I'm sure it'll be a permission the user can toggle. So they won't be taking away the ability for apps to see all the files but they'll be adding an extra layer of security so users can choose what an app can see. They're being light on details at the moment though.
But this is what it is currently. At the moment, not only is it a toggle, but unlike almost all other permissions, you can't just request the permission.
You have to send the user to the system settings pane for it and have them manually toggle it on there.
It's hard to imagine how it could be more explicit than it is currently. I imagine they have something draconian planned.
I don't know where this "ownership" debate came from. My ownership of my machine depends on strict, broad + fine grained control over what third-party devs (who are not me) get to do with my machine. Our interests are incompatible and hostile, in an era where most "native apps" ship analytics and marketing SDKs, or are videcoded. If macOS didn't offer these controls I would run every apps in a browser where it's sandboxed. This isn't the 90s.
This change is a reaction to a viral story from a tech reporter who shipped all his texts to Meta without meaning to, which tells you there's a consent and transparency issue for nontechnical users. I don't think anyone in the industry has figured out a proper solution. Unless you never interact with nontechnical people, it impacts your privacy indirectly no matter what you do. Though as technical user I hope we can get more fine-grained control and auditing.
Exactly. Third party software must be to some degree treated adversarially. Yes, even FLOSS software, as that can become subject to things like supply chain attacks. Giving any random program one downloads carte blanche access is as insane as leaving one's doors unlocked and open 24/7. It's inviting serious trouble.
> My ownership of my machine depends on strict, broad + fine grained control over what third-party devs (who are not me) get to do with my machine. Our interests are incompatible and hostile, in an era where most "native apps" ship analytics and marketing SDKs, or are videcoded. If macOS didn't offer these controls I would run every apps in a browser where it's sandboxed. This isn't the 90s.
There are benefits to sandboxing F/OSS too, but most of what you describe there are problems with proprietary software published by for-profit corporations and have dramatically less applicability to anything else.
macOS has been revoking access to stuff like this over the past decade. Things like unfettered access to modifying the OS went away with Gatekeeper and System Integrity Protection. "root" access is no longer true root on any Mac, and the user is treated like a prisoner. The UAC-esque prompts that come up in macOS would make Vista-era MS so jealous.
root access is also no longer true root access on a lot of linux distros that are immutable, and container-esque like interfaces such as namespaces + cgroups also limit roots power.
Pointless comment as the same holds true for macOS. Yes, you can load unsigned kext still, and yes, you can modify the userland. Not as easily, but I would argue it is also not harder as on an immutable linux distro.
being a nerd here, sudo - yes, but indeed I thought the entire UNIX design of everything is files and there are permissions, groups, etc, should be sufficient.
But I think the "new world" is, we are over stimulated (eg. agents ask us 'permissions' for a long command) so we might give a sudo not fully aware of it where a big bold UX message box after a 'pseudo' sudo would better catch our eyes.
So it seems this is about adding additional layers over already existing ones in a way?
I think its crazier that every app installed by default gets Cellular Data and on WiFi, its even worse because theres not even an option to granularly decide which apps should or shouldnt have that.
Things that have no conceivable need to phone home just get it for the hell of it. Its basically Full Disk Access but for Network Access which is arguably equally problematic
This isn't 1980 anymore. The internet is super hostile and everyone wants to extract data. You're still free to allow every app on your computer full access, I won't. I am very glad that none of the hundreds of apps installed across my phone and Mac can access my photos and cameras without permission.
My concern is that eventually Apple will require all apps (including non-App Store) to be specially approved by Apple in order to get full-disk-access, even if the end-user wants to allow it; like how there are no third-party iPhone/iPad backup apps.
I think GP was talking about backup apps that run on the iPhone/iPad itself.
It's still possible to back up an iPhone to a jailbroken computer, using roughly the same iTunes sync system that was available on iPods. For now.
>You're still free to allow every app on your computer full access, I won't.
Sure. Do I have to reboot the machine and put in special commands in the UEFI? Will the next OS update then revert that on me anyway? Will they silo all the data on a per-app database, then make the machine unjailbreakable?
I have little confidence that I am still free to do this much longer.
That's a reasonable concern and I do hope that there's an escape hatch, but it can't be as easy as "click here for full remote control" or else most people would just do that and fall victim. This already happens regularly and it's what privileged dialogs aim to prevent.
> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding.
If you think an app from (say) Facebook can be trusted with unrestricted access to your whole machine, you're at least a bit naive.
And despite hyperbole about Apple locking down macOS, ending the era of personal computing, it's hidden behind a toggle in settings. <a href="https://www.xkcd.com/1200/" rel="nofollow">https://www.xkcd.com/1200/ applies, and in the era of downloading random programs off the Internet and cryptocurrency, random programs should have to jump through an extra hoop before getting access to everything. Imo Apple went a bit overboard with granularity, but it's not 1990 and the Windows 98 (lack of) security model doesn't work, and neither does Unix permissions either.
It works just fine for any user with a modicum of sense. I know many people, not technical people at all, who avoid running malicious programs just fine. I don't see a reason why we should lock down everyone all for the sake of a minority who simply refuse to take responsibility or learn.
I am old, too, old enough to remember sending personal data over plain http with no encryption and needing to do a full wipe of Windows 98/XP machines on a periodic schedule just to keep viruses and malware off of them.
The idea that application A can just have full blown disk access and slurp up your tax returns or something was always a pretty crazy security posture. It just so happened that an honor system kind of almost sort of worked for a while.
You can’t really do an honor system when people are running artificial intelligence systems that have no concept of morality with full disk access.
Realistically we’re never going to be free of rowhammer and meltdown type attacks. Trying to prevent programs running on a computer from having full control of it just promotes a false sense of security.
If we read the article Apple isn’t planning to prevent programs from having full control, they’re just going to have better separation and user controls for “full disk access” versus “access to a limited subset of folders.”
This will allow programs like Spotify to only specify limited folder access while it’ll allow programs like Backblaze Backup
To specify full disk access.
No, you're not getting old. Tech companies are getting more and more paternalistic, refusing to treat users as adults who can make their own decisions. It's profoundly irritating.
When I hopped onto the Linux bandwagon in the 1990's, the community was touting its amazing security because any damage done was compartmentalized to a particular account. (Of course, that ignores root escalations. Of course, few Linux users cared about that back then because it was an obscure operating system.) In contrast, Macintosh and Windows (non-NT) security was non-existent.
These days, I find increasing security measures both burdensome and restrictive. That said, it is also necessary. We have long left the era when one could trust supposedly reputable software vendors -- never mind random developers.
Also, if you are really old, you may remember how unhappy people were when wheel group appeared, and not everyone could "su" to root anymore. Giving everyone root was supposed to be normal!
this is mostly a benefit to the owner. Every security feature , including firewalls, authorization ACLS, etc could potentially be used to reduce the owners rights, but they’ve all been necessary .
I’m with you on ownership, but push against signed code restrictions especially with bootloaders, and closed drivers.
Kim_Bruning · · focus · HN ↗
smith7018 · · focus · HN ↗
tekacs · · focus · HN ↗
You have to send the user to the system settings pane for it and have them manually toggle it on there.
It's hard to imagine how it could be more explicit than it is currently. I imagine they have something draconian planned.
pjmlp · · focus · HN ↗
chrisweekly · · focus · HN ↗
this is a majority of macos users (including many who are "technical")
concinds · · focus · HN ↗
I think so.
I don't know where this "ownership" debate came from. My ownership of my machine depends on strict, broad + fine grained control over what third-party devs (who are not me) get to do with my machine. Our interests are incompatible and hostile, in an era where most "native apps" ship analytics and marketing SDKs, or are videcoded. If macOS didn't offer these controls I would run every apps in a browser where it's sandboxed. This isn't the 90s.
This change is a reaction to a viral story from a tech reporter who shipped all his texts to Meta without meaning to, which tells you there's a consent and transparency issue for nontechnical users. I don't think anyone in the industry has figured out a proper solution. Unless you never interact with nontechnical people, it impacts your privacy indirectly no matter what you do. Though as technical user I hope we can get more fine-grained control and auditing.
cosmic_cheese · · focus · HN ↗
isityettime · · focus · HN ↗
There are benefits to sandboxing F/OSS too, but most of what you describe there are problems with proprietary software published by for-profit corporations and have dramatically less applicability to anything else.
Dylan16807 · · focus · HN ↗
VCFundedGenYer · · focus · HN ↗
littlecranky67 · · focus · HN ↗
debazel · · focus · HN ↗
littlecranky67 · · focus · HN ↗
rock_artist · · focus · HN ↗
But I think the "new world" is, we are over stimulated (eg. agents ask us 'permissions' for a long command) so we might give a sudo not fully aware of it where a big bold UX message box after a 'pseudo' sudo would better catch our eyes.
So it seems this is about adding additional layers over already existing ones in a way?
lokar · · focus · HN ↗
It has been extended, but not in a way that non-technical users can really use.
jeremyjh · · focus · HN ↗
Obscurity4340 · · focus · HN ↗
Things that have no conceivable need to phone home just get it for the hell of it. Its basically Full Disk Access but for Network Access which is arguably equally problematic
jeremyjh · · focus · HN ↗
etatester · · focus · HN ↗
DaiPlusPlus · · focus · HN ↗
zimpenfish · · focus · HN ↗
I might be missing something but isn't this exactly what iMazing[0] is? I know I use it to backup my iPhone, for example.
[0] <a href="https://imazing.com" rel="nofollow">https://imazing.com
csande17 · · focus · HN ↗
It's still possible to back up an iPhone to a jailbroken computer, using roughly the same iTunes sync system that was available on iPods. For now.
NoMoreNicksLeft · · focus · HN ↗
Sure. Do I have to reboot the machine and put in special commands in the UEFI? Will the next OS update then revert that on me anyway? Will they silo all the data on a per-app database, then make the machine unjailbreakable?
I have little confidence that I am still free to do this much longer.
etatester · · focus · HN ↗
spaqin · · focus · HN ↗
GeekyBear · · focus · HN ↗
> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding.
If you think an app from (say) Facebook can be trusted with unrestricted access to your whole machine, you're at least a bit naive.
fragmede · · focus · HN ↗
bigstrat2003 · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
comboy · · focus · HN ↗
charcircuit · · focus · HN ↗
Grombobulous · · focus · HN ↗
The idea that application A can just have full blown disk access and slurp up your tax returns or something was always a pretty crazy security posture. It just so happened that an honor system kind of almost sort of worked for a while.
You can’t really do an honor system when people are running artificial intelligence systems that have no concept of morality with full disk access.
bee_rider · · focus · HN ↗
Grombobulous · · focus · HN ↗
This will allow programs like Spotify to only specify limited folder access while it’ll allow programs like Backblaze Backup To specify full disk access.
chrisjj · · focus · HN ↗
Why would that stop at your computer's network socket?
chrisjj · · focus · HN ↗
Their problem is not lack of morality. It is simply being unreliable, untrustworthy and unsafe.
bigstrat2003 · · focus · HN ↗
II2II · · focus · HN ↗
When I hopped onto the Linux bandwagon in the 1990's, the community was touting its amazing security because any damage done was compartmentalized to a particular account. (Of course, that ignores root escalations. Of course, few Linux users cared about that back then because it was an obscure operating system.) In contrast, Macintosh and Windows (non-NT) security was non-existent.
These days, I find increasing security measures both burdensome and restrictive. That said, it is also necessary. We have long left the era when one could trust supposedly reputable software vendors -- never mind random developers.
iamcalledrob · · focus · HN ↗
happosai · · focus · HN ↗
<a href="https://xkcd.com/1200/" rel="nofollow">https://xkcd.com/1200/
Also, if you are really old, you may remember how unhappy people were when wheel group appeared, and not everyone could "su" to root anymore. Giving everyone root was supposed to be normal!
watt · · focus · HN ↗
tonymet · · focus · HN ↗
I’m with you on ownership, but push against signed code restrictions especially with bootloaders, and closed drivers.