‹ BackHN Continuity

Thread

Updates to Full Disk Access in macOS

309 points · 219 comments · notfirstpost

  1. moecables · · focus · HN ↗
    IMHO, it's good to add more specific controls for this. After reading this, I went and checked my list of app with full disk access:

    - Ghostty (fine, it's my terminal)

    - Alfred (fine, I use it for searching everywhere)

    Then I have a few turned off:

    - Spotify (why does it need full disk access) ??

    - Gemini (nope, don't need it to know everything about my computer)

    1. coderbants · · focus · HN ↗
      Terminal is a significant risk though and I’d still really like to see macOS improve the APIs around filesystem access.

      Granting terminal full disk access grants arbitrary scripts full disk access. There’s a lot you can do with ACLs and the permissions system, but it’s not reflected in the UI for settings.

      Then there’s allowing access to documents, downloads, desktop, external disks. This should really allow the user to select a path or paths for applications, because these options are way too broad (especially external disks).

      1. [deleted] · · focus · HN ↗

        [deleted]

      2. ashishb · · focus · HN ↗
        > Granting terminal full disk access grants arbitrary scripts full disk access.

        Indeed, I run all dev tools including coding agents inside sandbox now

        <a href="https:&#x2F;&#x2F;github.com&#x2F;ashishb&#x2F;amazing-sandbox" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;ashishb&#x2F;amazing-sandbox

        1. jackjeff · · focus · HN ↗
          I do the same but I rely on devcontainers because editors like vscode, zed, etc… provide native support. It seems easier to use than asb.

          If you open a project using a devcontainer it prompts you to build one. As long as you install all the tools you need in it, it just works.

          Orbstack is much nicer than Docker to host the containers.

      3. jshier · · focus · HN ↗
        This is why I use Terminal as my primary terminal, and iTerm as my AI terminal. iTerm gets no permissions, I move specific things to Terminal to do it. Plus I can then style them to optimize for the different usages. And iTerm has better harness hooks anyway.

        I would still like to see not only more granular permissions, but single use permissions. Once I grant iTerm access to Documents for whatever reason, it always has such permission. I would be nice to limit that to a single use, or a single harness session.

      4. ghusto · · focus · HN ↗
        &gt; Granting terminal full disk access grants arbitrary scripts full disk access

        No, it grants scripts I run full disk access. Unvetted scripts do not run in my terminal, so there are no secret sub-processes either.

      5. m463 · · focus · HN ↗
        I would want terminal and all its subprocesses to have full disk access - I do tons of stuff from the command line and don&#x27;t run nonsense stuff.

        get out of my way.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.