio devices
- Containerization framework
lapcat 19 hours ago [-]
> What about all the stuff they've done to keep it open
I don't understand the purpose of your reply?
One of your examples is "Disabling SIP", but you're replying to a thread that has already been discussing this very topic, so it makes no sense to ask us "what about" that.
The issue is really the difficulty of using macOS as an expert user, and this has become significantly more difficult over the years. You mention "Developer ID distribution and notarisation", but both of those are actually restrictions that were added later to a previously open system. Notarization in particular has become a major pain for developers. Also "Gatekeeper Open Anyway override" has become significantly more difficult for users over the years.
john_alan 19 hours ago [-]
> I don't understand the purpose of your reply?
to illustrate, counter to the HN narrative, they've actually done a lot to keep the platform open to hackers and hobbyists.
Sure, remove disabling SIP from the list, the others still stand and are quite compelling IMO.
Fair enough on the kernel extensions.
I take your point(s) but the doom about the Mac turning into iOS and the terminal being taken away is unfounded.
lapcat 19 hours ago [-]
> to illustrate, counter to the HN narrative, they've actually done a lot to keep the platform open to hackers and hobbyists.
My comment that you replied to was not about the HN narrative. Thus, I still don't understand the purpose of your reply.
wpm 22 hours ago [-]
It's like how all of the retail floor models are managed by Jamf Pro but you won't see an MDM profile in the Settings app.
7r33 23 hours ago [-]
Having 5900 hot to wan.. He wrote an article to tell the world that he doesn't understand basic networking.
fg137 23 hours ago [-]
Yeah, the dude wrote a 3,500-word article trashing Apple when he can't even follow the most basic security practice in the first place.
I got confused for a second how Claude Code and agents are related to this piece. Of course they aren't. Anyone with a half brain about securing their system would never run into any of this in the first place. Hiring Claude Code to do scanning every half an hour is such a waste of tokens.
7r33 14 hours ago [-]
You know he did the 'chef's kiss' when his frontier model that he pays a subscription on completed this article.
The 'built a server that's going to run linux' line confused me. gOiNg tO? This boy didn't have 20 minutes to write a usb, shred the disks in live boot and install?
throwawaythekey 5 hours ago [-]
Yeah he recently built a rack over a weekend and has been planning to fill it.
He has decent business takes on tech, the podcast/articles are worth paying attention to. The actual tech takes are probably too dumb for the hn audience, but you aren't the target audience.
archagon 17 hours ago [-]
Maybe Claude told him it was OK.
I'm not sure why a writer needs swarms of agents in the first place.
throwawaythekey 12 hours ago [-]
Forgive me for being the idiot in the room but is the argument:
1. 5900 was always known to be an extra unsafe port to have open
2. all ports should be assumed unsafe without explicit vetting
I'm assuming the argument being made is (2), but it really is a sad safe of affairs because use cases from time to time do involve having ports hot.
Or should things be taken one step further to *always* use a vpn or similar?
dns_snek 2 hours ago [-]
> Or should things be taken one step further to always use a vpn or similar
Yes. The vast majority of software is not hardened enough to be exposed to malicious actors. Any kind of control panel, device management interface, NAS/file sharing protocol, remote desktop protocols, and anything else that isn't explicitly designed to be a public service should be protected with a hardened outer layer like a VPN, SSH tunnel, or mutual TLS/client certificate authentication.
wa2flq 6 hours ago [-]
Very true. As a poor second option, if he is working from known fixed IP locations, he could have used a packet filter to allow access only from them.
If he is roaming freely, he had no business leaving port 5900 world accessible.
cyh555 5 hours ago [-]
He gonna write more articles if he uses Linux and Windows
piker 21 hours ago [-]
> I understand that people are nervous about giving these agents access to one’s computer — as I noted, the Mac Mini in question has nothing on it except for Codex and Claude — but in this case you could make the case that I would have been in much more trouble had I not had an agent running persistently.
If the burglar breaks in through the cat door but she wakes you to let you know, did the cat make you more safe?
I have a Macmini purposely for Codex to do whatever. Nothing personal on it. It’s been a productivity boost 1000x for me. I screen share in, give it some tasks, tell it to install software, run brew whatever, use QGIS and other complex software and email me screenshots. Astonishing.
But I’m worried because of this and other guardrails all of that will be impossible or much harder in the future.
jeremyjh 1 days ago [-]
Couldn’t you give agents access to the screen sharing software to see the TCC prompts?
1 days ago [-]
wpm 22 hours ago [-]
TCC prompts have some degree of "synthetic click" detection. It's been a while since I've tried to click "Allow" with osascript.
jeremyjh 22 hours ago [-]
Right, but that isn’t what I was suggesting. TFA - which I read - says the author uses remote screen technology to click through the prompts.
e28eta 18 hours ago [-]
I wonder what apple does when confronted with software that auto-approves the TCC prompt via a VNC connection to localhost.
If there’s some protections that prevent it from happening via localhost, it feels like the next step is to proxy through another host on the LAN.
Heck, I wonder if someone’s already written an app that’ll connect to VNC, look for any permission prompts, and approve. His agent software could just poke it anytime it thinks it’s blocked.
redmaple892 18 hours ago [-]
> What’s better, using a structured reminders app that you have to check, or simply being reminded directly by an agent? In truth the answer will likely vary by person, but it’s worth pointing out that Apple is so married to the app paradigm that they probably never even considered the alternative.
This was the most interesting part to me. I wonder what this divide looks like in the real world. I have a hard time believing this is true for everyone:
> I don’t want a different UI per app, when I have at my disposal true UI — the Universal Interface for everything digital.
mcepl 1 days ago [-]
If the main to run Apple computers is their hardware, why not to run it with Linux. Aside from better filesystems (Theo tests were shocking to me, how bad FS you guys have), you would get better compartmenalization and I believe better security. What's missing?
chr15m 10 hours ago [-]
> I use screen-sharing constantly — including from my phone — and almost every time it’s to click “OK” on a stupid prompt that I’ve long since stopped taking seriously;
It's insane what people will put up with to avoid just doing it properly on a real OS.
pasc1878 23 hours ago [-]
Linux.
There is no Linux that will run on anyhing newer than M4 and even that is incomplete.
tucosan 23 hours ago [-]
Sure there is. Containers and VMs.
That's how you properly isolate ai workloads.
datagazing 23 hours ago [-]
Linux VM guest, macOS host.
Better design in terms of resource isolation and control, too.
I use krunai. It is not quite as flexible as some people probably want (strongly linked to a specific non-systemd version of Debian 13), but there are many other options as well, such as Lume, Virtualization.framework, etc.
Much better than wrangling server code via Apple nonsense, and there are no real downsides after you've done the integration/deployment work once, assuming you are not building on some closed source thing that only runs on macOS.
adolfox 22 hours ago [-]
What I took home from reading this article is Apple NOT deploying security updates as security updates. That to me is SO stupid on their part—coercing to the point updates by withholding important security updates.
terminalbraid 21 hours ago [-]
The author themselves say "I am admittedly being pedantic here" to that point.
herf 21 hours ago [-]
You don't want a backup vulnerable to "reading iMessage" either - maybe they should just encrypt these things at rest.
hombre_fatal 1 days ago [-]
> Apple doesn’t seem too happy about agents
I don't get this reaction to Apple making Full Disk Access more explicit. Whether they're "happy" or "sad" about agents doesn't seem responsive at all.
Kinda seems like whenever you spend 10 seconds thinking about the average user, social media gets angry. The quoted justification by Apple seems reasonable.
askonomm 1 days ago [-]
Being happy or not has nothing to do with it, in my understanding as well. Removing full system access from non-deterministic tools prone to prompt injections seems like the most obvious thing to do. There's a reason I run all my projects in rootless isolated containers these days. There has never really been "trust" in software, but the lack of trust is a lot more obvious these days.
PaulHoule 24 hours ago [-]
Apple can’t see a future where Mac isn’t like iPhone. They need a 30% cut of all software revenue, want a 30% cut of any AI tokens you use, and will steal 30% of your time as a software developer developing for your own account any way you can.
rickdeckard 23 hours ago [-]
This. I'm quite confident that they look at the Mac as a "profit-leaking" product they gradually need to bring on-par with their other products, but can't make any big steps to avoid alienating the userbase.
But I'm sure the day of the iOS-based iMac will come, and pandora's box will be opened. Businesses will love it, especially those with Kiosk use-cases, and not before long we will read everywhere (including here) how superior the security is to a Mac for everyday use...
PaulHoule 23 hours ago [-]
They must have a prototype of an iPad somewhere that can run both iOS and Mac software but they are too comfortable with their current product positioning. I thought Microsoft had a good idea with Windows 8, I mean, I don’t travel with a laptop anymore, just an iPad and wireless mouse and keyboard. If I need to use desktop software I use RDP or something like that. I go to a hackathon and I have both the sleekest and the beefiest hardware. It’s great. An iPad could give a similar experience with local compute if only Apple would let it.
But to back into it…. OpenClaw amd Muse and stuff give people a real reason to buy a Mac but Apple doesn’t like it.
rickdeckard 23 hours ago [-]
> "OpenClaw amd Muse and stuff give people a real reason to buy a Mac but Apple doesn’t like it."
Yeah, because a year down the road they might give the same people a reason to upgrade to another box, not from Apple.
Apple needs to ensure that they stand in the middle of every supplier relationship their customers have.
That's quite difficult when they don't provide direct value to both, so the natural conclusion is for Apple to present itself as a care-taker, the only one who prevents the user from taking any harm...
brookst 22 hours ago [-]
That’s a pretty elaborate and conspiratorial way to say “Apple isn’t especially interested in market segments they’re not trying to serve”. Which I think is true of most companies?
rickdeckard 21 hours ago [-]
It's meant to say "Apple prefers if companies are not able to enter relationships with Apple customers without Apple being in the middle", which is not typical for most companies
brookst 13 hours ago [-]
It’s true of any two-sided marketplace, especially when part of the marketplace’s value prop is safety (see: eBay)
alt227 21 hours ago [-]
> I thought Microsoft had a good idea with Windows 8
Get out! Desktop are not mobile devices and there is still need for them. Microsoft learnt this the hard way.
PaulHoule 17 hours ago [-]
Well I hear a lot of “silly boomer, don’t you know a computer is a computer and a phone is a phone” but many whippersnappers don’t know that Von Newman proved all computers are equivalent in theory and video game emulation proves they are in practice.
I think the barriers that exist depend on path dependence and other accidents of development. The laptop has a hinge and a trackpad that help you when you are flying on a plane. 2-in-1s drove stewardesses crazy because they couldn’t figure out if you had to stow them for takeoff. For that matter battery sizes are limited because of the needs of that industry which might seem justified if you live in NYC and can fly to London for what it less to costs to fly from my small town to NYC. Maybe if they’d invest in my community I’d care what they think but I think it’s unjust.
All the time I use a cheap plastic clip and a cheap Bluetooth mouse and keyboard and RDP into a monster computer from my tablet. If I have a real desk or table it’s fine, if you really have to put your laptop on your lap that hinge looks like genius. I’ll grant the 2-in-1 can be demoed at CES and the Bluetooth-based system can’t because they have too many devices in too small a space for Bluetooth to be reliable.
Even if I don’t have the mouse and keyboard I can still do a lot with the touchscreen.
The worst thing Win 8 revealed was that you could have the ‘windows’ keys on computer keyboards for almost 20 years and nobody noticed because…. It looks like an ad and people think anything that looks like an ad “just doesn’t work” (as opposed to “doesn’t just work”). If you were missing the start button you could just push that button but people treated that like putting their hand in the toilet.
oliculipolicula 9 hours ago [-]
OT but I really would have liked to see your comments on this
Well Spanish is one of those “languages that I can’t read except that I can read it” together (in order of declining comprehension) with Dutch, German, French and (large gap) Chinese and Japanese.
rjrjrjrj 20 hours ago [-]
The Mac has had the ability to run iPad apps for quite a few years now, since Apple Silicon. Unfortunately it is opt-in for developers and most don't. I wonder if it will become non-optional (or at least opt-out) with the touchscreen MBP rumoured for this fall.
I think that's the unification route they are most likely to take, hopefully along with a thinner/smaller MacBook design and built-in cellular.
They've taken so many swings at the iPad Pro (both hardware and software), and it has never been as good as the MacBook.
easyThrowaway 22 hours ago [-]
> An iPad could give a similar experience with local compute if only Apple would let it.
It does, it's called the MacBook Neo.
iPad sales have been rather stagnant in the last few years, while they made bank with their low-cost laptop. On a purely conceptual level I don't think they're gonna merge the two anytime soon, even if they will probably start sharing the very same logic board from their next revision.
PaulHoule 22 hours ago [-]
Stagnant because (1) they don’t want to cannibalize iPhone and Mac and (2) competitors have failed to do make tablets that do a lot more than become e-waste. Microsoft had a reason to make the transition as carriers didn’t allow them to make a phone platform but their other enemies like Dell, HP and Lenovo had neither the motivation nor engineering skills to come along.
m463 15 hours ago [-]
> Businesses will love it
businesses can already lock down your mac so you can't use it inappropriately.
I'm reminded of the guy who ran afoul of google, and all of a sudden all his google devices got forced software updates and started doing things.
>...but can't make any big steps to avoid alienating the userbase.
I think the way this could work is by linking certain capabilities to MDM or a developer program membership. Organisations and people who really need it would still be able to get it but regular users would not.
23 hours ago [-]
larme 17 hours ago [-]
Unlike 30 years ago, now I see anti-developer as a feature for end users. The current trend is that big corporation developers just abuse any system to squeeze profits/information from end users as much as possible.
In this case apple do this because Meta are abusing.
otterley 21 hours ago [-]
What does this have to do with the article, exactly?
patja 20 hours ago [-]
Author's misguided choice of platform for running a headless server.
simondotau 9 hours ago [-]
I understand this mindset when I put my software developer hat on.
But as an end user, these are hollow words. As a consumer with Apple devices, I'm entrusting Apple to keep my computer protected from bad software, malicious or otherwise. You need to appreciate that you -- the software developer -- are not the good guy. We're not the same team. If you don't like your little sandbox, or if you resent having to ask for permission to go beyond it, that's a you problem, not a me problem.
As a software developer, I can see it from both sides. I wish more people did.
m463 16 hours ago [-]
You forgot, they want 30% (or more) of your files to be inaccessible by you, so you can't access the data/media you've downloaded in ways apple doesn't like, or disable apple daemons that collect telemetry or whatever.
john_alan 19 hours ago [-]
I don't think that's fair, they've spent a lot of time and effort ensuring the Mac is still an open/UNIX like platform, including (where they didn't have to):
- Per-install boot security policies
- Custom kernel boot (kmutil configure-boot)
- Raw-image boot mode
- XNU source releases
- Disabling SIP
- Disabling the Signed System Volume
- Third-party kernel extensions
- Developer ID distribution and notarisation
- Gatekeeper "Open Anyway" override
- Hypervisor.framework
- Virtualization.framework
- Rosetta for Linux VMs
- Nested virtualisation
- macOS guest provisioning
- DiskImageKit
- Custom Virtio devices
- Containerization framework
verall 18 hours ago [-]
These are basically all things that an engineering org can justify as necessary for some reason but can immediately disappear when leadership announces a change in strategy.
Not to take away from your point too much - this is a significant amount of work that shows their current stance towards maintaining the mac as a premium development platform. But I imagine they will start to split this - lower cost SKUs will get the iOS-ified OS while "Pro" SKUs will get (some of) the above and can still install homebrew, to prevent a full developer revolt.
Techies will figure out how to "jailbreak" the lower SKUs to unlock the full experience and the amount of people that follow through with that will round to 0%. Tech businesses will buy the >$3k Pros for their devs.
"Everyone" will be "happy".
amelius 22 hours ago [-]
> Apple can’t see a future where Mac isn’t like iPhone.
Can you blame them? Their managers cannot code, so they need something else that is "useful" to do. And the one thing they find useful is to increase revenue.
classified 21 hours ago [-]
Indeed, it's all beancounters and lawyers now, just as with any other run-of-the-mill monster corporation.
daft_pink 19 hours ago [-]
I do feel since I use hermes on my work windows computer and grok bot in the cloud on everything else that computer use is so useful and important, but I'm also worried that Apple will not be a good choice for that.
hennell 24 hours ago [-]
Is the conclusion of this that Apple shouldn't add robust and hard to automate around privacy guards because we should all just do as he does - use a dedicated Mac mini for agents with no personal files on for privacy?
geerlingguy 23 hours ago [-]
I assume any computer connected to my LAN is also a dedicated attack vector for everything on my LAN in case of compromise.
Exposing any port directly to the Internet is a huge risk these days—at minimum I'd put a very strong firewall in front, and unless it's serving the general public, switch to a non standard port. It's not much but would prevent the dumb automated scripts that operate on standard ports.
nixosbestos 1 days ago [-]
I feel like this article was all over the place. Also, this person was really running a macOS box raw on the Internet, no firewall, nothing? :/
GeekyBear 1 days ago [-]
He also had that computer configured to download system updates automatically, but not to install them.
On the plus side, at least he didn't run the AI agent on the computer with all of his personal data.
janfoeh 23 hours ago [-]
He had enabled a setting that says "Install [...] security updates". If enabling that setting does not lead to the system installing security updates, that's on Apple.
GeekyBear 23 hours ago [-]
System updates also include security fixes.
janfoeh 21 hours ago [-]
Which is not apparent if you give them an explicitly labelled separate toggle.
GeekyBear 21 hours ago [-]
I guess Apple could do what Microsoft did and take away the user's ability to control system updates.
However, this user made the choice to turn off the installation of system updates manually, based on a false assumption.
janfoeh 15 hours ago [-]
This user turned off the installation of system updates, because Apple labelled a control incorrectly.
mold_aid 1 days ago [-]
"Thank god the causes told me about the effects!"
amelius 23 hours ago [-]
My rule: if a company, in any way, forces you, the user, within reason to do anything you don't want to do, or prevent you from doing anything you would want to do, then ditch that company ASAP.
The entire iOS/MacOS schism already says enough.
john_alan 23 hours ago [-]
> Then there is the fact that macOS is a certified Unix system
They didn't renew Golden Gate's UNIX 03 certification this year:
> What I need is a permission layer for agents, not the programs they create; TCC is operating at the wrong level of abstraction.
Or... you are operating your computer at the wrong level of abstraction. It was made for use by a real intelligence.
trollbridge 23 hours ago [-]
We already have all these permission layers too. SELinux and Windows NT have existed for a long time.
So has macOS. It’s just a matter that the agents don’t bother to use the existing permission layers.
chrisjj 19 hours ago [-]
So all we need to do is get malware to play by the rules. :)
spoonsies 22 hours ago [-]
“If Woody had only gone right to the police(used a vpn), this would not have happened.”
It’s not like a VPN is some arcane knowledge. I guarantee Claude would have told him or practically yelled at him if he asked how he could have secured his mac exposed to the open internet.
Glad he actually acknowledged it and is getting tailscale or similar.
sharts 22 hours ago [-]
At this point Windows has become more usable than MacOS.
someguyiguess 21 hours ago [-]
No it hasn't and it's not even close.
- Guy writing to you from Windows 11 with multiple Macbook Pros next to him.
I'm missing a key point: why does the author say TCC is implicitly to blame for his Mac being hacked?
krackers 17 hours ago [-]
TCC throws up vista-style warning prompts everywhere, so to bypass them he opened up remote desktop so he could manually dismiss them, which then got exploited via a recent pre-auth bug in ARD.
If the TCC prompts could be dismissable some other way (e.g. via CLI with root permission) presumably he wouldn't have resorted to such measures. I sort of see the point, the lesson from Vista is that if you put up annoying obstacles people are going to the easiest workaround, bulldozing over them rather than putting up with them. People will end up disabling SIP or poking more hole if they don't have an easy way to bypass TCC stuff.
runjake 14 hours ago [-]
Thanks for that explanation, got it. Yes, they seem very Vista UAC-like in usability fail.
24 hours ago [-]
21 hours ago [-]
swozey 23 hours ago [-]
Giving a text assumption engine root access to the world, "hey little clanker, heard you understand 10% of every topic, go nuts."
meherabhossain 4 hours ago [-]
[flagged]
impure-aqua 24 hours ago [-]
[dead]
mertbio 1 days ago [-]
[dead]
soltanov 1 days ago [-]
It is not about emotion; it is about platform control. Apple limits background autonomy under the label of security, while ensuring only their first-party system frameworks get unfettered ambient access. Standard playbook.
detourdog 1 days ago [-]
This seems like sysadmin 101 to me. Controlling local access and who to trust was always the way. Platform vendors always enjoyed this privilege. Overriding the platform vendors software tools was done with variations kept in /usr/local/ and symlinked to over ride the vendors choices.
BirAdam 1 days ago [-]
Well, you don't even really need symlinks. You can just adjust the order of locations in $PATH
detourdog 21 hours ago [-]
The symlink works when the preferred tool has a different name from the vendor supplied tool being overridden.
simonh 24 hours ago [-]
Full disk access is a permission you can grant to software on you Mac, that is not reserved just for Apple, and nothing Apple has said implies they have any intention of removing that class of permission. All they said is that they want users to be fully aware of the implications when granting it.
trollbridge 23 hours ago [-]
My expectations aren’t high when we’re talking about opening up VNC to the public Internet.
simonh 15 hours ago [-]
Doesn’t port forwarding to an ssh tunnel work? I’ve used TeamViewer just for convenience.
trollbridge 7 hours ago [-]
Huh?
I put things behind a conventional firewall and then use a VPN for remote access.
rimliu 1 days ago [-]
maybe there is a reason they are called... system frameworks?
wowanapple 23 hours ago [-]
The sole fact that products from Apple and many other proprietary manufacturers receive so much attention on the discussion board called "Hacker News" is utterly ridiculous. A good example is the thread named "Turn off Apple Intelligence on macOS 27 and get its disk space back" with 600+ points and 400+ comments on the main page today.
What's worse is that a big part of the discussion here is just worshipping closed-source from a merely consumer perspective ('...wow! what a cool shiny UI feature to manage SSH keys for only 0.99$'), as if we were on the Tom's Guide forums. And some active members here even purchase browsers and seem to be very proud about it...
Klonoar 23 hours ago [-]
I will never understand comments like this.
You are on the wrong site if you think that HN was ever a bastion of the hyper OSS mindset.
This is a site powered by and run by one of the arms of a startup incubator/investor. It has always been clear on that.
Just because it has “hacker” in the name doesn’t mean what you think it means.
Citizen_Lame 22 hours ago [-]
Exactly. The audience used to be tinkerers, people who liked getting their hands dirty. Now it's mostly bros of one stripe or another (AI bros, finance bros, and so on).
shagie 22 hours ago [-]
The link 'past' in the top bar allows you to see the front page in the past.
From 2010 ... https://news.ycombinator.com/front?day=2010-10-04 that still looks similar (though I find it amusing that Ask HN: So what's new in the world of A.I.? https://news.ycombinator.com/item?id=1754134 is on the front page "... My prediction (heh pun intended) is that you see enormous changes in the field when processing by GPU's becomes much more available. There are some algorithms that are simply difficult to research because labs don't have access to fast enough machines. ...")
There's certainly been some broification and the various reddit exoduses have been shifting the average user a bit.
I do believe you've got your top color set to ff007f rather than ff6600 if you're forgetting what the site looked like then.
user43928 19 hours ago [-]
Isn't the AI stuff tinkering?
I've certainly thrown together more software and automations over the last year than I have in the other ~15 years since I started programming.
It's never been so fun.
ravenstine 21 hours ago [-]
I'm not sure where you're getting the "worshiping" part from. Though I respect your overall opinion while still disagreeing from it, it's been a very long time since HN came anywhere near worshiping Apple or even most big tech companies. Most of us simply live in the real world where using big tech wares is a soft-requirement. Using an Apple device or having interest in them makes one no more or less a "hacker", which is already a pretty subjective and contextual term to begin with.
AJRF 23 hours ago [-]
If you are interested in tech outside of consumer electronics lobsters is a good alternative to here.
sitzkrieg 7 hours ago [-]
the walled garden lifetime purchaser finds themselves unable to find an exit
If you give full-disk access to Meta software running on your main computer, Meta is not going to respect your privacy.
> Friday’s [full-disk access] announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.
https://arstechnica.com/security/2026/10/apple-changes-full-...
If you want to know why Apple is suddenly not happy about the way the full-disk access permission is being abused, look no further.
So, for example, if your backup software is a CLI, you have to give Full Disk Access permissions to your Terminal, not the backup software. And subsequently every other process you start from your terminal will also have Full Disk Access.
Enforcing it per executable down the process hierarchy isn't helpful either: you'll eventually grant it to an interpreter (zsh, python3) and create a hole.
TCC's security model is fundamentally wrong.
Unix solved this decades ago: agents should be their own user. What's missing is the tooling to make disposable users practical, and perhaps cross-platform filesystem ACLs.
There's a program that lets you use it from the terminal here:
https://github.com/AprilNEA/disclaim
I think Apple don't expose it as public API because TCC is meant to map user permission prompts to things the user understands logically as applications, which means things they started. If apps can have the user be prompted to grant permissions to sub-components of themselves it can get very confusing quite rapidly.
The supported way to do this is therefore to just make a proper Mac app with its own bundle ID, sign it, and ask Launch Services to start it up - potentially via XPC. It will get its own TCC permissions set along with its own icon and so on. You can, if necessary, embed this app inside another one, although of course the thing the user sees as the app being given permission will be the identity of the embedded app so that reintroduces the potential for confusion.
I don't know if the amount of machinery is such a big deal now, an LLM can produce the needed code quite quickly. Those sub-processes shouldn't be disclaimed anyway because they'd end up without a proper code signing/bundle identity and get weird permission restrictions that can't be elevated. Claude App makes this mistake, IIRC.
That’s a hand waving if I’ve ever seen one.
How is that going to help?
If the Agent gets launched with is own user is will not have access to ANY of the files that are only read by the user.
Of course, as a user, you need some way to easily modify ACLs to do this, but that’s just a front end concern on top of a solid security model that every OS supports.
This brought to mind Neal Stephenson's essay "Unix - The Hole Hawg of Operating Systems" from back in the day (1999):
> I myself used a Hole Hawg to drill many holes through studs, which it did as a blender chops cabbage. I also used it to cut a few six-inch-diameter holes through an old lath-and-plaster ceiling. I chucked in a new hole saw, went up to the second story, reached down between the newly installed floor joists, and began to cut through the first-floor ceiling below. Where my homeowner's drill had labored and whined to spin the huge bit around, and had stalled at the slightest obstruction, the Hole Hawg rotated with the stupid consistency of a spinning planet. When the hole saw seized up, the Hole Hawg spun itself and me around, and crushed one of my hands between the steel pipe handle and a joist, producing a few lacerations, each surrounded by a wide corona of deeply bruised flesh. It also bent the hole saw itself, though not so badly that I couldn't use it. After a few such run-ins, when I got ready to use the Hole Hawg my heart actually began to pound with atavistic terror.
> But I never blamed the Hole Hawg; I blamed myself. The Hole Hawg is dangerous because it does exactly what you tell it to. It is not bound by the physical limitations that are inherent in a cheap drill, and neither is it limited by safety interlocks that might be built into a homeowner's product by a liability-conscious manufacturer. The danger lies not in the machine itself but in the user's failure to envision the full consequences of the instructions he gives to it.
* http://www.team.net/mjb/hawg.html
* 2021: https://news.ycombinator.com/item?id=28015229
I do not want to hand my child a Hole Hog, I want to hand them a residential power drill with the torque settings locked to a safe level. I need a fucking Hole Hog for the work I do.
There is a time and a place for every tool, and sometimes the hands holding the tool influence this more than an expert would care to admit, who instead say things like “you’re doing it wrong!” to admonish users who didn’t even know there was a difference between the tool they held and the one they needed.
rm -rf / would like a word.
To your point though, not everything in Mac can be solved via root user privilege. SIP is annoying to toggle, the main issue being discussed also demonstrates why Mac OS is not the proverbial Hole Hawg as well.
macOS in its default configuration may not be the HH, but if SIP removes those limitations it is still available.
As someone who (a) does some tech support for family, but also (b) uses a MacBook for sysadmining Linux servers, but kind of happy with the current balance. I don't think I've run into SIP limitations, so perhaps I'm not an 'advanced' enough user of macOS (MacPorts generally works for the 'extras' I need on top of base macOS).
So I rescind “needing” a hole hawg and correct it to “strongly prefer or desire” a hole hawg. Mainly because I shouldn’t have to rip apart a magic keyboard to embed a touch ID module into a 3D printed case for a standalone fingerprint reader module.
(Bruce Sterling was the weird hippie who kept feeding interesting things into the machine to see what colors they made - without him, Cyberpunk would’ve died on the vine.)
There was a time I had their FB app and messenger on the phone. Then it was found out that their crappy engineering couldn't hide the fact their apps were constantly watching users and other apps on entire phone, causing >15% additional battery drain, even when they were not opened.
I've removed all of them, never needed them on phone (or at all) and can't complain at all. Don't expect privacy form meta, any, ever.
Apple stopped adding protected file-system domains for some reason, and have only expanded TCC to entail more vague and nonsense monikers. Sandboxed apps of importance like Messages, Notes, Reminders, and so on, all just end up under the "Full Disk Access" umbrella because they all store their databases in ~/Library/Containers, and FDA is really the only thing gating access to that. Apple should just start pushing the permissions one level down into that folder. Do I want to give an agent access to my Safari history, but not my messages? Too fuckin bad! No way to slice that right now, it gets full disk access and can access anything.
Apple considers a user deliberately delegating access to their data to any program not controlled by Apple to be a serious problem that must be corrected.
Application developers are not making the user experience worse, Apple is.
I really dislike this point of view.
1 - we're all going to suffer because meta are scum. It's not "all application developers", it's "exactly who you assumed it would be", and also too, "exactly the same scum who've spent the last 10 years working around privacy controls any possible way they can and deliberately obfuscating the choices people make around their privacy." The people who made pervert glasses and did covert web-to-app tracking by opening local ports [1] and bought sketchy spyware to track everything you did and scurried away from the light the second someone asked about it [2], [3]. And on and on and on.
Spotify has long asked for it and... they use it to copy my local mp3s onto my phone so I can listen to them away from my computer. It's awesome.
This doesn't mean that Apple isn't champing at the bit to use Meta as an excuse to screw all software developers. If Apple cared about their users, they'd do something like revoke Meta's software keys and leave responsible developers alone. Alas, Apple will obviously exploit this too :(
[1] https://localmess.github.io/
[2] https://en.wikipedia.org/wiki/Onavo
[3] https://uk.practicallaw.thomsonreuters.com/w-040-4130?transi...
https://pxlnv.com/blog/macos-full-disk-access-restrictions/
> ...the uses of Full Disk Access go well beyond the category of backup apps, and it is worrisome to see Apple give it such a limited frame. I have given that permission to disk management utilities, Sketch, Terminal, and other apps I do not want to be throwing permissions requests as I move around my drives. Is Apple suggesting this capability could be limited in the future to backup applications alone? I do not like that.
If Full Disk Access were, in future, to be something that I could not grant to (for instance) the Terminal, because it is not a backup app, that would severely limit my ability to do work on a Mac, both as hobbyist and as computer professional.
I agree that the agent situation is a fairly serious concern; I just don't want to see Apple throw the baby out with the proverbial bathwater.
They want unsophisticated users to understand that they would be granting unlimited access to all of their personal data if they grant software that permission.
> We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.
Microsoft attempted to lock Windows to their app store twice, with both Windows RT and Windows S, but the market rejected both of those attempts.
Apple hasn't done that, despite claims that it's coming any day now for at least a decade.
Overall the limits to AI productivity can be summarized in one word: discipline. If you're undisciplined in your security, your design constraints, your automated test coverage, your separation of the deterministic and indeterministic, you will be quite productive ... for a time. Until quite suddenly, you aren't, possibly due to catastrophe.
Similar to the early era of computers on the Internet, with lax security, we have a window where we can get away with this, but it will close quicker than many realize. Some things do seem to need to be learned the hard way.
Apple is trying to do the bare minimum here - not even introducing a new security model - and people are already freaking out. But a disciplined agent sandbox model is exactly what we need to get to.
In 2019, my SSN was used to purchase 4 iPhones, open 2 credit cards, and used to buy perfume in another state.
In 2026, almost mainstream messaging app monitors your private messages (yes, even Whatsapp now [0]).
Society decided that to be in it, you must give up your privacy along time ago.
[0] - https://engineering.fb.com/2026/08/12/security/how-were-buil...
Yeah, it was neat that Claude found this, but Thompson showed an almost criminal lack of security awareness by having VNC/ARD open to the internet
And, all of that said, Apple hasn't said anything about not letting people have full access to their disks. Just that you're going to have to be very intentional, click through a very scary warning, to do so. Happy to do that to prevent my mom or dad from accidentally opening up their machine to every hacker in Belarus or worse yet Facebook
Is it because of most of virus/malware target Windows OS due to its sheer size, or because MacOS security system is more superior than Windows ?
I also less likely to get hack if i open url link on templeOS
God doesn't believe in the networking stack so you're good
Then take away cars as someone could crash and kill themselves with them. What kind of babyified logic is that?
Correct. This is why gun safety is taught. Try and bring up banning shotguns in the US and see what happens.
b) there are plenty of options for completely open computing platforms. Apple has every right to build the platform they want to build, and you as a consumer have every right to go buy a Framework laptop and install Debian on it instead if you don't like it
When my mother in law switched from (XP-era) Windows to OS X, she expressed a profound sense of relief that she didn't have to worry so much about accidentally breaking it. She has absolutely no desire to learn computers well enough to understand a system that gives her more control. In her experience it never enabled her to do anything particularly relevant to her own interests, and mostly accomplished the complete opposite by leaving her slightly afraid to do anything. My own efforts to try and explain her computer problems and how to avoid them in the future did not help; they only served to communicate to her that the computer was indeed complicated and scary.
Limitations ARE a liberating force. No limitations is having skyscrapers with doors opening to outside, because people should have the choice to step out among the birds and the clouds.
The Vision Pro could (in terms of hardware) be the Mac successor. Just the virtual Mac screen feature alone is great ... but the rest is "It's an iPad! But in 3D!" Ugh.
Don't underestimate the power of Apple's dream of locking everything down.
Apple's priorities (as Daring Fireball notes), are Apple, customers, something, something, something, ...., developers and suppliers.
I think Tim Cook missed his chance to leave a Steve Jobs like mark on Apple when he championed a next generation graphical interface on next generation hardware, but only for toy apps and media.
And for those that think "what could 3D/spacial really do for interfaces?", don't think exciting, just think about the simple perks that grow into usefulness, like your entire environment being (Mac-level capable) screens as you work. Consider how much of the real world and its activities, problems and structure are in 3D. And how people adapted to 2D graphical interfaces not because "wow!", but because many mundane things, like editing a table and writing a letter, got easier. And a lot of new mundane things became possible/practical.
That won't happen on a Vision "Pro" limited to being a toy app platform, media kiosk, and Apple iCloud services recurring revenue store front.
The software limitations are why it isn't worth the price, not the hardware.
The negativity here climbs up out of my deep love for my Vision Pro.
If you don't like System Integrity Protection on your Mac, you can turn it off and YOLO to your heart's content.
"If you are protected by a steel door, but you don't have the key, you are not safe -- you are imprisoned."
That said, I disagree on Apple: while the UI can be perfect, it has always imperfectly been trying to do the right thing technically in concert with developers and users, which puts it in the position of imposing constraints that developers and users can relax to varying degrees: wearable and home devices (not at all), iOS (somewhat), macOS (mostly).
wrt a hacker's future: I'm still traumatized both by decades of windows reboots and virus scanning, and by decades of squeezing into Linux (just don't sleep, avoid these displays...). I'm glad Apple stuff mostly just works and ordinary people still have access to unlocked, general-purpose computers, but that might not last. Cheap AI coding might remove any financial incentive to support users programming on their own, and we'd be left with locked devices as consumers or work-only access to programmable computers (at least for the latest hardware of note). If a 40% premium for mac hardware is the price we pay for continued access, so be it.
I think he was burying the lede but glad he finally posed the question.
I think it's a bigger risk factor for Apple than is generally assumed. If consumers get used to the freedom but endemic spying of products like Muse, Apple may have a hard time sticking to their privacy and security mandate.
> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.
As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.
This "you are entering the wilderness, I will not be able to protect you anymore if you proceed" framing reminds me of the alternative AppStore case, where Apple (and Google) applied scare-tactics in the UI to discourage users from giving permissions to alternative stores.
Which happens to be the only way to disable the TCC permission dialogs OP complains about. Guess the warnings worked well enough that no one knows that anymore.
Before System Integrity Protection, the root user had no permission restrictions, so it could access any system folder or app on your Mac. Software obtained root-level access when you entered your administrator name and password to install the software. That allowed the software to modify or overwrite any system file
https://support.apple.com/en-us/102149
This is the only weapon they have when governments have forced them to open their doors to the scary world outside.
This is not going to end well for everyone involved - especially for the user.
But that's the case on all platforms with any LLM agent being given full access.
There will be an adjustment period where users will learn of the risks - hopefully without much harm occurring.
The risk of having human assistant can be mitigated by background check, insurance and legal recourse. We have none of these for AI agents.
So as always, for the sake of "privacy" Apple needs to take action to protect the users from "themselves", and make it undesirable to grant others the same access Apple has...
Observationally, I would argue we've all been expecting this for this for a long time. Every year Apple has raised the price of allegiance and every year we've paid it, waiting for products like the framework laptop or certain linux distros to become mature. We're still not there yet, but how much longer until there is real competition in the personal computer market?
https://www.infoq.com/news/2026/10/snapdragon-x2-linux
So did this initiative within Apple just start and we could be looking at this change coming in Mac 28?
I don't remember another time of an announcement like this from Apple of a major change with so little information, though I could be wrong or hint of when.
Regarding the concern, while I do hope that there is still a way to grant actual full disk access to some applications. Even Apple called out a non controversial need for something like that, backup software. I can also think of security scanning software, a lot of businesses have those deployed to corporate Mac's. I do also think that better controls around it, especially in this age of vibe coded apps that never actually think about security or actively hostile companies like meta.
Doesn’t that already exist? If I give Terminal.app access to the entire disk, CLI tools started by the app (indirectly: Terminal.app runs a shell, and the shell runs the tools) have that access, too.
And I don’t think that’s because Apple gives Terminal.app preferential access. Google tells me that works for iTerm, too.
Or would it mean agents need to do some special thing to launch tools?
> this setting does not in fact apply to most security updates. CVE fixes almost always arrive in point releases; in fact, the most recent point release was about fixing this bug
So yes, Apple is very bad at security, borderline malicious even.
Why would anyone open up random ports (or even all ports) to the internet?
> The problem is that for my particular use case — a headless, always-on Mac Mini that I primarily access from other computers and my phone through the ChatGPT and Claude apps — macOS is incredibly hostile
> As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting.
> Obviously I should have — and will be — using a VPN going forward (the foundation of my entire approach to security is Tailscale); what I will note, however, is that TCC basically leaves me no choice but to have screen sharing enabled if I want to actually use my Mac Mini in the way I want to use it. I use screen-sharing constantly — including from my phone — and almost every time it’s to click “OK” on a stupid prompt that I’ve long since stopped taking seriously.
That's my takeaway from the article. I have trouble understanding how the author managed to extrapolate all these things about Apple from an obvious oversight on their part. I would never write a 3,000-word article about how bad someone else is because of an issue I caused for myself.
Software WILL have bugs and vulnerabilities, regardless of whether it's an OS or user application, whether it's from Apple or another company, or the update frequency/mechanism. If you can't even follow the most basic security practice on your part, you simply don't have any authority to discuss security otherwise.
Apple's remote access feature, that you would make remotely accessible for obvious reasons, apparently had a critical authentication bug.
Apple did not ship a security patch for this, allowing the vulnerability to be exploited a week later despite "automatically install security updates" being on.
Yes, OP could have prevented this by putting an additional VPN authentication layer in front of the Mac's built-in remote access.
That doesn't excuse the mistakes on Apple's part.
Let's first establish that Apple definitely has a stake in this.
How long they can come up with a fix and then distribute them, that's a question. You can't expect any company to fix a vulnerability within 5min. Whether one week is too long or their delivery mechanism is good, I can't tell, and I don't think there is a standard in the entire industry.
That doesn't mean it's useful to write an article about "I didn't do my part BUT you are too slow". Even if Apple somehow fixes this within an hour of the disclosure and delivers the update, with the bad configuration, the machine is still vulnerable within that window. Does that change the nature of the narrative?
An actively and easily exploited (just a port scan), and high-impact root RCE needs faster patching than one week.
When there was a more user visible bug (2017, empty root password gives you root, CVE-2017-13872), Apple managed to remotely patch this across all supported macOS versions in about 26 hours + next macOS online, end to end, without user intervention or manual updates.
And that was a decade ago before Apple built “rapid response security updates”
But I find it egregious that they didn't roll it out as a security update at all, which is why it was not automatically installed in OP's case, even though the fix was already available.
I mean, what else requires a hotfix via security update if not a fatal flaw in your remote access authentication leading to full root access, that is actively being exploited in the wild?
Also, it's not really on the user to gate remote access behind an additional firewall and authentication layer. This is something that just has to work securely.
If it doesn't, that's understandable, but still hardly the user's fault.
> Also, it's not really on the user to gate remote access behind an additional firewall and authentication layer. This is something that just has to work securely.
About that, I have a bridge to sell.
For Ex, the best practice is to use VPN, so you only open port for VPN, and you assume whatever VPN protocol/software does not have any bugs.
You can use tailscale so you dont have to open port, but after all, tailscale is also software.
Welcome to hacker news!
Even though this was a valid critical bug [1], you need to enable screen sharing and allow connections to and from port 5900 on your router for a remote person to be able to exploit this.
Any security conscious person would probably be using a VPN (Wireguard or Tailscale) to prevent something like this, in the first place.
> almost every time it’s to click “OK” on a stupid prompt that I’ve long since stopped taking seriously.
The line above tells you how seriously this person takes security prompts.
[1]: https://nvd.nist.gov/vuln/detail/cve-2026-65400
I mean, every time ISPs, NAT, or IPv6 is mentioned you have a LOT of people who are really angry they can't just netcat a random port on their friends' machine to send files to it.
I have a PiKVM on my Mac Mini for this reason, and I bet the author would be well served by one as well.
We’ve known that improperly secured ports and non-firewalled machines get popped. When will people learn?
I know let’s put our power plants and water treatment out there with open ports too. Why should endusers have all the fun?
> Hopefully Apple has in mind a solution to this situation that will still enable knowledgeable power users to confirm agreement to a sufficiently scary warning and put their Macs in a state similar to what we have today. I worry. What alleviates my worst fears is the knowledge that every technical user at Apple itself needs to use their Mac as the powerful Unix workstation OS that it is. Some of us need dangerously powerful tools. Most Mac users, however, do not — and don’t realize they’re using a dangerously powerful Unix workstation with a very friendly (literal) face.
* https://daringfireball.net/2026/10/apple_full_disk_access
What Gruber didn't realize is that Apple gives its engineers special internal tools that can bypass the restrictions we on the outside have to suffer.
I'm sure it's also the case that internal development macOS builds are compiled differently than public release builds. They basically have to be for Apple engineers to modify them during development.
We can disable SIP with a reboot to recovery and a single command. That doesn't seem like too high a bridge to cross and probably as good as any internal tool, if that isn't what they get in the first place.
But this eliminates all SIP protections, for example, as discussed in the article, preventing Meta Muse from reading your Messages db.
Muse doesn't need Full Disk Access if SIP is disabled.
And OP had SIP enabled, but his system still got compromised with a remote exploit.
> that's why Muse could get it even with SIP.
Both of these assumptions are mistaken.
I care more about the integrity of my personal privacy than I do about the integrity of the "system". The point of the system is to serve me.
> And OP had SIP enabled, but his system still got compromised with a remote exploit.
Nobody said that SIP magically prevents macOS bugs and security vulnerabilities.
No. The confusion here is that the Stratechery post combines multiple stories. There was a macOS screen sharing vulnerability, now fixed. The vulnerability existed even with SIP enabled, and that vulnerability is how Ben Thompson's Mac was hacked.
The question was, why did Thompson's Mac have the screen sharing port open to the internet, and that's when Thompson explained that the Mac was running an agent.
Coincidentally, Apple published a developer note on Friday about upcoming changes to Full Disk Access, which mentioned AI agents. Apple did not give any specific reason for this change, but presumably the inspiration was a very recent public controversy initiated by a journalist whose Messages database on macOS was read and uploaded by the Meta Muse app. Muse and similar AI apps request Full Disk Access to access all of the user's information. Without SIP, these apps would be able to suck up all of your data without permission.
Sandboxing full disk reads is orthogonal to what SIP actually provides. It's entirely possible for an unsandboxed binary to slurp your private data even with SIP enabled.
No? I'm not.
SIP is of course not a universal defense against every possible kind of attack, but did anyone ever expect it to be?
> Sandboxing full disk reads is orthogonal to what SIP actually provides.
No, because again, as I already said, disabling SIP also disables some TCC privacy protections.
> It's entirely possible for an unsandboxed binary to slurp your private data even with SIP enabled.
Not the data protected by TCC.
- Per-install boot security policies
- Custom kernel boot (kmutil configure-boot)
- Raw-image boot mode
- XNU source releases
- Disabling SIP
- Disabling the Signed System Volume
- Third-party kernel extensions
- Developer ID distribution and notarisation
- Gatekeeper "Open Anyway" override
- Hypervisor.framework
- Virtualization.framework
- Rosetta for Linux VMs
- Nested virtualisation
- macOS guest provisioning
- DiskImageKit
- Custom Virtio devices
- Containerization framework
I don't understand the purpose of your reply?
One of your examples is "Disabling SIP", but you're replying to a thread that has already been discussing this very topic, so it makes no sense to ask us "what about" that.
> - Third-party kernel extensions
Deprecated: https://developer.apple.com/support/kernel-extensions/
The issue is really the difficulty of using macOS as an expert user, and this has become significantly more difficult over the years. You mention "Developer ID distribution and notarisation", but both of those are actually restrictions that were added later to a previously open system. Notarization in particular has become a major pain for developers. Also "Gatekeeper Open Anyway override" has become significantly more difficult for users over the years.
to illustrate, counter to the HN narrative, they've actually done a lot to keep the platform open to hackers and hobbyists.
Sure, remove disabling SIP from the list, the others still stand and are quite compelling IMO.
Fair enough on the kernel extensions.
I take your point(s) but the doom about the Mac turning into iOS and the terminal being taken away is unfounded.
My comment that you replied to was not about the HN narrative. Thus, I still don't understand the purpose of your reply.
I got confused for a second how Claude Code and agents are related to this piece. Of course they aren't. Anyone with a half brain about securing their system would never run into any of this in the first place. Hiring Claude Code to do scanning every half an hour is such a waste of tokens.
The 'built a server that's going to run linux' line confused me. gOiNg tO? This boy didn't have 20 minutes to write a usb, shred the disks in live boot and install?
He has decent business takes on tech, the podcast/articles are worth paying attention to. The actual tech takes are probably too dumb for the hn audience, but you aren't the target audience.
I'm not sure why a writer needs swarms of agents in the first place.
1. 5900 was always known to be an extra unsafe port to have open
2. all ports should be assumed unsafe without explicit vetting
I'm assuming the argument being made is (2), but it really is a sad safe of affairs because use cases from time to time do involve having ports hot.
Or should things be taken one step further to *always* use a vpn or similar?
Yes. The vast majority of software is not hardened enough to be exposed to malicious actors. Any kind of control panel, device management interface, NAS/file sharing protocol, remote desktop protocols, and anything else that isn't explicitly designed to be a public service should be protected with a hardened outer layer like a VPN, SSH tunnel, or mutual TLS/client certificate authentication.
If he is roaming freely, he had no business leaving port 5900 world accessible.
If the burglar breaks in through the cat door but she wakes you to let you know, did the cat make you more safe?
https://www.youtube.com/watch?v=cKwKysk5rEw
But I’m worried because of this and other guardrails all of that will be impossible or much harder in the future.
If there’s some protections that prevent it from happening via localhost, it feels like the next step is to proxy through another host on the LAN.
Heck, I wonder if someone’s already written an app that’ll connect to VNC, look for any permission prompts, and approve. His agent software could just poke it anytime it thinks it’s blocked.
This was the most interesting part to me. I wonder what this divide looks like in the real world. I have a hard time believing this is true for everyone:
> I don’t want a different UI per app, when I have at my disposal true UI — the Universal Interface for everything digital.
It's insane what people will put up with to avoid just doing it properly on a real OS.
There is no Linux that will run on anyhing newer than M4 and even that is incomplete.
Better design in terms of resource isolation and control, too.
I use krunai. It is not quite as flexible as some people probably want (strongly linked to a specific non-systemd version of Debian 13), but there are many other options as well, such as Lume, Virtualization.framework, etc.
Much better than wrangling server code via Apple nonsense, and there are no real downsides after you've done the integration/deployment work once, assuming you are not building on some closed source thing that only runs on macOS.
I don't get this reaction to Apple making Full Disk Access more explicit. Whether they're "happy" or "sad" about agents doesn't seem responsive at all.
Kinda seems like whenever you spend 10 seconds thinking about the average user, social media gets angry. The quoted justification by Apple seems reasonable.
But I'm sure the day of the iOS-based iMac will come, and pandora's box will be opened. Businesses will love it, especially those with Kiosk use-cases, and not before long we will read everywhere (including here) how superior the security is to a Mac for everyday use...
But to back into it…. OpenClaw amd Muse and stuff give people a real reason to buy a Mac but Apple doesn’t like it.
Yeah, because a year down the road they might give the same people a reason to upgrade to another box, not from Apple.
Apple needs to ensure that they stand in the middle of every supplier relationship their customers have.
That's quite difficult when they don't provide direct value to both, so the natural conclusion is for Apple to present itself as a care-taker, the only one who prevents the user from taking any harm...
Get out! Desktop are not mobile devices and there is still need for them. Microsoft learnt this the hard way.
I think the barriers that exist depend on path dependence and other accidents of development. The laptop has a hinge and a trackpad that help you when you are flying on a plane. 2-in-1s drove stewardesses crazy because they couldn’t figure out if you had to stow them for takeoff. For that matter battery sizes are limited because of the needs of that industry which might seem justified if you live in NYC and can fly to London for what it less to costs to fly from my small town to NYC. Maybe if they’d invest in my community I’d care what they think but I think it’s unjust.
All the time I use a cheap plastic clip and a cheap Bluetooth mouse and keyboard and RDP into a monster computer from my tablet. If I have a real desk or table it’s fine, if you really have to put your laptop on your lap that hinge looks like genius. I’ll grant the 2-in-1 can be demoed at CES and the Bluetooth-based system can’t because they have too many devices in too small a space for Bluetooth to be reliable.
Even if I don’t have the mouse and keyboard I can still do a lot with the touchscreen.
The worst thing Win 8 revealed was that you could have the ‘windows’ keys on computer keyboards for almost 20 years and nobody noticed because…. It looks like an ad and people think anything that looks like an ad “just doesn’t work” (as opposed to “doesn’t just work”). If you were missing the start button you could just push that button but people treated that like putting their hand in the toilet.
I think that's the unification route they are most likely to take, hopefully along with a thinner/smaller MacBook design and built-in cellular.
They've taken so many swings at the iPad Pro (both hardware and software), and it has never been as good as the MacBook.
It does, it's called the MacBook Neo.
iPad sales have been rather stagnant in the last few years, while they made bank with their low-cost laptop. On a purely conceptual level I don't think they're gonna merge the two anytime soon, even if they will probably start sharing the very same logic board from their next revision.
businesses can already lock down your mac so you can't use it inappropriately.
I'm reminded of the guy who ran afoul of google, and all of a sudden all his google devices got forced software updates and started doing things.
it is sad, really.
https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2F...
I think the way this could work is by linking certain capabilities to MDM or a developer program membership. Organisations and people who really need it would still be able to get it but regular users would not.
In this case apple do this because Meta are abusing.
But as an end user, these are hollow words. As a consumer with Apple devices, I'm entrusting Apple to keep my computer protected from bad software, malicious or otherwise. You need to appreciate that you -- the software developer -- are not the good guy. We're not the same team. If you don't like your little sandbox, or if you resent having to ask for permission to go beyond it, that's a you problem, not a me problem.
As a software developer, I can see it from both sides. I wish more people did.
- Per-install boot security policies
- Custom kernel boot (kmutil configure-boot)
- Raw-image boot mode
- XNU source releases
- Disabling SIP
- Disabling the Signed System Volume
- Third-party kernel extensions
- Developer ID distribution and notarisation
- Gatekeeper "Open Anyway" override
- Hypervisor.framework
- Virtualization.framework
- Rosetta for Linux VMs
- Nested virtualisation
- macOS guest provisioning
- DiskImageKit
- Custom Virtio devices
- Containerization framework
Not to take away from your point too much - this is a significant amount of work that shows their current stance towards maintaining the mac as a premium development platform. But I imagine they will start to split this - lower cost SKUs will get the iOS-ified OS while "Pro" SKUs will get (some of) the above and can still install homebrew, to prevent a full developer revolt.
Techies will figure out how to "jailbreak" the lower SKUs to unlock the full experience and the amount of people that follow through with that will round to 0%. Tech businesses will buy the >$3k Pros for their devs.
"Everyone" will be "happy".
Can you blame them? Their managers cannot code, so they need something else that is "useful" to do. And the one thing they find useful is to increase revenue.
Exposing any port directly to the Internet is a huge risk these days—at minimum I'd put a very strong firewall in front, and unless it's serving the general public, switch to a non standard port. It's not much but would prevent the dumb automated scripts that operate on standard ports.
On the plus side, at least he didn't run the AI agent on the computer with all of his personal data.
However, this user made the choice to turn off the installation of system updates manually, based on a false assumption.
The entire iOS/MacOS schism already says enough.
They didn't renew Golden Gate's UNIX 03 certification this year:
https://www.opengroup.org/openbrand/register/
Or... you are operating your computer at the wrong level of abstraction. It was made for use by a real intelligence.
So has macOS. It’s just a matter that the agents don’t bother to use the existing permission layers.
It’s not like a VPN is some arcane knowledge. I guarantee Claude would have told him or practically yelled at him if he asked how he could have secured his mac exposed to the open internet.
Glad he actually acknowledged it and is getting tailscale or similar.
- Guy writing to you from Windows 11 with multiple Macbook Pros next to him.
Updates to Full Disk Access in macOS
https://news.ycombinator.com/item?id=49937631
If the TCC prompts could be dismissable some other way (e.g. via CLI with root permission) presumably he wouldn't have resorted to such measures. I sort of see the point, the lesson from Vista is that if you put up annoying obstacles people are going to the easiest workaround, bulldozing over them rather than putting up with them. People will end up disabling SIP or poking more hole if they don't have an easy way to bypass TCC stuff.
I put things behind a conventional firewall and then use a VPN for remote access.
What's worse is that a big part of the discussion here is just worshipping closed-source from a merely consumer perspective ('...wow! what a cool shiny UI feature to manage SSH keys for only 0.99$'), as if we were on the Tom's Guide forums. And some active members here even purchase browsers and seem to be very proud about it...
You are on the wrong site if you think that HN was ever a bastion of the hyper OSS mindset.
This is a site powered by and run by one of the arms of a startup incubator/investor. It has always been clear on that.
Just because it has “hacker” in the name doesn’t mean what you think it means.
From 2010 ... https://news.ycombinator.com/front?day=2010-10-04 that still looks similar (though I find it amusing that Ask HN: So what's new in the world of A.I.? https://news.ycombinator.com/item?id=1754134 is on the front page "... My prediction (heh pun intended) is that you see enormous changes in the field when processing by GPU's becomes much more available. There are some algorithms that are simply difficult to research because labs don't have access to fast enough machines. ...")
There's certainly been some broification and the various reddit exoduses have been shifting the average user a bit.
I do believe you've got your top color set to ff007f rather than ff6600 if you're forgetting what the site looked like then.
I've certainly thrown together more software and automations over the last year than I have in the other ~15 years since I started programming.
It's never been so fun.