DE version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
44% Positive
Analyzed from 800 words in the discussion.
Trending Topics
#access#muse#disk#app#macos#full#permissions#run#user#more

Discussion (30 Comments)Read Original on HackerNews
Permissionless action is about to skyrocket as an issue, but this particular scenario strikes me as incredibly unlikely. Would be interested to know if Muse can provide more meaningful data provenance/logs.
Scanning iMessage dbs as a passive part of full disk access (and not a messages grant), if true, is a little sketchy, regardless.
https://hntrbrk.com/breaking-news/muse-doxxing
I’d argue this is a five alarm fire for macOS and Meta simply exploited it.
Open your terminal app and run /Applications/Firefox.app/Contents/MacOS/firefox
This opens a normal-looking Firefox window, but it has whatever permissions you gave to the terminal, which likely has Full Disk Access.
It’s insane.
This used to work when you could trust the software you ran on your system to have access to everything you have access to on your computer. I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.
Best solution is to simply not run software made by blatantly untrustworthy developers. Second best solution would be to run such software as a severely sandboxed user who basically doesn't have access to anything important on your system.
> I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.
Agreed, but what can you do about your OS vendor?
Muse is not available in the macOS app store.
Is this a setting configured in Muse itself?
> It took Meta a single day to begin "helpfully" pitching article ideas based on texts he'd sent to a podcast co-host. When he asked Muse how it got the information, it said that it read banners from incoming texts. But that's not true, either.bAfter doing a little digging, Aten says Muse synced 187,000 lines from his Messages database, despite Full Disk Access being off.
Is full disk access enforced on the OS side, or the app side? Like is this claiming MacOS security was breached by Muse somehow acting in spite of deliberately disabled access somehow?
Has this been reproduced / recorded?
The OS side.
> Has this been reproduced / recorded?
No.
This is absolutely untrue, and impossible.
I haven't spoken directly with Aten, but I have second-hand information from someone who has spoken directly with Aten, and it turns out that he has two Macs and may have allowed Full Disk Access to Muse on one of them.