▲ 163 ▼ Apple will update Macs to protect users from AI agents with full disk access (mashable.com) submitted 7 hours ago by TryingToBeGood@reddthat.com to c/technology@lemmy.world 32 comments fedilink hide all child comments
[–] DickHertz@lemmy.world 23 points 7 hours ago (21 children) Protect the user from themselves. permalink fedilink source hideshow 21 child comments replies: [–] Semi_Hemi_Demigod@lemmy.world 8 points 6 hours ago All of computing beyond programming with switches is “protecting the user from themselves.” “Why use a language? Aren’t you able to perfectly program in binary? I’m not going to waste time building something just because you’re stupid.” permalink fedilink source parent [+] dudeface@lemmy.world -7 points 6 hours ago* (9 children) MacOS is an open platform, I am glad you have to jump through a few hoops to put yourself in danger unlike windows permalink fedilink source parent hideshow 9 child comments replies: [–] voidsignal@lemmy.world 8 points 6 hours ago* (last edited 6 hours ago) (8 children) An "open" platform? Edit: Of course, here come the fanboys lol it's ok. I was one of you once. You'll grow. permalink fedilink source parent hideshow 8 child comments replies: [–] dudeface@lemmy.world -4 points 6 hours ago (7 children) I can run anything I want on it, what is closed about it? permalink fedilink source parent hideshow 7 child comments replies: [–] voidsignal@lemmy.world 10 points 6 hours ago (6 children) Being able to run a program on an OS is the bare minimum. Anything not signed by Daddy Apple, you have to add an exception. The moment the exceptions are no longer enough to "protect the user against themselves," you can't do a thing. Why? Because it's a fully closed, walled platform. It's like being in prison and being told you're free because you can walk in the yard. permalink fedilink source parent hideshow 6 child comments replies: [–] dudeface@lemmy.world -2 points 6 hours ago (5 children) Downloaded apps that are unsigned just need to be approved in settings It is clear you don’t know what you are talking about permalink fedilink source parent hideshow 5 child comments replies: [–] voidsignal@lemmy.world 3 points 6 hours ago* (4 children) You own the keys? It is actually extremely clear that you have no clue about what you are talking about. Re-read what I said. permalink fedilink source parent hideshow 4 child comments replies: [–] dudeface@lemmy.world -3 points 6 hours ago (3 children) I read it, none of makes sense to anyone that understands how computer work You argued I couldn’t run anything I wanted, I proved you can Go learn how an operating system works permalink fedilink source parent hideshow 3 child comments replies: [–] voidsignal@lemmy.world 9 points 6 hours ago* (2 children) No. I said the platform is closed. Not that you could not run anything. I argued that while you still CAN run whatever you want, that does not make it an open platform. Apple is one flag away from removing that right from you, and you won't be able to do jack shit about it if (when) they do. And thank you, but I know very well how a computer works. I also happen to know macOS very well too, and you, you just don't my friend. You understand marketing. It's ok. Not arguing more than that with a fanboy. I was one of you back in the days. You'll eventually understand. In the meantime, good luck. permalink fedilink source parent hideshow 2 child comments replies: [–] dudeface@lemmy.world -4 points 6 hours ago* (1 child) I saw your deleted comment You are acting dense on purpose and equating security controls to a walled garden You can disable the controls if you go in to system recovery mode (which will disable protections for the whole OS) Give it up permalink fedilink source parent hideshow 1 child comment replies: [–] voidsignal@lemmy.world 1 point 4 hours ago you are cute permalink fedilink source parent [–] finley@lemmy.zip 0 points 7 hours ago (9 children) So, you didn’t read the article permalink fedilink source parent hideshow 9 child comments replies: [–] Zak@lemmy.world 14 points 6 hours ago (3 children) I read the article, and I think DickHertz's comment is pretty much right. The article's example illustrates the point: For example, Inc. columnist Jason Aten recently discovered that Meta's Muse AI assistant somehow had synced his entire local Messages database and was using those messages as context for its tasks. Aten did not understand that the Messages database is stored on the disk (presumably) unencrypted and readable by anything with full disk access. He got a result he didn't want because he did not understand the implications of granting that permission, and Apple seeks to add more friction to the process to protect users from making that mistake. permalink fedilink source parent hideshow 3 child comments replies: [–] Grimy@lemmy.world 1 point 2 hours ago I think his point was that apple would abuse it, like they are already doing. Good thing if implemented properly, bad thing if implemented the apple way. permalink fedilink source parent [–] 4am@lemmy.zip 2 points 3 hours ago (1 child) Even if it was encrypted, it could be unlocked because with full disk access it can read the local private key, which probably doesn’t need a passphrase because it’s be a pain in the ass for the user to retype that every reboot or more Starting to see why you shouldn’t let any corporate AI loose on your daily driver yet? permalink fedilink source parent hideshow 1 child comment replies: [–] Zak@lemmy.world 1 point 1 hour ago Macs have a hardware secure enclave that apps can use to store keys where other apps can't access them. Apple itself does not seem to be making adequate use of it here. permalink fedilink source parent [–] DickHertz@lemmy.world 7 points 6 hours ago (4 children) Yeah, I read it. That’s kind of the point. Apple’s adding more guardrails because people will click Allow on damn near anything without thinking about what they’re actually giving access to. 🙄 permalink fedilink source parent hideshow 4 child comments replies: [–] Carl@anarchist.nexus 1 point 3 hours ago It’s also because Apple’s permissions are hilariously monolithic. A lot of their permissions are set up as an all-or-nothing event, instead of allowing granular control. Full disc access is a great example, where a user should be able to grant access to specific folders and files on an as-needed basis. But that’s not the default behavior. The default behavior is to just go “hey do you wanna give this app access to everything? permalink fedilink source parent [–] plantfanatic@sh.itjust.works -1 points 6 hours ago (2 children) Or an update adds it without your knowledge… permalink fedilink source parent hideshow 2 child comments replies: [–] Carl@anarchist.nexus 1 point 3 hours ago Apps can’t add permissions via an update. If an app adds a new feature with an update that requires a new permission, the user will be prompted the first time the app tries to use that new feature. permalink fedilink source parent [–] DickHertz@lemmy.world 9 points 6 hours ago Correct me if I’m wrong, but I don’t think an app could give itself Full Disk Access without the user explicitly approving it, even during an update. permalink fedilink source parent
[–] Semi_Hemi_Demigod@lemmy.world 8 points 6 hours ago All of computing beyond programming with switches is “protecting the user from themselves.” “Why use a language? Aren’t you able to perfectly program in binary? I’m not going to waste time building something just because you’re stupid.” permalink fedilink source parent
[+] dudeface@lemmy.world -7 points 6 hours ago* (9 children) MacOS is an open platform, I am glad you have to jump through a few hoops to put yourself in danger unlike windows permalink fedilink source parent hideshow 9 child comments replies: [–] voidsignal@lemmy.world 8 points 6 hours ago* (last edited 6 hours ago) (8 children) An "open" platform? Edit: Of course, here come the fanboys lol it's ok. I was one of you once. You'll grow. permalink fedilink source parent hideshow 8 child comments replies: [–] dudeface@lemmy.world -4 points 6 hours ago (7 children) I can run anything I want on it, what is closed about it? permalink fedilink source parent hideshow 7 child comments replies: [–] voidsignal@lemmy.world 10 points 6 hours ago (6 children) Being able to run a program on an OS is the bare minimum. Anything not signed by Daddy Apple, you have to add an exception. The moment the exceptions are no longer enough to "protect the user against themselves," you can't do a thing. Why? Because it's a fully closed, walled platform. It's like being in prison and being told you're free because you can walk in the yard. permalink fedilink source parent hideshow 6 child comments replies: [–] dudeface@lemmy.world -2 points 6 hours ago (5 children) Downloaded apps that are unsigned just need to be approved in settings It is clear you don’t know what you are talking about permalink fedilink source parent hideshow 5 child comments replies: [–] voidsignal@lemmy.world 3 points 6 hours ago* (4 children) You own the keys? It is actually extremely clear that you have no clue about what you are talking about. Re-read what I said. permalink fedilink source parent hideshow 4 child comments replies: [–] dudeface@lemmy.world -3 points 6 hours ago (3 children) I read it, none of makes sense to anyone that understands how computer work You argued I couldn’t run anything I wanted, I proved you can Go learn how an operating system works permalink fedilink source parent hideshow 3 child comments replies: [–] voidsignal@lemmy.world 9 points 6 hours ago* (2 children) No. I said the platform is closed. Not that you could not run anything. I argued that while you still CAN run whatever you want, that does not make it an open platform. Apple is one flag away from removing that right from you, and you won't be able to do jack shit about it if (when) they do. And thank you, but I know very well how a computer works. I also happen to know macOS very well too, and you, you just don't my friend. You understand marketing. It's ok. Not arguing more than that with a fanboy. I was one of you back in the days. You'll eventually understand. In the meantime, good luck. permalink fedilink source parent hideshow 2 child comments replies: [–] dudeface@lemmy.world -4 points 6 hours ago* (1 child) I saw your deleted comment You are acting dense on purpose and equating security controls to a walled garden You can disable the controls if you go in to system recovery mode (which will disable protections for the whole OS) Give it up permalink fedilink source parent hideshow 1 child comment replies: [–] voidsignal@lemmy.world 1 point 4 hours ago you are cute permalink fedilink source parent
[–] voidsignal@lemmy.world 8 points 6 hours ago* (last edited 6 hours ago) (8 children) An "open" platform? Edit: Of course, here come the fanboys lol it's ok. I was one of you once. You'll grow. permalink fedilink source parent hideshow 8 child comments replies: [–] dudeface@lemmy.world -4 points 6 hours ago (7 children) I can run anything I want on it, what is closed about it? permalink fedilink source parent hideshow 7 child comments replies: [–] voidsignal@lemmy.world 10 points 6 hours ago (6 children) Being able to run a program on an OS is the bare minimum. Anything not signed by Daddy Apple, you have to add an exception. The moment the exceptions are no longer enough to "protect the user against themselves," you can't do a thing. Why? Because it's a fully closed, walled platform. It's like being in prison and being told you're free because you can walk in the yard. permalink fedilink source parent hideshow 6 child comments replies: [–] dudeface@lemmy.world -2 points 6 hours ago (5 children) Downloaded apps that are unsigned just need to be approved in settings It is clear you don’t know what you are talking about permalink fedilink source parent hideshow 5 child comments replies: [–] voidsignal@lemmy.world 3 points 6 hours ago* (4 children) You own the keys? It is actually extremely clear that you have no clue about what you are talking about. Re-read what I said. permalink fedilink source parent hideshow 4 child comments replies: [–] dudeface@lemmy.world -3 points 6 hours ago (3 children) I read it, none of makes sense to anyone that understands how computer work You argued I couldn’t run anything I wanted, I proved you can Go learn how an operating system works permalink fedilink source parent hideshow 3 child comments replies: [–] voidsignal@lemmy.world 9 points 6 hours ago* (2 children) No. I said the platform is closed. Not that you could not run anything. I argued that while you still CAN run whatever you want, that does not make it an open platform. Apple is one flag away from removing that right from you, and you won't be able to do jack shit about it if (when) they do. And thank you, but I know very well how a computer works. I also happen to know macOS very well too, and you, you just don't my friend. You understand marketing. It's ok. Not arguing more than that with a fanboy. I was one of you back in the days. You'll eventually understand. In the meantime, good luck. permalink fedilink source parent hideshow 2 child comments replies: [–] dudeface@lemmy.world -4 points 6 hours ago* (1 child) I saw your deleted comment You are acting dense on purpose and equating security controls to a walled garden You can disable the controls if you go in to system recovery mode (which will disable protections for the whole OS) Give it up permalink fedilink source parent hideshow 1 child comment replies: [–] voidsignal@lemmy.world 1 point 4 hours ago you are cute permalink fedilink source parent
[–] dudeface@lemmy.world -4 points 6 hours ago (7 children) I can run anything I want on it, what is closed about it? permalink fedilink source parent hideshow 7 child comments replies: [–] voidsignal@lemmy.world 10 points 6 hours ago (6 children) Being able to run a program on an OS is the bare minimum. Anything not signed by Daddy Apple, you have to add an exception. The moment the exceptions are no longer enough to "protect the user against themselves," you can't do a thing. Why? Because it's a fully closed, walled platform. It's like being in prison and being told you're free because you can walk in the yard. permalink fedilink source parent hideshow 6 child comments replies: [–] dudeface@lemmy.world -2 points 6 hours ago (5 children) Downloaded apps that are unsigned just need to be approved in settings It is clear you don’t know what you are talking about permalink fedilink source parent hideshow 5 child comments replies: [–] voidsignal@lemmy.world 3 points 6 hours ago* (4 children) You own the keys? It is actually extremely clear that you have no clue about what you are talking about. Re-read what I said. permalink fedilink source parent hideshow 4 child comments replies: [–] dudeface@lemmy.world -3 points 6 hours ago (3 children) I read it, none of makes sense to anyone that understands how computer work You argued I couldn’t run anything I wanted, I proved you can Go learn how an operating system works permalink fedilink source parent hideshow 3 child comments replies: [–] voidsignal@lemmy.world 9 points 6 hours ago* (2 children) No. I said the platform is closed. Not that you could not run anything. I argued that while you still CAN run whatever you want, that does not make it an open platform. Apple is one flag away from removing that right from you, and you won't be able to do jack shit about it if (when) they do. And thank you, but I know very well how a computer works. I also happen to know macOS very well too, and you, you just don't my friend. You understand marketing. It's ok. Not arguing more than that with a fanboy. I was one of you back in the days. You'll eventually understand. In the meantime, good luck. permalink fedilink source parent hideshow 2 child comments replies: [–] dudeface@lemmy.world -4 points 6 hours ago* (1 child) I saw your deleted comment You are acting dense on purpose and equating security controls to a walled garden You can disable the controls if you go in to system recovery mode (which will disable protections for the whole OS) Give it up permalink fedilink source parent hideshow 1 child comment replies: [–] voidsignal@lemmy.world 1 point 4 hours ago you are cute permalink fedilink source parent
[–] voidsignal@lemmy.world 10 points 6 hours ago (6 children) Being able to run a program on an OS is the bare minimum. Anything not signed by Daddy Apple, you have to add an exception. The moment the exceptions are no longer enough to "protect the user against themselves," you can't do a thing. Why? Because it's a fully closed, walled platform. It's like being in prison and being told you're free because you can walk in the yard. permalink fedilink source parent hideshow 6 child comments replies: [–] dudeface@lemmy.world -2 points 6 hours ago (5 children) Downloaded apps that are unsigned just need to be approved in settings It is clear you don’t know what you are talking about permalink fedilink source parent hideshow 5 child comments replies: [–] voidsignal@lemmy.world 3 points 6 hours ago* (4 children) You own the keys? It is actually extremely clear that you have no clue about what you are talking about. Re-read what I said. permalink fedilink source parent hideshow 4 child comments replies: [–] dudeface@lemmy.world -3 points 6 hours ago (3 children) I read it, none of makes sense to anyone that understands how computer work You argued I couldn’t run anything I wanted, I proved you can Go learn how an operating system works permalink fedilink source parent hideshow 3 child comments replies: [–] voidsignal@lemmy.world 9 points 6 hours ago* (2 children) No. I said the platform is closed. Not that you could not run anything. I argued that while you still CAN run whatever you want, that does not make it an open platform. Apple is one flag away from removing that right from you, and you won't be able to do jack shit about it if (when) they do. And thank you, but I know very well how a computer works. I also happen to know macOS very well too, and you, you just don't my friend. You understand marketing. It's ok. Not arguing more than that with a fanboy. I was one of you back in the days. You'll eventually understand. In the meantime, good luck. permalink fedilink source parent hideshow 2 child comments replies: [–] dudeface@lemmy.world -4 points 6 hours ago* (1 child) I saw your deleted comment You are acting dense on purpose and equating security controls to a walled garden You can disable the controls if you go in to system recovery mode (which will disable protections for the whole OS) Give it up permalink fedilink source parent hideshow 1 child comment replies: [–] voidsignal@lemmy.world 1 point 4 hours ago you are cute permalink fedilink source parent
[–] dudeface@lemmy.world -2 points 6 hours ago (5 children) Downloaded apps that are unsigned just need to be approved in settings It is clear you don’t know what you are talking about permalink fedilink source parent hideshow 5 child comments replies: [–] voidsignal@lemmy.world 3 points 6 hours ago* (4 children) You own the keys? It is actually extremely clear that you have no clue about what you are talking about. Re-read what I said. permalink fedilink source parent hideshow 4 child comments replies: [–] dudeface@lemmy.world -3 points 6 hours ago (3 children) I read it, none of makes sense to anyone that understands how computer work You argued I couldn’t run anything I wanted, I proved you can Go learn how an operating system works permalink fedilink source parent hideshow 3 child comments replies: [–] voidsignal@lemmy.world 9 points 6 hours ago* (2 children) No. I said the platform is closed. Not that you could not run anything. I argued that while you still CAN run whatever you want, that does not make it an open platform. Apple is one flag away from removing that right from you, and you won't be able to do jack shit about it if (when) they do. And thank you, but I know very well how a computer works. I also happen to know macOS very well too, and you, you just don't my friend. You understand marketing. It's ok. Not arguing more than that with a fanboy. I was one of you back in the days. You'll eventually understand. In the meantime, good luck. permalink fedilink source parent hideshow 2 child comments replies: [–] dudeface@lemmy.world -4 points 6 hours ago* (1 child) I saw your deleted comment You are acting dense on purpose and equating security controls to a walled garden You can disable the controls if you go in to system recovery mode (which will disable protections for the whole OS) Give it up permalink fedilink source parent hideshow 1 child comment replies: [–] voidsignal@lemmy.world 1 point 4 hours ago you are cute permalink fedilink source parent
[–] voidsignal@lemmy.world 3 points 6 hours ago* (4 children) You own the keys? It is actually extremely clear that you have no clue about what you are talking about. Re-read what I said. permalink fedilink source parent hideshow 4 child comments replies: [–] dudeface@lemmy.world -3 points 6 hours ago (3 children) I read it, none of makes sense to anyone that understands how computer work You argued I couldn’t run anything I wanted, I proved you can Go learn how an operating system works permalink fedilink source parent hideshow 3 child comments replies: [–] voidsignal@lemmy.world 9 points 6 hours ago* (2 children) No. I said the platform is closed. Not that you could not run anything. I argued that while you still CAN run whatever you want, that does not make it an open platform. Apple is one flag away from removing that right from you, and you won't be able to do jack shit about it if (when) they do. And thank you, but I know very well how a computer works. I also happen to know macOS very well too, and you, you just don't my friend. You understand marketing. It's ok. Not arguing more than that with a fanboy. I was one of you back in the days. You'll eventually understand. In the meantime, good luck. permalink fedilink source parent hideshow 2 child comments replies: [–] dudeface@lemmy.world -4 points 6 hours ago* (1 child) I saw your deleted comment You are acting dense on purpose and equating security controls to a walled garden You can disable the controls if you go in to system recovery mode (which will disable protections for the whole OS) Give it up permalink fedilink source parent hideshow 1 child comment replies: [–] voidsignal@lemmy.world 1 point 4 hours ago you are cute permalink fedilink source parent
[–] dudeface@lemmy.world -3 points 6 hours ago (3 children) I read it, none of makes sense to anyone that understands how computer work You argued I couldn’t run anything I wanted, I proved you can Go learn how an operating system works permalink fedilink source parent hideshow 3 child comments replies: [–] voidsignal@lemmy.world 9 points 6 hours ago* (2 children) No. I said the platform is closed. Not that you could not run anything. I argued that while you still CAN run whatever you want, that does not make it an open platform. Apple is one flag away from removing that right from you, and you won't be able to do jack shit about it if (when) they do. And thank you, but I know very well how a computer works. I also happen to know macOS very well too, and you, you just don't my friend. You understand marketing. It's ok. Not arguing more than that with a fanboy. I was one of you back in the days. You'll eventually understand. In the meantime, good luck. permalink fedilink source parent hideshow 2 child comments replies: [–] dudeface@lemmy.world -4 points 6 hours ago* (1 child) I saw your deleted comment You are acting dense on purpose and equating security controls to a walled garden You can disable the controls if you go in to system recovery mode (which will disable protections for the whole OS) Give it up permalink fedilink source parent hideshow 1 child comment replies: [–] voidsignal@lemmy.world 1 point 4 hours ago you are cute permalink fedilink source parent
[–] voidsignal@lemmy.world 9 points 6 hours ago* (2 children) No. I said the platform is closed. Not that you could not run anything. I argued that while you still CAN run whatever you want, that does not make it an open platform. Apple is one flag away from removing that right from you, and you won't be able to do jack shit about it if (when) they do. And thank you, but I know very well how a computer works. I also happen to know macOS very well too, and you, you just don't my friend. You understand marketing. It's ok. Not arguing more than that with a fanboy. I was one of you back in the days. You'll eventually understand. In the meantime, good luck. permalink fedilink source parent hideshow 2 child comments replies: [–] dudeface@lemmy.world -4 points 6 hours ago* (1 child) I saw your deleted comment You are acting dense on purpose and equating security controls to a walled garden You can disable the controls if you go in to system recovery mode (which will disable protections for the whole OS) Give it up permalink fedilink source parent hideshow 1 child comment replies: [–] voidsignal@lemmy.world 1 point 4 hours ago you are cute permalink fedilink source parent
[–] dudeface@lemmy.world -4 points 6 hours ago* (1 child) I saw your deleted comment You are acting dense on purpose and equating security controls to a walled garden You can disable the controls if you go in to system recovery mode (which will disable protections for the whole OS) Give it up permalink fedilink source parent hideshow 1 child comment replies: [–] voidsignal@lemmy.world 1 point 4 hours ago you are cute permalink fedilink source parent
[–] finley@lemmy.zip 0 points 7 hours ago (9 children) So, you didn’t read the article permalink fedilink source parent hideshow 9 child comments replies: [–] Zak@lemmy.world 14 points 6 hours ago (3 children) I read the article, and I think DickHertz's comment is pretty much right. The article's example illustrates the point: For example, Inc. columnist Jason Aten recently discovered that Meta's Muse AI assistant somehow had synced his entire local Messages database and was using those messages as context for its tasks. Aten did not understand that the Messages database is stored on the disk (presumably) unencrypted and readable by anything with full disk access. He got a result he didn't want because he did not understand the implications of granting that permission, and Apple seeks to add more friction to the process to protect users from making that mistake. permalink fedilink source parent hideshow 3 child comments replies: [–] Grimy@lemmy.world 1 point 2 hours ago I think his point was that apple would abuse it, like they are already doing. Good thing if implemented properly, bad thing if implemented the apple way. permalink fedilink source parent [–] 4am@lemmy.zip 2 points 3 hours ago (1 child) Even if it was encrypted, it could be unlocked because with full disk access it can read the local private key, which probably doesn’t need a passphrase because it’s be a pain in the ass for the user to retype that every reboot or more Starting to see why you shouldn’t let any corporate AI loose on your daily driver yet? permalink fedilink source parent hideshow 1 child comment replies: [–] Zak@lemmy.world 1 point 1 hour ago Macs have a hardware secure enclave that apps can use to store keys where other apps can't access them. Apple itself does not seem to be making adequate use of it here. permalink fedilink source parent [–] DickHertz@lemmy.world 7 points 6 hours ago (4 children) Yeah, I read it. That’s kind of the point. Apple’s adding more guardrails because people will click Allow on damn near anything without thinking about what they’re actually giving access to. 🙄 permalink fedilink source parent hideshow 4 child comments replies: [–] Carl@anarchist.nexus 1 point 3 hours ago It’s also because Apple’s permissions are hilariously monolithic. A lot of their permissions are set up as an all-or-nothing event, instead of allowing granular control. Full disc access is a great example, where a user should be able to grant access to specific folders and files on an as-needed basis. But that’s not the default behavior. The default behavior is to just go “hey do you wanna give this app access to everything? permalink fedilink source parent [–] plantfanatic@sh.itjust.works -1 points 6 hours ago (2 children) Or an update adds it without your knowledge… permalink fedilink source parent hideshow 2 child comments replies: [–] Carl@anarchist.nexus 1 point 3 hours ago Apps can’t add permissions via an update. If an app adds a new feature with an update that requires a new permission, the user will be prompted the first time the app tries to use that new feature. permalink fedilink source parent [–] DickHertz@lemmy.world 9 points 6 hours ago Correct me if I’m wrong, but I don’t think an app could give itself Full Disk Access without the user explicitly approving it, even during an update. permalink fedilink source parent
[–] Zak@lemmy.world 14 points 6 hours ago (3 children) I read the article, and I think DickHertz's comment is pretty much right. The article's example illustrates the point: For example, Inc. columnist Jason Aten recently discovered that Meta's Muse AI assistant somehow had synced his entire local Messages database and was using those messages as context for its tasks. Aten did not understand that the Messages database is stored on the disk (presumably) unencrypted and readable by anything with full disk access. He got a result he didn't want because he did not understand the implications of granting that permission, and Apple seeks to add more friction to the process to protect users from making that mistake. permalink fedilink source parent hideshow 3 child comments replies: [–] Grimy@lemmy.world 1 point 2 hours ago I think his point was that apple would abuse it, like they are already doing. Good thing if implemented properly, bad thing if implemented the apple way. permalink fedilink source parent [–] 4am@lemmy.zip 2 points 3 hours ago (1 child) Even if it was encrypted, it could be unlocked because with full disk access it can read the local private key, which probably doesn’t need a passphrase because it’s be a pain in the ass for the user to retype that every reboot or more Starting to see why you shouldn’t let any corporate AI loose on your daily driver yet? permalink fedilink source parent hideshow 1 child comment replies: [–] Zak@lemmy.world 1 point 1 hour ago Macs have a hardware secure enclave that apps can use to store keys where other apps can't access them. Apple itself does not seem to be making adequate use of it here. permalink fedilink source parent
[–] Grimy@lemmy.world 1 point 2 hours ago I think his point was that apple would abuse it, like they are already doing. Good thing if implemented properly, bad thing if implemented the apple way. permalink fedilink source parent
[–] 4am@lemmy.zip 2 points 3 hours ago (1 child) Even if it was encrypted, it could be unlocked because with full disk access it can read the local private key, which probably doesn’t need a passphrase because it’s be a pain in the ass for the user to retype that every reboot or more Starting to see why you shouldn’t let any corporate AI loose on your daily driver yet? permalink fedilink source parent hideshow 1 child comment replies: [–] Zak@lemmy.world 1 point 1 hour ago Macs have a hardware secure enclave that apps can use to store keys where other apps can't access them. Apple itself does not seem to be making adequate use of it here. permalink fedilink source parent
[–] Zak@lemmy.world 1 point 1 hour ago Macs have a hardware secure enclave that apps can use to store keys where other apps can't access them. Apple itself does not seem to be making adequate use of it here. permalink fedilink source parent
[–] DickHertz@lemmy.world 7 points 6 hours ago (4 children) Yeah, I read it. That’s kind of the point. Apple’s adding more guardrails because people will click Allow on damn near anything without thinking about what they’re actually giving access to. 🙄 permalink fedilink source parent hideshow 4 child comments replies: [–] Carl@anarchist.nexus 1 point 3 hours ago It’s also because Apple’s permissions are hilariously monolithic. A lot of their permissions are set up as an all-or-nothing event, instead of allowing granular control. Full disc access is a great example, where a user should be able to grant access to specific folders and files on an as-needed basis. But that’s not the default behavior. The default behavior is to just go “hey do you wanna give this app access to everything? permalink fedilink source parent [–] plantfanatic@sh.itjust.works -1 points 6 hours ago (2 children) Or an update adds it without your knowledge… permalink fedilink source parent hideshow 2 child comments replies: [–] Carl@anarchist.nexus 1 point 3 hours ago Apps can’t add permissions via an update. If an app adds a new feature with an update that requires a new permission, the user will be prompted the first time the app tries to use that new feature. permalink fedilink source parent [–] DickHertz@lemmy.world 9 points 6 hours ago Correct me if I’m wrong, but I don’t think an app could give itself Full Disk Access without the user explicitly approving it, even during an update. permalink fedilink source parent
[–] Carl@anarchist.nexus 1 point 3 hours ago It’s also because Apple’s permissions are hilariously monolithic. A lot of their permissions are set up as an all-or-nothing event, instead of allowing granular control. Full disc access is a great example, where a user should be able to grant access to specific folders and files on an as-needed basis. But that’s not the default behavior. The default behavior is to just go “hey do you wanna give this app access to everything? permalink fedilink source parent
[–] plantfanatic@sh.itjust.works -1 points 6 hours ago (2 children) Or an update adds it without your knowledge… permalink fedilink source parent hideshow 2 child comments replies: [–] Carl@anarchist.nexus 1 point 3 hours ago Apps can’t add permissions via an update. If an app adds a new feature with an update that requires a new permission, the user will be prompted the first time the app tries to use that new feature. permalink fedilink source parent [–] DickHertz@lemmy.world 9 points 6 hours ago Correct me if I’m wrong, but I don’t think an app could give itself Full Disk Access without the user explicitly approving it, even during an update. permalink fedilink source parent
[–] Carl@anarchist.nexus 1 point 3 hours ago Apps can’t add permissions via an update. If an app adds a new feature with an update that requires a new permission, the user will be prompted the first time the app tries to use that new feature. permalink fedilink source parent
[–] DickHertz@lemmy.world 9 points 6 hours ago Correct me if I’m wrong, but I don’t think an app could give itself Full Disk Access without the user explicitly approving it, even during an update. permalink fedilink source parent