‹ BackHN Continuity

Thread

Updates to Full Disk Access in macOS

309 points · 219 comments · notfirstpost

  1. liuliu · · focus · HN ↗
    I don’t quite understand why people complains this is bad for AI agents. Local Code (<a href="https:&#x2F;&#x2F;releases.drawthings.ai&#x2F;p&#x2F;public-beta-of-local-code-by-draw" rel="nofollow">https:&#x2F;&#x2F;releases.drawthings.ai&#x2F;p&#x2F;public-beta-of-local-code-b...) doesn’t require full disk access, when you ask the agent to deal with some files it doesn’t have access to, the built-in ‘permit’ tool will trigger the OS folder grant interface and that information will be recorded both by Apple and by the app so it can be revoked later if you want. That allows you to not give full disk access to the app to be useful.
    1. wpm · · focus · HN ↗
      If anything in a world with agents, these TCC dialogs just need to have an &quot;allow once&quot;, just like Location Services has on iOS, and just like most harnesses have, a la &quot;Do you want to allow $AGENT to run the following command?&quot; A. Yes. B. Yes and don&#x27;t ask for $command, C. No but instead just asking &quot;Do you want to allow Claude Desktop access to files and folders on your Desktop?&quot; A. Once. B. Always C. No

      I think the issue comes in with terminal emulators and CLI harnesses. TCC permissions are inherited from the &quot;responsible&quot; process, so if you grant Terminal.app or ghostty.app FDA, you&#x27;ve granted zsh or bash or python or any goddamned thing you can run in a shell FDA.

      1. liuliu · · focus · HN ↗
        It is! The directory grant is once and the sandboxed app can save the bookmark for the future access. As a agent program, you can display this so users can revoke &#x2F; temporarily disable access for a period of time: <a href="https:&#x2F;&#x2F;developer.apple.com&#x2F;documentation&#x2F;foundation&#x2F;nsurl&#x2F;startaccessingsecurityscopedresource()?language=objc" rel="nofollow">https:&#x2F;&#x2F;developer.apple.com&#x2F;documentation&#x2F;foundation&#x2F;nsurl&#x2F;s...

        Agree, I think for CLI harness, there is no good alternative, you either have access permit per terminal app (which is not ideal), or I guess that is what Apple means they will &quot;address&quot; it?

    2. tannertech · · focus · HN ↗

      [dead]

    3. tekacs · · focus · HN ↗
      Because it&#x27;s deeply annoying&#x2F;unenjoyable to have to click &quot;Allow&quot; in the middle of a flow, especially if you&#x27;re not at the time actually _at_ your computer?
      1. liuliu · · focus · HN ↗
        Just add to system prompt: “ask permissions for files and folders you might need upfront. Don’t annoy users with permission request in the middle of the flow.”
        1. atonse · · focus · HN ↗
          This works alright.

          In fact, my pet peeve is why can&#x27;t 1Password build in the ability to &quot;remotely&quot; approve something via the 1Password app? I&#x27;d get a push message, hit allow, and it does the negotiation in an e2e encrypted way.

          Then I could approve something my agent needs when I&#x27;m not at the computer. Service Accounts are a crappy solution to be honest.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.