I'm no evangelist for LLM assistants, but this seems incredibly improbable and represents a failure of MacOS security if so. If full disk access isn't granted, Mac blocks it from the Downloads folder, to say nothing of actually sensitive paths. I would expect a far more likely case of an accidentally granted permission on another device or a permission that was on and then turned off.
Permissionless action is about to skyrocket as an issue, but this particular scenario strikes me as incredibly unlikely. Would be interested to know if Muse can provide more meaningful data provenance/logs.
Scanning iMessage dbs as a passive part of full disk access (and not a messages grant), if true, is a little sketchy, regardless.
I think what’s more alarming is the macOS nannying UAC-like toggles to block disk access and other “protections” are apparently all UX reducing flash and no actual functionality.
I’d argue this is a five alarm fire for macOS and Meta simply exploited it.
At least on Unix-like systems, if it's free for you to read, then it's free for any process you run as you to read. Sure, macOS has grafted its own weird "permissions" layer on top of the existing OS level permissions, but at the end of the day, when you run an app on Unix, you're allowing it to act as you, with all the powers your user has.
This used to work when you could trust the software you ran on your system to have access to everything you have access to on your computer. I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.
Best solution is to simply not run software made by blatantly untrustworthy developers. Second best solution would be to run such software as a severely sandboxed user who basically doesn't have access to anything important on your system.
I do not know about all Unix like OSes, but Linux has sandboxes you can run as you main user. Not as safe as running as a separate user and sandboxing, or running in a VM, but reasonably solid.
> I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.
> After doing a little digging, Aten says Muse synced 187,000 lines from his Messages database, despite Full Disk Access being off.
This is absolutely untrue, and impossible.
I haven't spoken directly with Aten, but I have second-hand information from someone who has spoken directly with Aten, and it turns out that he has two Macs and may have allowed Full Disk Access to Muse on one of them.
Whenever one of these AI CEOs (Altman, Amodeo, Huang) talk about "responsibility" and show some care (honest or not) for the consequences of their technology, I can't help thinking about Meta.
This is a company that is built in exploiting people's naiveté and turning them into products. They sell their users.
And this blatant irresponsible company has deep pockets and influential lobbyists. Worse yet: their cameras (ie. those glasses they make with RayBan) are far more ubiquitous than Flock cameras yet very few people freak out about them.
It really pisses me off that Meta always gets a free pass just because every grandma and their grandchildren uses Facebook. A "nice" scumbag gets away with abuse just because he is "nice".
Permissionless action is about to skyrocket as an issue, but this particular scenario strikes me as incredibly unlikely. Would be interested to know if Muse can provide more meaningful data provenance/logs.
Scanning iMessage dbs as a passive part of full disk access (and not a messages grant), if true, is a little sketchy, regardless.
I’d argue this is a five alarm fire for macOS and Meta simply exploited it.
This used to work when you could trust the software you ran on your system to have access to everything you have access to on your computer. I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.
Best solution is to simply not run software made by blatantly untrustworthy developers. Second best solution would be to run such software as a severely sandboxed user who basically doesn't have access to anything important on your system.
> I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.
Agreed, but what can you do about your OS vendor?
This is absolutely untrue, and impossible.
I haven't spoken directly with Aten, but I have second-hand information from someone who has spoken directly with Aten, and it turns out that he has two Macs and may have allowed Full Disk Access to Muse on one of them.
This is a company that is built in exploiting people's naiveté and turning them into products. They sell their users.
And this blatant irresponsible company has deep pockets and influential lobbyists. Worse yet: their cameras (ie. those glasses they make with RayBan) are far more ubiquitous than Flock cameras yet very few people freak out about them.
It really pisses me off that Meta always gets a free pass just because every grandma and their grandchildren uses Facebook. A "nice" scumbag gets away with abuse just because he is "nice".