40 comments

jkingsman1 day ago
I'm no evangelist for LLM assistants, but this seems incredibly improbable and represents a failure of MacOS security if so. If full disk access isn't granted, Mac blocks it from the Downloads folder, to say nothing of actually sensitive paths. I would expect a far more likely case of an accidentally granted permission on another device or a permission that was on and then turned off.

Permissionless action is about to skyrocket as an issue, but this particular scenario strikes me as incredibly unlikely. Would be interested to know if Muse can provide more meaningful data provenance/logs.

Scanning iMessage dbs as a passive part of full disk access (and not a messages grant), if true, is a little sketchy, regardless.

skohan1 day ago
Agent sandboxing/access control is one of the biggest problems to be solved before this technology really should go mainstream.

Even as a technical person, it's not trivial to sandbox agents correctly. The fact that an mis-clicked permission popup could give an agent unrestricted access to a user's disk is a massive risk vector in the hands of lay people who barely understand how any of this works.

So much of current security depends on the model of tying access control to a user account. A lot has to be re-thought in terms of how to grant access to an agent working on the user's behalf, in a way that doesn't make it completely useless, and also doesn't require every user to become a sysadmin managing fine-grained agent permissions manually.

robby_w_g1 day ago
I think sandboxing could be solved if effort was put into it. Webassembly seems like a great way to enforce data and execution boundaries for an LLM, for example.

I think the problem is that LLM providers are dis-incentivized from pursuing it because their ethos is gobbling up any and all data they can get.

> Oops, we accidentally yoinked your personal documents, photos, and videos and they’re now swimming in our model’s data ocean! We’re sorrrry, oh well let’s move on.

It’s up to the users to use tools that enforce security/privacy. Open source harnesses like pi.dev seem like a good path forward to me

thefounder1 day ago
something tell me that the vast majority of people will give all the permissions the agent ask but even more look for a bypass/yolo permission.

I say that from coding experience. You don’t want to approve 100 windows to get a task done. In the end the only “sane” solution for my setup was a dedicated machine just for the agent with Bitwarden for secrets and full access/yolo mode.

If you are concerned about the agent deleting everything make sure you have a process backing up the git repositories at least to a separate service/hosting and that’s it…for now.

So the solution is to have backups and a way to restore data…

SamInTheShell1 day ago
It's already solved. I have two git repos proving these companies can fix the problems. The fact this continues just proves they don't care. In one project I literally containerize CLI coding tools, it works. You might say "sure, but network." I literally wrote a desktop app harness that you can toggle the network on/off too.

This is all amateur hour shenanigans.

kstrauser1 day ago
Nothing you said was wrong, but I can’t imagine giving Meta the benefit of the doubt on, well, anything. Fool me once, shame on you. Fool me 137 times…
iamacyborg1 day ago
The story from Hunterbrook is also pretty crazy with Muse having much more access to Meta’s social graphs than I suspect most users would hope.

https://hntrbrk.com/breaking-news/muse-doxxing

SwabbyNat741 day ago
And we're surprised by this?? Its Meta after all. The social graph data we had access to in the social games we built back in 2009/2010 was literally insane by todays standards of security. They've just gotten better at hiding it.
iamacyborg1 day ago
Post-Cambridge Analytica, yeah, a smidge surprised.
I think what’s more alarming is the macOS nannying UAC-like toggles to block disk access and other “protections” are apparently all UX reducing flash and no actual functionality.

I’d argue this is a five alarm fire for macOS and Meta simply exploited it.

PaulHoule1 day ago
Personally that stuff drives me up the wall, it's the Mac wanting to become the iPhone and close off everything but the App Economy. They'll geofence XCode to the Bay Area or something so only "professionals" can develop software and eventually ban web browsers.
dec0dedab0de1 day ago
I think we need more granular permissions, and built in ways to trick apps into thinking they have permissions they do not.
drdexebtjl1 day ago
A lot of comments saying this must not have happened because of macOS app permissions. That system is completely broken.

Open your terminal app and run /Applications/Firefox.app/Contents/MacOS/firefox

This opens a normal-looking Firefox window, but it has whatever permissions you gave to the terminal, which likely has Full Disk Access.

It’s insane.

How is this possible? Apple messages are just free for anyone to read?
macOS’s permission model doesn’t work correctly. The only thing it’s good at is allotting the user with consent prompts that don’t stop anything.
ryandrake1 day ago
At least on Unix-like systems, if it's free for you to read, then it's free for any process you run as you to read. Sure, macOS has grafted its own weird "permissions" layer on top of the existing OS level permissions, but at the end of the day, when you run an app on Unix, you're allowing it to act as you, with all the powers your user has.

This used to work when you could trust the software you ran on your system to have access to everything you have access to on your computer. I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.

Best solution is to simply not run software made by blatantly untrustworthy developers. Second best solution would be to run such software as a severely sandboxed user who basically doesn't have access to anything important on your system.

anonymousDan1 day ago
My mental model is to treat AI agents running on your system as a form of malware that is running in a honeypot you control. You don't want to just get rid of it as you want to observe its behaviour (in the case of malware) or hopefully do something useful (AI). But you certainly shouldn't assume it won't do anything bad to your system.
daishi551 day ago
> at the end of the day, when you run an app on Unix, you're allowing it to act as you with all the powers your user has.

This is not at all how it works on macOS, which is what is being discussed in the original post. There are a million different things that require per-app explicit opt-in permissions. This is a case of user error.

graemep1 day ago
I do not know about all Unix like OSes, but Linux has sandboxes you can run as you main user. Not as safe as running as a separate user and sandboxing, or running in a VM, but reasonably solid.

> I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.

Agreed, but what can you do about your OS vendor?

daishi551 day ago
It’s not possible. User error lol

Read the full thread on Hacker News →

Related stories