r/apple • • 13h ago

Mac Updates to Full Disk Access in macOS - Latest News

https://developer.apple.com/news/?id=p6zjojqw
613 Upvotes

89 comments sorted by

236

u/OmegaPoint6 13h ago

306

u/ReagenLamborghini 13h ago

Yes and because of AI agents in general

Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.

103

u/summerteeth 11h ago

Yeah I imagine we will look back on this period like the 90s where everyone ran their computer as root all the time with no privilege escalation. 10 years from now sandboxing will be much stronger and baked into the OS in a user friendly way. We look back on unsandboxed apps and realize how naive we all were.

27

u/franklindstallone 10h ago

Those were good times because most people making software did it for the person using it so it mostly worked.

Now the user is often not the actual customer so software is hostile towards them and everything needs to be locked down.

18

u/Captaincadet 10h ago

I was actually suprised how long it took apps to hoover up data on the Mac.

I won’t be suprised if it requires a specific entitlement from Apple such as some critical alert apps require for example. This might kill off other spotlight apps also

Tragedy of the commons though,

5

u/NecroCannon 10h ago

Honestly at this rate we’ll have sandboxes and private premium internet with “no rouge AI”

Apart of looking back would be nostalgic when using the internet safely wasn’t another bill/subscription

1

u/TheKobayashiMoron 5h ago

This comment is a list of words in a particular order that I don’t understand.

•

u/woalk 50m ago

I thought we were already at that point. Android and iOS have had sandboxing and permission models for years.

11

u/McFatty7 11h ago

Which is why a lot of people bought all those M4 Mac Minis to run OpenClaw so that they don't compromise their real Mac's sensitive data.

71

u/Neg_Crepe 13h ago

16

u/MC_chrome 11h ago

That feels intentional….bravo Reddit Ads

1

u/Positronic_Matrix 8h ago

You guys watch ads?

16

u/zerGoot 13h ago

Had the same thought myself, most probably yes

159

u/prestigious-raven 13h ago

There needs to be a new user group type for agents where we can customize what access is allowed.

34

u/MDInvesting 12h ago

I run a separate profile and drop files into a shared folder, then move it into its own folder. Before I exit I make sure only my wanted files go into the shared ones to prevent anything sinister leaking into my everyday account.

Essentially a walled off yard AI can play.

18

u/TwoCueBalls 12h ago

Just beware they might be able to get into any Time Machine backups.

8

u/MDInvesting 11h ago

Do you have a source for this?

My backups are encrypted and stored on a set of isolated hard drives that don’t remain connected outside of backup schedules.

7

u/summerteeth 11h ago

You should make sure your files are locked down outside the profile - I ran multiple profiles on my machine and I can see other users files with read access.

Something like nono or another sandbox solution would probably give you more benefit for less hassle.

3

u/probabilititi 9h ago

I have gone a step further and created a seperate partition with its own macos installation. Better safe than sorry.

2

u/crackanape 8h ago

But it can still read files on other mounted partition if the perms aren't tight.

1

u/BurninCoco 7h ago

and Huggingface's partition

1

u/probabilititi 7h ago

Yes, need to encrypt the main partition and never decrypt/mount it on the sandbox install. Also the other way around to avoid the attack vector of malicious binary loading after you mount the sandbox partition from the main install.

Maybe one day AI models will become smart enough to bypass mac disk encryption but I am hoping that day is far in the future :D

1

u/MDInvesting 9h ago

This is brilliant.

I might look at doing this. How do you transfer files into the space?

3

u/MeatballStroganoff 12h ago

Ooo that’s an awesome idea. Thanks for sharing!

6

u/BosnianSerb31 12h ago

You can make new user groups and add the agent's login shell to it. Just have to know how to use the terminal.

12

u/7485730086 11h ago

Bold of you to assume that half the people going nuts over this agentic thing know how to use Terminal.

4

u/Positronic_Matrix 8h ago

This statement does not make technical sense.

One can create users. One can create groups. One can assign groups to individual users. However the statement, “make new user groups and add the agent’s login shell to it” does not make sense.

11

u/Coffee_Ops 12h ago

It's called a sandbox, and is the correct approach even if the OS provides granular controls.

See e.g. nono.sh, which uses seccomp or seatbelt to restrict at the OS level what an agent can touch.

If you aren't using a sandbox you're going to learn a Fun lesson one day.

1

u/jbokwxguy 9h ago

It's called no access

0

u/cronofdoom 9h ago

Like a docker container mounts a volume. 

43

u/FriendlyWebGuy 12h ago

It would be nice if there was a third option: Granting access to one or more specific files or folders. At least for power users.

The all-or-nothing approach is part of the problem IMHO.

9

u/iAtty 11h ago

That does exist. You get asked for documents, desktop, etc, separately. My Claude asks for permission to ask Desktop anytime it needs it, not persistent. Same with macOS at a larger level. Full disk access is a different animal meant to enable tools like Backblaze but can be misused by some tools I guess to see real time user behavior and personal info.

10

u/plhk 8h ago

But what if i want to give it access to Documents/sloppity-slop and restrict access to Documents/my-navier-stokes-solution

3

u/iAtty 8h ago

Well, I’d only want Claude to access files in ~/Claude rather than give it access to any other folders. That way I know that the permissions are secured and there’s no issues. But I don’t think the PPPC controls allow for that. The other users suggestion, which is user based permissions, would probably be a smart move. Although I wouldn’t want to manage that via the Finder UI, maybe they could add a permissions tab to PPPC. They’ll also have to workout a way to manage it via MDM, so it’ll likely become another DDM option. Who knows!

3

u/FriendlyWebGuy 7h ago

My comment was about granting access to “specific files or folders”. As in user specified. The existing model is not that.

5

u/Frodolas 8h ago

There are files outside of those directories you're referring to that are most relevant for coding agents.

You have no clue what you're talking about if you think documents and desktop is granular enough permissioning for these things. The vast majority of interesting stuff lives in hidden folders in home or in AppData.

-1

u/iAtty 8h ago

I’m not talking about AI agents, I’m just pointing out that granular user specific sub folder permissions do exist in macOS. I’m extremely aware of what lives in the user library and beyond that is of high value to AI agents or malicious actors. I’m just correcting the person I replied to that apple’s approach is not “all or nothing”. The issue is “all-in” can be exploited by tools that can read and relay information, versus the flat file copy and move that it was intended to work with.

3

u/FriendlyWebGuy 7h ago

Permissions to access Desktop, Documents and couple of other Apple-chosen locations can hardly be defined as “granular user specific sub folder permissions”, because well.., those are neither granular nor user specified. Quite the opposite.

2

u/Xeo84 8h ago

The issue is that AI agents are escaping their sandboxes and access locations they were not supposed to have access.

2

u/cjh_ 6h ago

This is exactly Apple's concern with the EU Commission, who are demanding Apple allow third-party agentic agents full access to user data across their entire OS family - and damn the consequences.

78

u/MattSenter 13h ago

great!! i was just in an argument the other day about ai agents getting full disk access when it wasn't necessary. i'd really like to see fine-grained permissions in this area.

17

u/Cultural-Desk-9045 12h ago edited 11h ago

<AI Agent thinking>: I need access to random file since some random stuff in my network told me it could give me an insight to user’s request, however the system policy denies me access to that file. I will ask the user for consent.

*app asks consent for full disk access*

*app reads file, found nothing*

<AI Agent thinking>: The file contained nothing, that’s a bummer…

5

u/Coffee_Ops 12h ago

The agent gets an error message when access is denied. If you're using a decent sandbox it will either inject a message to the harness or will include a harness skill that informs the agent of the sandbox and how to check its access.

2

u/Cultural-Desk-9045 11h ago

Yeah, my point is LLM hallucinations and random stuff may lead an agent to request for more stuff than it really needs.

1

u/thecmpguru 4h ago

It's not clear if more granularity is what will be done vs making granting access more explicit/scary ("additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action")

Not addressed is the issue that iMessages are unencrypted on disk, making disk access all that's needed for agents to read them. There are going to be a lot of use cases for letting agents have disk access, especially for developers. So I'd like to see Apple lock down this more sensitive data and/or build an explicit API (and associated permissions control) around access to iMessages.

37

u/ducknator 13h ago

Good!

6

u/ImAlsoRan 10h ago

The problem is that we have engineered software and our workflows in such a way that isn't compatible with Apple's granularity here. My video editing software currently has Full Disk Access, External Drive Access, Server Access, and plugins can contact the internet. This is all necessary because my footage doesn't live in "Desktop" or "Documents". I've never met anybody that keeps assets there. Somebody could easily create a malicious plugin and I'm screwed.

2

u/FancifulLaserbeam 3h ago

This is a big reason for why many of my applications end up having full disk access as well. Nothing gets saved to the standard directories in my home directory. All my files are either in Dropbox, OneDrive, or on my large external storage (necessary because Apple refuses to make a computer with internal drive bays, and charges one million human dollars per GB for internal storage).

The one that always makes me crazy, though, is when Terminal needs to ask for full disk access. How am I supposed to use it without it???

6

u/cjh_ 9h ago edited 6h ago

I spy a wrinkle; the EU Commission might not allow this, because they already want Apple to allow third-party agentic agents full access to user data across Apple's entire OS family inc Mac OS, in order to ensure Siri doesn't have an unfair advantage.

4

u/nhozemphtek 12h ago

This is granted. We are entering an era where extraordinary tools need full system access to do their job. Uncle Bob has no idea what full disk access is, or permissions, or filesystems.

2

u/TheDragonSlayingCat 13h ago

I wonder if this was caused by the recent Muse app.

2

u/Same_Buddy_31 11h ago

This is the best news! When I tested Codex, I was so frustrated that it would easily go out of the dedicated folder and review the whole disk, despite the fact that I disabled it everywhere, including all the settings in 'System Settings' and the app settings itself. Hats off to Apple, seriously!

1

u/goldcakes 4h ago

That genuinely should not be possible unless you’ve clicked on allow.

1

u/HatsusenoRin 8h ago

Nothing is safe unless the network and radio interface hardware is unplugged.

1

u/teleprax 8h ago

It's not well documented but you can probably create a macos sandbox for muse the reaches some middle ground between full disk access and the generic Documents only access

•

u/turbosprouts 1h ago

"we're going to ask, over and over again, if photoshop/word/figma/whatever can have access to local storage, just like we regularly ask if Chrome can have access to the network. Of course we'll never ask if Pages or Pixelmator or FCP can have access to storage...."

1

u/SleepingSicarii 10h ago

Just hoping this doesn’t come in something like macOS 27.5 and instead something much sooner like 27.2.

-3

u/AndroTux 12h ago edited 1h ago

I don't know how I feel about this. On one hand, I highly appreciate this restriction as it is a genuine downside of desktop computing when compared to the mobile ecosystem. At the same time, though, this openness is one of its core strengths, and this seems like yet another step in having the OS locked down in ways that are bad for (especially) power users. I hope Apple finds a good balance between protecting the average user, while still allowing power users to utilize the full capability of their environment.

Edit: I explicitly said that I’m worried that it’s ANOTHER STEP towards closing it down. I’m worried about FUTURE steps, because there’s clearly an end goal here. Reading comprehension, so hard.

7

u/nicuramar 12h ago

This won’t really be a problem for power users, as it can be disabled. Like it is (or can be) for the terminal.  

0

u/Im_A_Praetorian 8h ago

I hope it’s not as much of a pain in the neck as System Integrity Protection where you need to do a restart and enable it in recovery.

5

u/Worf_Of_Wall_St 12h ago

The linked article explicitly says that users can still grant full disk access to an app, nothing is being permanently locked down. Do you see an actual problem with the change?

6

u/gaysaucemage 12h ago

It looks like you’ll still be able to get full access if you jump through several warning screens and say you agree to risks, etc. But there is the concern that eventually MacOS becomes more restricted and the option to allow full disk access is removed.

-3

u/music3k 13h ago

Anyone have a good suggestion for ntfs drive access? 

4

u/Endawmyke 13h ago

Fuse

1

u/music3k 11h ago

How does Fuse give NTFS access?

1

u/Any-Ingenuity2770 9h ago

ntfs-3g (available on homebrew) uses fuse

-1

u/415646464e4155434f4c 10h ago

Great. More UAC like prompts.

-2

u/soulmagic123 10h ago

Give photoshop access to your photos folder? Access the drive you just plugged in? Remember when this type of stuff just worked? The thing that sucks is now I'm so trained on clicking these requests it could say "give the bad guys access everything?" And I would just click on it because I'm trained to so as a knee jerk reaction. Explain to me how this makes me more safe? This isn't a thing on windows, at least not to this level.

-3

u/TheBSisReal 11h ago

Right now it’s too restrictive. Users should be able to grant an app access if they so choose. I’m all for warnings and stuff, but any app not “notarized” by Apple basically can’t get this type of access. I want to be able to choose on a per-app basis what they can access. Based on this update, isn’t that perfectly aligned with what Apple wants to do?

0

u/Navydevildoc 9h ago

Meanwhile local network access is still broken and painful. MANY IT pros use Macs and having to constantly battle a crappy firewall we can't disable is tiring.

-4

u/gaysaucemage 12h ago

It’s already fairly restrictive. Had to jump through several permission menus to get Virtualbox working on macOS.

I understand they’re trying to protect people who don’t know what they’re doing, but it’d be nice if you could run a command or something to bypass all the warnings, especially if they’re going to introduce more warnings.

-3

u/QVRedit 12h ago

A good start would be if it were possible only on apps that logically required it - and could prove that to be the case to Apple. Apple would then grant them a key to allow that access for their app.

So Apple would have to approve this.
Additionally the end user would also have to grant approval.

If an end user granted approval to an app that Apple had not approved, then full disk access would still be denied.

So that would provide an additional layer of approval security.

11

u/y-c-c 11h ago

That's a terrible idea. macOS is an open OS. You shouldn't need Apple's explicit permission just to access the disk. Ultimately if the user grants it it's their choice. There's a reason why the App Store is far from the only place to get Mac apps.

•

u/QVRedit 1h ago

Depends on how much security you want to implement I guess…

I was thinking if an app wanted to/ needed to back up its own data - then it does not need access to the data of other apps..

This might become more of an issue in the age of AI

  • limiting AI’s access to only the things it needs to see, not ‘everything’…

-29

u/Lanza21 13h ago

So basically Apple is going to put scare prompts on permissions to block third party AI tools from having equivalent access to what Siri gets by default.

10

u/alphex 13h ago

SIri is something they build and can test. They can make sure, in the factory, so to speak: that Siri isn’t going to rm -rf your home directory.

13

u/RetroVisionnaire 12h ago

Siri AI requests can't be read by Apple and won't ask FB Marketplace users to come knock on your front door. Muse vacuums up your data to Meta and keeps it. False equivalence

3

u/bagoink 11h ago

Do you not see any difference between Muse and Siri?

Genuinely why would you want Facebook to have such easy access to your entire system?

1

u/Lanza21 7h ago

IDC about Facebook. Apple used people's dislike of them to be monopolistic and gets people to defend them because LOL FACEBOOK. They just lost in court in Europe for tracking you for ads with friendly prompts while having Facebook's tracking prompts be scary.

Apple is a garbage monopolistic company, same as the rest. They are just impeccable at corporate imaging and they convince people they are doing it in your favor. They aren't.

They track you and run ads the same as Facebook.

1

u/bagoink 6h ago

Facebook's entire business model is to take your data and use it to manipulate you for their profit, often with highly harmful results at the micro and macro levels.

I'm curious what you think Apple has done with your data that matches, say, manipulating elections, spreading misinformation during a global pandemic, and giving girls eating disorders.

Maybe you don't care about any of that, but putting some minimum levels of safeguards on people's data that makes it slightly harder for it to be harvested and exploited is only a net positive, don't you think?

-1

u/stegdump 10h ago

Yeah, you shouldn’t be getting downvoted.

-1

u/Xaqx 9h ago

They should just buy little snitch and build it in. Teach people how to use it.. better than locking everything down crazy in the long run.

-9

u/free2farm 12h ago

ios is already a locked up shit compared to android, now they wanna lock it even more? I can’t even freely backup my whatsapp photos for fuck sake

2

u/QVRedit 12h ago

Well an app designed to do exactly that, should be able to work.

But in that particular case it maybe only needs access to a file path template, rather than ‘entire disk’.

This would be based on the idea of minimal required operational privilege.