Can I just tap out of using AI agents altogether, and go back to the "Full Disk Access" setup from Mac OS Snow Leopard, where we just used UNIX permissions?
I can keep the malware off my machine just fine, thankyouverymuch. It's annoying not to be able to set normal permissions on my non-malware-using, non-agent-using machine.
The point of capabilities is protecting against not just malware, but also "innocent" that has been hijacked from upstream. Protection from ""rogue"" AI agents isn't/shouldn't even be the primary goal here, we needed a sandboxed application model 20 years ago.
We're all just one NPM update away from getting our browser cookies yanked.
We are long into an arms race between our private data, and corporations who want us to install trinkets that will attempt to steal everything.
It’s not about AI specifically, they have been pulling this shit for years. AI is just making it worse.
Even if you don’t use AI directly, you can’t trust any app you install, and you can be pretty sure that even without intending to, you’re gonna install software that was written with AI. And who knows what it is going to pull.
Or you could admit to yourself you are not Apple's target customer and draw the conclusion you need to move to Linux/BSD/whatever. I did about a year ago, and it's been much less painful than I expected:
I daily drove Linux on my desktop for several years, and wound up back on mac because I needed to build things for iDevices again. I didn't want two different daily driving systems, and there are actually some things that I like about Mac.
But if I no longer have that need next time I'm ready to cycle hardware, I'm likely to go back to Linux. If we don't have good support for Affinity apps on Linux by then, I'll probably keep an iPad around to run those.
I'm not a professional artist, but I've found DarkTable and Inkscape a perfectly suitable replacement for my previous Mac apps. I hear you on not having multiple daily drivers but that ship sailed a long time ago for me, at last count I have 26 computers, 4 of them daily drivers.
It's impressive how there are absolutely no details in this announcement... I learnt nothing.
Seriously though, MacOS could really use a serious sandbox implementation that's actually usable and documented. sandbox-exec is right there and waiting.
That's for running Linux containers not macos containers. I run my Linux containers on my Linux hosts. I want to run macos containers on my macos hosts.
I stopped using Claude Code after it started writing its own programs to search through my whole computer and makes changes as it sees fit to run "experiments". This was a good reminder to actually go back and delete that piece of malware from my computer for good
Looking at this MacBook Pro, only a handful of apps to which I’ve granted Full Disk Access are backup apps. Others include the Finder replacement Bloom, launchers like Alfred, the wonderful selection utility PopClip, Apple’s own Pixelmator Pro, Setapp, TestFlight, Unread, Supercharge, Madden NFL 27 Arcade Edition, Hazel, and many others.
Half of the apps on this list have no reason whatsoever to be granted full disk access, and should not have it. If anything, this change might encourage developers to limit their products to only the access they actually need.
Except you can't disable Apple Intelligence in macOS 27, and it has full access to everything on your Mac, so the motivation may be kneecapping AI competitors under pretence of protecting your privacy.
Apple is an advertising company (the so-called "Services" revenue, along with the App Store tax), and thus inherently untrustworthy. They just have better privacy-washing marketing than the other Big Tech.
I’m unfamiliar with some of the tech stack at $WORK so I use Claude to navigate it. It’s very good at this sort of thing.
The Claude desktop app for MacOS was becoming more and more insistent on escalating privs that I ended up deleting it. It turns out that the web app works great if you add it to the dock from safari. It’s functionally identical to the desktop app but it doesn’t continually ask to install “plugins” in MacOS.
I used Claude code for a while, it is an excellent search engine for our large existing code base, but they took all the default guardrails away, so an innocuous prompt can have it write code, compile and attempt to run it, without permission.
I absolutely hate it. Using the products of these awful companies is bad enough. Giving them access to all my data is just asking for trouble.
While I work 100% remote from home, I find it convenient to have a separate machine for work. They don’t want me to use the work machine for personal stuff, which is fine since they paid for it. This strikes both ways; I don’t want the work machine to have access to my home network, so it gets its own access point. I also don’t have any personal data on the work machine. I do have a few accounts I use in both contexts (GitHub, iCloud, etc) that I’ve been thinking of changing so agents on my work machine don’t have access to my personal accounts however.
Maybe, instead of reminding people that these controls are not necessarily for the experts every time, we need to come up with a catchy phrase. What do y'all think about:
This is great! I feel we are long due for something like this in Linux land. Flatpak is very close, but isn't the best way to package non-GUI applications.
There are plenty of sandboxes, whether running in Firecracker microVMs, under gVisor (which has just been transferred to CNCF) and so on. If anything we are beset by the tyranny of choice, just as with desktop environments.
hoistbypetard | a day ago
Can I just tap out of using AI agents altogether, and go back to the "Full Disk Access" setup from Mac OS Snow Leopard, where we just used UNIX permissions?
That'd be my honest preference.
icefox | a day ago
Then you just have malware scraping your home dir for bitcoin wallets and ssh keys anyway.
hoistbypetard | a day ago
I can keep the malware off my machine just fine, thankyouverymuch. It's annoying not to be able to set normal permissions on my non-malware-using, non-agent-using machine.
icefox | 22 hours ago
We all like to think that, don't we?
vforvaline | 16 hours ago
The point of capabilities is protecting against not just malware, but also "innocent" that has been hijacked from upstream. Protection from ""rogue"" AI agents isn't/shouldn't even be the primary goal here, we needed a sandboxed application model 20 years ago.
We're all just one NPM update away from getting our browser cookies yanked.
Halkcyon | 21 hours ago
https://gist.github.com/arianvp/5f59f1783e3eaf1a2d4cd8e952bb4acf?permalink_comment_id=5877110
fazalmajid | 10 hours ago
Or FIDO U2F USB key backed ed25519-sk keys, supported by OpenSSH since 8.2 in 2020, more portable
hoistbypetard | 11 hours ago
Nice find!
doctor_eval | a day ago
We are long into an arms race between our private data, and corporations who want us to install trinkets that will attempt to steal everything.
It’s not about AI specifically, they have been pulling this shit for years. AI is just making it worse.
Even if you don’t use AI directly, you can’t trust any app you install, and you can be pretty sure that even without intending to, you’re gonna install software that was written with AI. And who knows what it is going to pull.
fazalmajid | 10 hours ago
Or you could admit to yourself you are not Apple's target customer and draw the conclusion you need to move to Linux/BSD/whatever. I did about a year ago, and it's been much less painful than I expected:
https://blog.majid.info/quit-apple/
hoistbypetard | 10 hours ago
I daily drove Linux on my desktop for several years, and wound up back on mac because I needed to build things for iDevices again. I didn't want two different daily driving systems, and there are actually some things that I like about Mac.
But if I no longer have that need next time I'm ready to cycle hardware, I'm likely to go back to Linux. If we don't have good support for Affinity apps on Linux by then, I'll probably keep an iPad around to run those.
fazalmajid | 9 hours ago
I'm not a professional artist, but I've found DarkTable and Inkscape a perfectly suitable replacement for my previous Mac apps. I hear you on not having multiple daily drivers but that ship sailed a long time ago for me, at last count I have 26 computers, 4 of them daily drivers.
viraptor | a day ago
It's impressive how there are absolutely no details in this announcement... I learnt nothing. Seriously though, MacOS could really use a serious sandbox implementation that's actually usable and documented. sandbox-exec is right there and waiting.
fazalmajid | 10 hours ago
I'm guessing they will make FDA an entitlement that will only be granted during App Store review.
ianloic | 20 hours ago
Some kind of lightweight containers like I use for build and test on Windows and Linux would be amazing. Instead, just lock it down like an iPhone.
scraps | 18 hours ago
do you mean something different than this? https://github.com/apple/container
ianloic | 7 hours ago
That's for running Linux containers not macos containers. I run my Linux containers on my Linux hosts. I want to run macos containers on my macos hosts.
ashwinsundar | 23 hours ago
I stopped using Claude Code after it started writing its own programs to search through my whole computer and makes changes as it sees fit to run "experiments". This was a good reminder to actually go back and delete that piece of malware from my computer for good
doctor_eval | 11 hours ago
Yep it will write, build and run code at the slightest provocation, all the guardrails are entirely off.
I alone am responsible for the code I commit but Claude is happy to make whatever change.
It’s out of control and it’s despicable practice.
diktomat | 12 hours ago
I found this quote from the MacStories post on the matter interesting:
Half of the apps on this list have no reason whatsoever to be granted full disk access, and should not have it. If anything, this change might encourage developers to limit their products to only the access they actually need.
[OP] videah | a day ago
Some further context, this is in the wake of an exploit with Meta’s LLM agent.
SamRW | 16 hours ago
My god. We've truly learnt nothing about security in all these years.
ndegruchy | a day ago
Good. At least someone is considering the reach of local agents being able to access everything on the disk.
fazalmajid | 10 hours ago
Except you can't disable Apple Intelligence in macOS 27, and it has full access to everything on your Mac, so the motivation may be kneecapping AI competitors under pretence of protecting your privacy.
https://mjtsai.com/blog/2026/10/01/i-said-no-and-apple-said-yes/
Apple is an advertising company (the so-called "Services" revenue, along with the App Store tax), and thus inherently untrustworthy. They just have better privacy-washing marketing than the other Big Tech.
doctor_eval | a day ago
I’m unfamiliar with some of the tech stack at $WORK so I use Claude to navigate it. It’s very good at this sort of thing.
The Claude desktop app for MacOS was becoming more and more insistent on escalating privs that I ended up deleting it. It turns out that the web app works great if you add it to the dock from safari. It’s functionally identical to the desktop app but it doesn’t continually ask to install “plugins” in MacOS.
I used Claude code for a while, it is an excellent search engine for our large existing code base, but they took all the default guardrails away, so an innocuous prompt can have it write code, compile and attempt to run it, without permission.
I absolutely hate it. Using the products of these awful companies is bad enough. Giving them access to all my data is just asking for trouble.
stig | 5 hours ago
While I work 100% remote from home, I find it convenient to have a separate machine for work. They don’t want me to use the work machine for personal stuff, which is fine since they paid for it. This strikes both ways; I don’t want the work machine to have access to my home network, so it gets its own access point. I also don’t have any personal data on the work machine. I do have a few accounts I use in both contexts (GitHub, iCloud, etc) that I’ve been thinking of changing so agents on my work machine don’t have access to my personal accounts however.
apromixately | 7 hours ago
Maybe, instead of reminding people that these controls are not necessarily for the experts every time, we need to come up with a catchy phrase. What do y'all think about:
Or maybe we just need to identify the bias more clearly...this is probably either https://en.wikipedia.org/wiki/Curse_of_knowledge or https://en.wikipedia.org/wiki/False_consensus_effect
The first seems to fit better but neither seems to be really on point.
vforvaline | 16 hours ago
This is great! I feel we are long due for something like this in Linux land. Flatpak is very close, but isn't the best way to package non-GUI applications.
fazalmajid | 10 hours ago
There are plenty of sandboxes, whether running in Firecracker microVMs, under gVisor (which has just been transferred to CNCF) and so on. If anything we are beset by the tyranny of choice, just as with desktop environments.