Updates to Full Disk Access in macOS
9 points by videah
9 points by videah
Can I just tap out of using AI agents altogether, and go back to the "Full Disk Access" setup from Mac OS Snow Leopard, where we just used UNIX permissions?
That'd be my honest preference.
Then you just have malware scraping your home dir for bitcoin wallets and ssh keys anyway.
I can keep the malware off my machine just fine, thankyouverymuch. It's annoying not to be able to set normal permissions on my non-malware-using, non-agent-using machine.
I can keep the malware off my machine just fine, thankyouverymuch.
We all like to think that, don't we?
We are long into an arms race between our private data, and corporations who want us to install trinkets that will attempt to steal everything.
It’s not about AI specifically, they have been pulling this shit for years. AI is just making it worse.
Even if you don’t use AI directly, you can’t trust any app you install, and you can be pretty sure that even without intending to, you’re gonna install software that was written with AI. And who knows what it is going to pull.
It's impressive how there are absolutely no details in this announcement... I learnt nothing. Seriously though, MacOS could really use a serious sandbox implementation that's actually usable and documented. sandbox-exec is right there and waiting.
Some kind of lightweight containers like I use for build and test on Windows and Linux would be amazing. Instead, just lock it down like an iPhone.
I stopped using Claude Code after it started writing its own programs to search through my whole computer and makes changes as it sees fit to run "experiments". This was a good reminder to actually go back and delete that piece of malware from my computer for good
Good. At least someone is considering the reach of local agents being able to access everything on the disk.
I’m unfamiliar with some of the tech stack at $WORK so I use Claude to navigate it. It’s very good at this sort of thing.
The Claude desktop app for MacOS was becoming more and more insistent on escalating privs that I ended up deleting it. It turns out that the web app works great if you add it to the dock from safari. It’s functionally identical to the desktop app but it doesn’t continually ask to install “plugins” in MacOS.
I used Claude code for a while, it is an excellent search engine for our large existing code base, but they took all the default guardrails away, so an innocuous prompt can have it write code, compile and attempt to run it, without permission.
I absolutely hate it. Using the products of these awful companies is bad enough. Giving them access to all my data is just asking for trouble.