Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

44% Positive

Analyzed from 800 words in the discussion.

Trending Topics

#access#muse#disk#app#macos#full#permissions#run#user#more

Discussion (30 Comments)Read Original on HackerNews

jkingsman•about 2 hours ago
I'm no evangelist for LLM assistants, but this seems incredibly improbable and represents a failure of MacOS security if so. If full disk access isn't granted, Mac blocks it from the Downloads folder, to say nothing of actually sensitive paths. I would expect a far more likely case of an accidentally granted permission on another device or a permission that was on and then turned off.

Permissionless action is about to skyrocket as an issue, but this particular scenario strikes me as incredibly unlikely. Would be interested to know if Muse can provide more meaningful data provenance/logs.

Scanning iMessage dbs as a passive part of full disk access (and not a messages grant), if true, is a little sketchy, regardless.

iamacyborg•about 2 hours ago
The story from Hunterbrook is also pretty crazy with Muse having much more access to Meta’s social graphs than I suspect most users would hope.

https://hntrbrk.com/breaking-news/muse-doxxing

VCFundedGenYer•about 2 hours ago
I think what’s more alarming is the macOS nannying UAC-like toggles to block disk access and other “protections” are apparently all UX reducing flash and no actual functionality.

I’d argue this is a five alarm fire for macOS and Meta simply exploited it.

PaulHoule•about 2 hours ago
Personally that stuff drives me up the wall, it's the Mac wanting to become the iPhone and close off everything but the App Economy. They'll geofence XCode to the Bay Area or something so only "professionals" can develop software and eventually ban web browsers.
dec0dedab0de•about 2 hours ago
I think we need more granular permissions, and built in ways to trick apps into thinking they have permissions they do not.
drdexebtjl•29 minutes ago
A lot of comments saying this must not have happened because of macOS app permissions. That system is completely broken.

Open your terminal app and run /Applications/Firefox.app/Contents/MacOS/firefox

This opens a normal-looking Firefox window, but it has whatever permissions you gave to the terminal, which likely has Full Disk Access.

It’s insane.

cleandreams•35 minutes ago
I think the fundamental problem is that AI companies have been assuming that reinforcement learning with human feedback is an adequate foundational technology for guardrails. And that simply isn’t true.
ParanoidShroom•about 2 hours ago
How is this possible? Apple messages are just free for anyone to read?
ryandrake•about 2 hours ago
At least on Unix-like systems, if it's free for you to read, then it's free for any process you run as you to read. Sure, macOS has grafted its own weird "permissions" layer on top of the existing OS level permissions, but at the end of the day, when you run an app on Unix, you're allowing it to act as you, with all the powers your user has.

This used to work when you could trust the software you ran on your system to have access to everything you have access to on your computer. I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.

Best solution is to simply not run software made by blatantly untrustworthy developers. Second best solution would be to run such software as a severely sandboxed user who basically doesn't have access to anything important on your system.

anonymousDan•about 2 hours ago
My mental model is to treat AI agents running on your system as a form of malware that is running in a honeypot you control. You don't want to just get rid of it as you want to observe its behaviour (in the case of malware) or hopefully do something useful (AI). But you certainly shouldn't assume it won't do anything bad to your system.
graemep•about 2 hours ago
I do not know about all Unix like OSes, but Linux has sandboxes you can run as you main user. Not as safe as running as a separate user and sandboxing, or running in a VM, but reasonably solid.

> I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.

Agreed, but what can you do about your OS vendor?

brigade•about 1 hour ago
App store apps are required to run in a sandbox that denies file accesses without user permission.

Muse is not available in the macOS app store.

red_admiral•about 2 hours ago
In theory, iOS has some protection: the security model is that not all apps can be trusted with everything, so they have to ask for permission to access camera, GPS, texts and so on. I think apple even kicks apps out of its store that try and abuse this.
daishi55•about 2 hours ago
It’s not possible. User error lol
SaucyWrong•33 minutes ago
The user is nothing but a mark to Meta. If you use anything they make, they have you. Someday I hope more people realize this.
SamInTheShell•about 1 hour ago
These companies don't care. The technology exists, but the legislative stick just isn't there to incentivize these idiots to do the right things.
mock-possum•about 1 hour ago
> Meta says that Muse has to obey permissions that users set up. It won't access any data you don't explicitly allow it to access.

Is this a setting configured in Muse itself?

> It took Meta a single day to begin "helpfully" pitching article ideas based on texts he'd sent to a podcast co-host. When he asked Muse how it got the information, it said that it read banners from incoming texts. But that's not true, either.bAfter doing a little digging, Aten says Muse synced 187,000 lines from his Messages database, despite Full Disk Access being off.

Is full disk access enforced on the OS side, or the app side? Like is this claiming MacOS security was breached by Muse somehow acting in spite of deliberately disabled access somehow?

Has this been reproduced / recorded?

lapcat•about 1 hour ago
> Is full disk access enforced on the OS side, or the app side?

The OS side.

> Has this been reproduced / recorded?

No.

bethekidyouwant•about 2 hours ago
How is this a story anybody who knows how a computer works knows this is nonsense.
lapcat•about 1 hour ago
> After doing a little digging, Aten says Muse synced 187,000 lines from his Messages database, despite Full Disk Access being off.

This is absolutely untrue, and impossible.

I haven't spoken directly with Aten, but I have second-hand information from someone who has spoken directly with Aten, and it turns out that he has two Macs and may have allowed Full Disk Access to Muse on one of them.

Advertisement