‹ BackHN Continuity

Thread

Updates to Full Disk Access in macOS

309 points · 219 comments · notfirstpost

  1. moecables · · focus · HN ↗
    IMHO, it's good to add more specific controls for this. After reading this, I went and checked my list of app with full disk access:

    - Ghostty (fine, it's my terminal)

    - Alfred (fine, I use it for searching everywhere)

    Then I have a few turned off:

    - Spotify (why does it need full disk access) ??

    - Gemini (nope, don't need it to know everything about my computer)

    1. 0c3ca83 · · focus · HN ↗
      - Ghostty (fine, it's my terminal)

      But your terminal shouldn't be accessing any files; you just need to be able to launch /bin/zsh or whatever you use as your shell. The shell needs to be able to access files, but its container doesn't.

      Of course, you could go farther. For example, on OpenBSD, even /bin/ksh has been somewhat sandboxed; it can see most of the file system, but the things it can do have been limited:

        if (pledge("stdio rpath wpath cpath fattr flock getpw proc "
            "exec tty id", NULL) == -1) {
      1. saagarjha · · focus · HN ↗
        macOS attributes shell commands to their parent app bundle.
        1. 0c3ca83 · · focus · HN ↗
          That seems like a massive hole in the model that would make it very hard to lock down multi-process/privsep programs like sshd.
          1. saagarjha · · focus · HN ↗
            Sandboxing something like that is challenging, yes. But probably not for this reason you can always disclaim responsibility for your process.
            1. 0c3ca83 · · focus · HN ↗
              It really isn't; the program just needs to be able to declare what it expects it should be able to do, and what it expects its children should be able to do. The latter doesn't need to be a subset of the former.
              1. saagarjha · · focus · HN ↗
                This is really hard to do in general
                1. 0c3ca83 · · focus · HN ↗
                  It's done on the majority of the OpenBSD base system, as well as important ports like Chrome and Firefox. Linux also has the parts to do this, though it's more fragile and complicated.
                  1. saagarjha · · focus · HN ↗
                    To be clear I have a much higher standard for what is acceptable than that, you really need to consider software that a hundred million people are going to use
                2. eviks · · focus · HN ↗
                  Indeed, is only the OS mastermind had billions and years to fix the foundation...
                  1. saagarjha · · focus · HN ↗
                    While looking at resources invested is necessarily a great measure of difficulty, it is somewhat indicative, yes.
                    1. eviks · · focus · HN ↗
                      you mean "isn't"? Though there is no indication that a lot was invested, so doesn't give you the measure (my comment was about the availability of resources, not of their actual use)
                      1. saagarjha · · focus · HN ↗
                        I did yes, sorry
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.