40 comments
Permissionless action is about to skyrocket as an issue, but this particular scenario strikes me as incredibly unlikely. Would be interested to know if Muse can provide more meaningful data provenance/logs.
Scanning iMessage dbs as a passive part of full disk access (and not a messages grant), if true, is a little sketchy, regardless.
Even as a technical person, it's not trivial to sandbox agents correctly. The fact that an mis-clicked permission popup could give an agent unrestricted access to a user's disk is a massive risk vector in the hands of lay people who barely understand how any of this works.
So much of current security depends on the model of tying access control to a user account. A lot has to be re-thought in terms of how to grant access to an agent working on the user's behalf, in a way that doesn't make it completely useless, and also doesn't require every user to become a sysadmin managing fine-grained agent permissions manually.
I think the problem is that LLM providers are dis-incentivized from pursuing it because their ethos is gobbling up any and all data they can get.
> Oops, we accidentally yoinked your personal documents, photos, and videos and they’re now swimming in our model’s data ocean! We’re sorrrry, oh well let’s move on.
It’s up to the users to use tools that enforce security/privacy. Open source harnesses like pi.dev seem like a good path forward to me
I say that from coding experience. You don’t want to approve 100 windows to get a task done. In the end the only “sane” solution for my setup was a dedicated machine just for the agent with Bitwarden for secrets and full access/yolo mode.
If you are concerned about the agent deleting everything make sure you have a process backing up the git repositories at least to a separate service/hosting and that’s it…for now.
So the solution is to have backups and a way to restore data…
This is all amateur hour shenanigans.
I’d argue this is a five alarm fire for macOS and Meta simply exploited it.
Open your terminal app and run /Applications/Firefox.app/Contents/MacOS/firefox
This opens a normal-looking Firefox window, but it has whatever permissions you gave to the terminal, which likely has Full Disk Access.
It’s insane.
This used to work when you could trust the software you ran on your system to have access to everything you have access to on your computer. I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.
Best solution is to simply not run software made by blatantly untrustworthy developers. Second best solution would be to run such software as a severely sandboxed user who basically doesn't have access to anything important on your system.
This is not at all how it works on macOS, which is what is being discussed in the original post. There are a million different things that require per-app explicit opt-in permissions. This is a case of user error.
> I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.
Agreed, but what can you do about your OS vendor?
Read the full thread on Hacker News →
Related stories
- The Verge · 0 points · 2 days ago
- Can you forget how you feel about Meta?theverge.comThe Verge · 0 points · 9 days ago
- The Verge · 0 points · 4 days ago
- The Verge · 0 points · about 9 hours ago
- Can John Ternus find Apple’s next big thing?theverge.comThe Verge · 0 points · 9 days ago
- Hacker News · 73 points · 8 days ago