Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • The user is nothing but a mark to Meta. If you use anything they make, they have you. Someday I hope more people realize this.
  • I think the fundamental problem is that AI companies have been assuming that reinforcement learning with human feedback is an adequate foundational technology for guardrails. And that simply isn’t true.
  • These companies don't care. The technology exists, but the legislative stick just isn't there to incentivize these idiots to do the right things.
  • How is this possible? Apple messages are just free for anyone to read?
  • A lot of comments saying this must not have happened because of macOS app permissions. That system is completely broken.

    Open your terminal app and run /Applications/Firefox.app/Contents/MacOS/firefox

    This opens a normal-looking Firefox window, but it has whatever permissions you gave to the terminal, which likely has Full Disk Access.

    It’s insane.

  • I think what’s more alarming is the macOS nannying UAC-like toggles to block disk access and other “protections” are apparently all UX reducing flash and no actual functionality.

    I’d argue this is a five alarm fire for macOS and Meta simply exploited it.

  • The story from Hunterbrook is also pretty crazy with Muse having much more access to Meta’s social graphs than I suspect most users would hope.

    https://hntrbrk.com/breaking-news/muse-doxxing

  • I'm no evangelist for LLM assistants, but this seems incredibly improbable and represents a failure of MacOS security if so. If full disk access isn't granted, Mac blocks it from the Downloads folder, to say nothing of actually sensitive paths. I would expect a far more likely case of an accidentally granted permission on another device or a permission that was on and then turned off.

    Permissionless action is about to skyrocket as an issue, but this particular scenario strikes me as incredibly unlikely. Would be interested to know if Muse can provide more meaningful data provenance/logs.

    Scanning iMessage dbs as a passive part of full disk access (and not a messages grant), if true, is a little sketchy, regardless.

Explore Birbla archives