We give developers powerful APIs to build incredible capabilities into their apps for Apple products, backed by a set of controls designed to protect users’ private data. Full Disk Access largely sidesteps these…

138 points•notfirstpost•about 8 hours ago•81 comments•

81 comments

liuliuabout 3 hours ago
I don’t quite understand why people complains this is bad for AI agents. Local Code (https://releases.drawthings.ai/p/public-beta-of-local-code-b...) doesn’t require full disk access, when you ask the agent to deal with some files it doesn’t have access to, the built-in ‘permit’ tool will trigger the OS folder grant interface and that information will be recorded both by Apple and by the app so it can be revoked later if you want. That allows you to not give full disk access to the app to be useful.
wpmabout 3 hours ago
If anything in a world with agents, these TCC dialogs just need to have an "allow once", just like Location Services has on iOS, and just like most harnesses have, a la "Do you want to allow $AGENT to run the following command?" A. Yes. B. Yes and don't ask for $command, C. No but instead just asking "Do you want to allow Claude Desktop access to files and folders on your Desktop?" A. Once. B. Always C. No

I think the issue comes in with terminal emulators and CLI harnesses. TCC permissions are inherited from the "responsible" process, so if you grant Terminal.app or ghostty.app FDA, you've granted zsh or bash or python or any goddamned thing you can run in a shell FDA.

moecablesabout 7 hours ago
IMHO, it's good to add more specific controls for this. After reading this, I went and checked my list of app with full disk access:

- Ghostty (fine, it's my terminal)

- Alfred (fine, I use it for searching everywhere)

Then I have a few turned off:

- Spotify (why does it need full disk access) ??

- Gemini (nope, don't need it to know everything about my computer)

coderbantsabout 6 hours ago
Terminal is a significant risk though and I’d still really like to see macOS improve the APIs around filesystem access.

Granting terminal full disk access grants arbitrary scripts full disk access. There’s a lot you can do with ACLs and the permissions system, but it’s not reflected in the UI for settings.

Then there’s allowing access to documents, downloads, desktop, external disks. This should really allow the user to select a path or paths for applications, because these options are way too broad (especially external disks).

jshierabout 4 hours ago
This is why I use Terminal as my primary terminal, and iTerm as my AI terminal. iTerm gets no permissions, I move specific things to Terminal to do it. Plus I can then style them to optimize for the different usages. And iTerm has better harness hooks anyway.

I would still like to see not only more granular permissions, but single use permissions. Once I grant iTerm access to Documents for whatever reason, it always has such permission. I would be nice to limit that to a single use, or a single harness session.

ashishbabout 4 hours ago
> Granting terminal full disk access grants arbitrary scripts full disk access.

Indeed, I run all dev tools including coding agents inside sandbox now

https://github.com/ashishb/amazing-sandbox

king_geedorahabout 1 hour ago
Spotify has (had? I no longer use it) a feature that would allow you to make local media available as part of your library anywhere so long as your machine was on and connected to the internet. I would imagine that feature requires disk access under these sandbox / permission models.

Edit: I should say, the model it was created with (select a folder, all media in that folder is mirrored) requires such permissions. One could imagine designs that don’t.

0c3ca83about 3 hours ago
- Ghostty (fine, it's my terminal)

But your terminal shouldn't be accessing any files; you just need to be able to launch /bin/zsh or whatever you use as your shell. The shell needs to be able to access files, but its container doesn't.

Of course, you could go farther. For example, on OpenBSD, even /bin/ksh has been somewhat sandboxed; it can see most of the file system, but the things it can do have been limited:

  if (pledge("stdio rpath wpath cpath fattr flock getpw proc "
      "exec tty id", NULL) == -1) {
rolosaabout 3 hours ago
If you try to ls / for example it's going to pop up a request to access your disk, multiple times. It's rather annoying.
saagarjhaabout 3 hours ago
macOS attributes shell commands to their parent app bundle.
smcleodabout 3 hours ago
I wouldn't allow your terminal full disk access, that's quite a risk vector.
mrkpdlabout 7 hours ago
I would like the ability to see which specific folders I have granted access to on an app by app basis. And edit. It’s not clear to me how you revoke an app’s individual folder access after you have granted it.
kccqzyabout 7 hours ago
I have been wanting this for years.

For those who haven’t heard of this, sandboxed apps can request access to a file or folder and persist such access using a security-scoped bookmark. The user however does not know whether the app chooses to persist this bookmark or not; in other words the user does not know whether in each case they are granting a one-time access or persistent access.

lapcatabout 7 hours ago
This is unrelated to Full Disk Access, though.

There are already folder-specific permissions for every app, including non-sandboxed apps: Desktop, Documents, Downloads. FDA is "everything else". The user has to specifically grant each of those permissions via a system dialog.

With sandboxed apps, you grant access to a file outside the sandbox via a system dialog, open or save. But with non-sandboxed apps, if there were separate permissions for each specific folder, there would have to be separate permission dialogs for each of those folders, and then macOS would become even more of a permissions dialog hell than it already is.

post_breakabout 7 hours ago
One update away to revoking Full Disk Access in the future. This commercial has come full circle: https://www.youtube.com/watch?v=VuqZ8AqmLPY
jeremyjhabout 7 hours ago
You could say that about anything, in any OS. Windows is one update away from insulting the user whenever they login. MacOS is one update away from mining crypto for Apple. Android is one update away from sending spam to all your contacts.
DaiPlusPlusabout 2 hours ago
I think it’s the threshold of them getting-away-with-it without too many people wielding pitchforks.
etatesterabout 7 hours ago
Please do. Too many applications have too much access. Why do people not realize they installed literal Trojan horses that visit websites and execute commands found on them (prompt injection)?
steve-atx-7600about 7 hours ago
Need some Vaseline for your slope?
cungabout 7 hours ago
Hah! I had forgotten this ad. Using a mac nowadays is definitely just like Windows Vista in this ad.
nozzlegearabout 4 hours ago
Inshallah
Kim_Bruningabout 7 hours ago
Am I getting old? "full disk access" used to be something that's supposed to be normal; if you're the owner of the machine.
concindsabout 7 hours ago
> Am I getting old?

I think so.

I don't know where this "ownership" debate came from. My ownership of my machine depends on strict, broad + fine grained control over what third-party devs (who are not me) get to do with my machine. Our interests are incompatible and hostile, in an era where most "native apps" ship analytics and marketing SDKs, or are videcoded. If macOS didn't offer these controls I would run every apps in a browser where it's sandboxed. This isn't the 90s.

This change is a reaction to a viral story from a tech reporter who shipped all his texts to Meta without meaning to, which tells you there's a consent and transparency issue for nontechnical users. I don't think anyone in the industry has figured out a proper solution. Unless you never interact with nontechnical people, it impacts your privacy indirectly no matter what you do. Though as technical user I hope we can get more fine-grained control and auditing.

etatesterabout 7 hours ago
This isn't 1980 anymore. The internet is super hostile and everyone wants to extract data. You're still free to allow every app on your computer full access, I won't. I am very glad that none of the hundreds of apps installed across my phone and Mac can access my photos and cameras without permission.
DaiPlusPlusabout 2 hours ago
My concern is that eventually Apple will require all apps (including non-App Store) to be specially approved by Apple in order to get full-disk-access, even if the end-user wants to allow it; like how there are no third-party iPhone/iPad backup apps.
jeremyjhabout 7 hours ago
I’m 50 and I think it’s crazy we ever thought it was acceptable to give every app you run full access to all the files on your computer by default.
VCFundedGenYerabout 7 hours ago
macOS has been revoking access to stuff like this over the past decade. Things like unfettered access to modifying the OS went away with Gatekeeper and System Integrity Protection. "root" access is no longer true root on any Mac, and the user is treated like a prisoner. The UAC-esque prompts that come up in macOS would make Vista-era MS so jealous.
littlecranky67about 7 hours ago
root access is also no longer true root access on a lot of linux distros that are immutable, and container-esque like interfaces such as namespaces + cgroups also limit roots power.
GeekyBearabout 7 hours ago
TFA:

> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding.

If you think an app from (say) Facebook can be trusted with unrestricted access to your whole machine, you're at least a bit naive.

Read the full thread on Hacker News →

Related stories