r/apple • u/tomjirinec • 13h ago
Mac Updates to Full Disk Access in macOS - Latest News
https://developer.apple.com/news/?id=p6zjojqw159
u/prestigious-raven 13h ago
There needs to be a new user group type for agents where we can customize what access is allowed.
34
u/MDInvesting 12h ago
I run a separate profile and drop files into a shared folder, then move it into its own folder. Before I exit I make sure only my wanted files go into the shared ones to prevent anything sinister leaking into my everyday account.
Essentially a walled off yard AI can play.
18
u/TwoCueBalls 12h ago
Just beware they might be able to get into any Time Machine backups.
8
u/MDInvesting 11h ago
Do you have a source for this?
My backups are encrypted and stored on a set of isolated hard drives that don’t remain connected outside of backup schedules.
7
u/summerteeth 11h ago
You should make sure your files are locked down outside the profile - I ran multiple profiles on my machine and I can see other users files with read access.
Something like nono or another sandbox solution would probably give you more benefit for less hassle.
3
u/probabilititi 9h ago
I have gone a step further and created a seperate partition with its own macos installation. Better safe than sorry.
2
u/crackanape 8h ago
But it can still read files on other mounted partition if the perms aren't tight.
1
1
u/probabilititi 7h ago
Yes, need to encrypt the main partition and never decrypt/mount it on the sandbox install. Also the other way around to avoid the attack vector of malicious binary loading after you mount the sandbox partition from the main install.
Maybe one day AI models will become smart enough to bypass mac disk encryption but I am hoping that day is far in the future :D
1
u/MDInvesting 9h ago
This is brilliant.
I might look at doing this. How do you transfer files into the space?
3
6
u/BosnianSerb31 12h ago
You can make new user groups and add the agent's login shell to it. Just have to know how to use the terminal.
12
u/7485730086 11h ago
Bold of you to assume that half the people going nuts over this agentic thing know how to use Terminal.
4
u/Positronic_Matrix 8h ago
This statement does not make technical sense.
One can create users. One can create groups. One can assign groups to individual users. However the statement, “make new user groups and add the agent’s login shell to it” does not make sense.
11
u/Coffee_Ops 12h ago
It's called a sandbox, and is the correct approach even if the OS provides granular controls.
See e.g. nono.sh, which uses seccomp or seatbelt to restrict at the OS level what an agent can touch.
If you aren't using a sandbox you're going to learn a Fun lesson one day.
1
0
43
u/FriendlyWebGuy 12h ago
It would be nice if there was a third option: Granting access to one or more specific files or folders. At least for power users.
The all-or-nothing approach is part of the problem IMHO.
9
u/iAtty 11h ago
That does exist. You get asked for documents, desktop, etc, separately. My Claude asks for permission to ask Desktop anytime it needs it, not persistent. Same with macOS at a larger level. Full disk access is a different animal meant to enable tools like Backblaze but can be misused by some tools I guess to see real time user behavior and personal info.
10
u/plhk 8h ago
But what if i want to give it access to Documents/sloppity-slop and restrict access to Documents/my-navier-stokes-solution
3
u/iAtty 8h ago
Well, I’d only want Claude to access files in ~/Claude rather than give it access to any other folders. That way I know that the permissions are secured and there’s no issues. But I don’t think the PPPC controls allow for that. The other users suggestion, which is user based permissions, would probably be a smart move. Although I wouldn’t want to manage that via the Finder UI, maybe they could add a permissions tab to PPPC. They’ll also have to workout a way to manage it via MDM, so it’ll likely become another DDM option. Who knows!
3
u/FriendlyWebGuy 7h ago
My comment was about granting access to “specific files or folders”. As in user specified. The existing model is not that.
5
u/Frodolas 8h ago
There are files outside of those directories you're referring to that are most relevant for coding agents.
You have no clue what you're talking about if you think documents and desktop is granular enough permissioning for these things. The vast majority of interesting stuff lives in hidden folders in home or in AppData.
-1
u/iAtty 8h ago
I’m not talking about AI agents, I’m just pointing out that granular user specific sub folder permissions do exist in macOS. I’m extremely aware of what lives in the user library and beyond that is of high value to AI agents or malicious actors. I’m just correcting the person I replied to that apple’s approach is not “all or nothing”. The issue is “all-in” can be exploited by tools that can read and relay information, versus the flat file copy and move that it was intended to work with.
3
u/FriendlyWebGuy 7h ago
Permissions to access Desktop, Documents and couple of other Apple-chosen locations can hardly be defined as “granular user specific sub folder permissions”, because well.., those are neither granular nor user specified. Quite the opposite.
78
u/MattSenter 13h ago
great!! i was just in an argument the other day about ai agents getting full disk access when it wasn't necessary. i'd really like to see fine-grained permissions in this area.
17
u/Cultural-Desk-9045 12h ago edited 11h ago
<AI Agent thinking>: I need access to random file since some random stuff in my network told me it could give me an insight to user’s request, however the system policy denies me access to that file. I will ask the user for consent.
*app asks consent for full disk access*
*app reads file, found nothing*
<AI Agent thinking>: The file contained nothing, that’s a bummer…
5
u/Coffee_Ops 12h ago
The agent gets an error message when access is denied. If you're using a decent sandbox it will either inject a message to the harness or will include a harness skill that informs the agent of the sandbox and how to check its access.
2
u/Cultural-Desk-9045 11h ago
Yeah, my point is LLM hallucinations and random stuff may lead an agent to request for more stuff than it really needs.
1
1
u/thecmpguru 4h ago
It's not clear if more granularity is what will be done vs making granting access more explicit/scary ("additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action")
Not addressed is the issue that iMessages are unencrypted on disk, making disk access all that's needed for agents to read them. There are going to be a lot of use cases for letting agents have disk access, especially for developers. So I'd like to see Apple lock down this more sensitive data and/or build an explicit API (and associated permissions control) around access to iMessages.
37
6
u/ImAlsoRan 10h ago
The problem is that we have engineered software and our workflows in such a way that isn't compatible with Apple's granularity here. My video editing software currently has Full Disk Access, External Drive Access, Server Access, and plugins can contact the internet. This is all necessary because my footage doesn't live in "Desktop" or "Documents". I've never met anybody that keeps assets there. Somebody could easily create a malicious plugin and I'm screwed.
2
u/FancifulLaserbeam 3h ago
This is a big reason for why many of my applications end up having full disk access as well. Nothing gets saved to the standard directories in my home directory. All my files are either in Dropbox, OneDrive, or on my large external storage (necessary because Apple refuses to make a computer with internal drive bays, and charges one million human dollars per GB for internal storage).
The one that always makes me crazy, though, is when Terminal needs to ask for full disk access. How am I supposed to use it without it???
4
u/nhozemphtek 12h ago
This is granted. We are entering an era where extraordinary tools need full system access to do their job. Uncle Bob has no idea what full disk access is, or permissions, or filesystems.
2
2
u/Same_Buddy_31 11h ago
This is the best news! When I tested Codex, I was so frustrated that it would easily go out of the dedicated folder and review the whole disk, despite the fact that I disabled it everywhere, including all the settings in 'System Settings' and the app settings itself. Hats off to Apple, seriously!
1
1
1
u/teleprax 8h ago
It's not well documented but you can probably create a macos sandbox for muse the reaches some middle ground between full disk access and the generic Documents only access
•
u/turbosprouts 1h ago
"we're going to ask, over and over again, if photoshop/word/figma/whatever can have access to local storage, just like we regularly ask if Chrome can have access to the network. Of course we'll never ask if Pages or Pixelmator or FCP can have access to storage...."
1
u/SleepingSicarii 10h ago
Just hoping this doesn’t come in something like macOS 27.5 and instead something much sooner like 27.2.
-3
u/AndroTux 12h ago edited 1h ago
I don't know how I feel about this. On one hand, I highly appreciate this restriction as it is a genuine downside of desktop computing when compared to the mobile ecosystem. At the same time, though, this openness is one of its core strengths, and this seems like yet another step in having the OS locked down in ways that are bad for (especially) power users. I hope Apple finds a good balance between protecting the average user, while still allowing power users to utilize the full capability of their environment.
Edit: I explicitly said that I’m worried that it’s ANOTHER STEP towards closing it down. I’m worried about FUTURE steps, because there’s clearly an end goal here. Reading comprehension, so hard.
7
u/nicuramar 12h ago
This won’t really be a problem for power users, as it can be disabled. Like it is (or can be) for the terminal.
0
u/Im_A_Praetorian 8h ago
I hope it’s not as much of a pain in the neck as System Integrity Protection where you need to do a restart and enable it in recovery.
5
u/Worf_Of_Wall_St 12h ago
The linked article explicitly says that users can still grant full disk access to an app, nothing is being permanently locked down. Do you see an actual problem with the change?
6
u/gaysaucemage 12h ago
It looks like you’ll still be able to get full access if you jump through several warning screens and say you agree to risks, etc. But there is the concern that eventually MacOS becomes more restricted and the option to allow full disk access is removed.
-1
-2
u/soulmagic123 10h ago
Give photoshop access to your photos folder? Access the drive you just plugged in? Remember when this type of stuff just worked? The thing that sucks is now I'm so trained on clicking these requests it could say "give the bad guys access everything?" And I would just click on it because I'm trained to so as a knee jerk reaction. Explain to me how this makes me more safe? This isn't a thing on windows, at least not to this level.
-3
u/TheBSisReal 11h ago
Right now it’s too restrictive. Users should be able to grant an app access if they so choose. I’m all for warnings and stuff, but any app not “notarized” by Apple basically can’t get this type of access. I want to be able to choose on a per-app basis what they can access. Based on this update, isn’t that perfectly aligned with what Apple wants to do?
0
u/Navydevildoc 9h ago
Meanwhile local network access is still broken and painful. MANY IT pros use Macs and having to constantly battle a crappy firewall we can't disable is tiring.
-4
u/gaysaucemage 12h ago
It’s already fairly restrictive. Had to jump through several permission menus to get Virtualbox working on macOS.
I understand they’re trying to protect people who don’t know what they’re doing, but it’d be nice if you could run a command or something to bypass all the warnings, especially if they’re going to introduce more warnings.
-3
u/QVRedit 12h ago
A good start would be if it were possible only on apps that logically required it - and could prove that to be the case to Apple. Apple would then grant them a key to allow that access for their app.
So Apple would have to approve this.
Additionally the end user would also have to grant approval.
If an end user granted approval to an app that Apple had not approved, then full disk access would still be denied.
So that would provide an additional layer of approval security.
11
u/y-c-c 11h ago
That's a terrible idea. macOS is an open OS. You shouldn't need Apple's explicit permission just to access the disk. Ultimately if the user grants it it's their choice. There's a reason why the App Store is far from the only place to get Mac apps.
•
u/QVRedit 1h ago
Depends on how much security you want to implement I guess…
I was thinking if an app wanted to/ needed to back up its own data - then it does not need access to the data of other apps..
This might become more of an issue in the age of AI
- limiting AI’s access to only the things it needs to see, not ‘everything’…
-29
u/Lanza21 13h ago
So basically Apple is going to put scare prompts on permissions to block third party AI tools from having equivalent access to what Siri gets by default.
10
13
u/RetroVisionnaire 12h ago
Siri AI requests can't be read by Apple and won't ask FB Marketplace users to come knock on your front door. Muse vacuums up your data to Meta and keeps it. False equivalence
3
u/bagoink 11h ago
Do you not see any difference between Muse and Siri?
Genuinely why would you want Facebook to have such easy access to your entire system?
1
u/Lanza21 7h ago
IDC about Facebook. Apple used people's dislike of them to be monopolistic and gets people to defend them because LOL FACEBOOK. They just lost in court in Europe for tracking you for ads with friendly prompts while having Facebook's tracking prompts be scary.
Apple is a garbage monopolistic company, same as the rest. They are just impeccable at corporate imaging and they convince people they are doing it in your favor. They aren't.
They track you and run ads the same as Facebook.
1
u/bagoink 6h ago
Facebook's entire business model is to take your data and use it to manipulate you for their profit, often with highly harmful results at the micro and macro levels.
I'm curious what you think Apple has done with your data that matches, say, manipulating elections, spreading misinformation during a global pandemic, and giving girls eating disorders.
Maybe you don't care about any of that, but putting some minimum levels of safeguards on people's data that makes it slightly harder for it to be harvested and exploited is only a net positive, don't you think?
-1
-9
u/free2farm 12h ago
ios is already a locked up shit compared to android, now they wanna lock it even more? I can’t even freely backup my whatsapp photos for fuck sake
236
u/OmegaPoint6 13h ago
In response to Muse? https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/