Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • > This system is annoying but manageable on your primary Mac; it’s a disaster on a headless Mac running agents, for two reasons. First, agents write new programs all of the time, and in my case, those programs need access to devices on my network (SMB shares, for example, trigger a TCC warning). What I need is a permission layer for agents, not the programs they create; TCC is operating at the wrong level of abstraction.

    Doesn’t that already exist? If I give Terminal.app access to the entire disk, CLI tools started by the app (indirectly: Terminal.app runs a shell, and the shell runs the tools) have that access, too.

    And I don’t think that’s because Apple gives Terminal.app preferential access. Google tells me that works for iTerm, too.

    Or would it mean agents need to do some special thing to launch tools?

  • What I find most surprising, is that I don't think we got any sort of timeline from Apple on this change and its very vague (which just fuels articles like this).

    So did this initiative within Apple just start and we could be looking at this change coming in Mac 28?

    I don't remember another time of an announcement like this from Apple of a major change with so little information, though I could be wrong or hint of when.

    Regarding the concern, while I do hope that there is still a way to grant actual full disk access to some applications. Even Apple called out a non controversial need for something like that, backup software. I can also think of security scanning software, a lot of businesses have those deployed to corporate Mac's. I do also think that better controls around it, especially in this age of vibe coded apps that never actually think about security or actively hostile companies like meta.

  • I think the observation Ben is making, is that Apple no longer has a grasp on the future purchases in the market. He makes it explicit with this quote: "I can, for the first time, envision a future where I don’t buy Apple by default." It used to be a given that we would refresh every 3-4 years, thats probably no longer guaranteed.

    Observationally, I would argue we've all been expecting this for this for a long time. Every year Apple has raised the price of allegiance and every year we've paid it, waiting for products like the framework laptop or certain linux distros to become mature. We're still not there yet, but how much longer until there is real competition in the personal computer market?

  • > The question, however, is whether what they are designed for is the future I am barreling towards, one where agentic abstraction both renders traditional interfaces relics

    I think he was burying the lede but glad he finally posed the question.

    I think it's a bigger risk factor for Apple than is generally assumed. If consumers get used to the freedom but endemic spying of products like Muse, Apple may have a hard time sticking to their privacy and security mandate.

  • To read Ben is to glimpse the AI divide: he's honestly and emphatically choosing based on whether it makes it easier for him to use his AI agents, even if that means ditching Apple for the Zuckerberg's melee. It's that important to his personal productivity. AI-native product streams will separate from what came before, as will the people who master them.

    That said, I disagree on Apple: while the UI can be perfect, it has always imperfectly been trying to do the right thing technically in concert with developers and users, which puts it in the position of imposing constraints that developers and users can relax to varying degrees: wearable and home devices (not at all), iOS (somewhat), macOS (mostly).

    wrt a hacker's future: I'm still traumatized both by decades of windows reboots and virus scanning, and by decades of squeezing into Linux (just don't sleep, avoid these displays...). I'm glad Apple stuff mostly just works and ordinary people still have access to unlocked, general-purpose computers, but that might not last. Cheap AI coding might remove any financial incentive to support users programming on their own, and we'd be left with locked devices as consumers or work-only access to programmable computers (at least for the latest hardware of note). If a 40% premium for mac hardware is the price we pay for continued access, so be it.

  • I would argue that someone who would open a remote access port to the internet with no filtering is exactly the kind of person that Apple needs to protect from themselves

    Yeah, it was neat that Claude found this, but Thompson showed an almost criminal lack of security awareness by having VNC/ARD open to the internet

  • It strikes me that heavy AI agent users have an extraordinarily high risk tolerance for identity theft, privacy breaches and data loss vs. perceived productivity. Far beyond what any responsible medium to large size company would ever tolerate.

    Overall the limits to AI productivity can be summarized in one word: discipline. If you're undisciplined in your security, your design constraints, your automated test coverage, your separation of the deterministic and indeterministic, you will be quite productive ... for a time. Until quite suddenly, you aren't, possibly due to catastrophe.

    Similar to the early era of computers on the Internet, with lax security, we have a window where we can get away with this, but it will close quicker than many realize. Some things do seem to need to be learned the hard way.

    Apple is trying to do the bare minimum here - not even introducing a new security model - and people are already freaking out. But a disciplined agent sandbox model is exactly what we need to get to.

  • The full disk access permission is something you give to backup software.

    If you give full-disk access to Meta software running on your main computer, Meta is not going to respect your privacy.

    > Friday’s [full-disk access] announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.

    https://arstechnica.com/security/2026/10/apple-changes-full-...

    If you want to know why Apple is suddenly not happy about the way the full-disk access permission is being abused, look no further.

Explore Birbla archives

Apple and a Hacker's Future · Birbla