‹ BackHN Continuity

Thread

Updates to Full Disk Access in macOS

309 points · 219 comments · notfirstpost

  1. Kim_Bruning · · focus · HN ↗
    Am I getting old? "full disk access" used to be something that's supposed to be normal; if you're the owner of the machine.
    1. Grombobulous · · focus · HN ↗
      I am old, too, old enough to remember sending personal data over plain http with no encryption and needing to do a full wipe of Windows 98/XP machines on a periodic schedule just to keep viruses and malware off of them.

      The idea that application A can just have full blown disk access and slurp up your tax returns or something was always a pretty crazy security posture. It just so happened that an honor system kind of almost sort of worked for a while.

      You can’t really do an honor system when people are running artificial intelligence systems that have no concept of morality with full disk access.

      1. bee_rider · · focus · HN ↗
        Realistically we’re never going to be free of rowhammer and meltdown type attacks. Trying to prevent programs running on a computer from having full control of it just promotes a false sense of security.
        1. Grombobulous · · focus · HN ↗
          If we read the article Apple isn’t planning to prevent programs from having full control, they’re just going to have better separation and user controls for “full disk access” versus “access to a limited subset of folders.”

          This will allow programs like Spotify to only specify limited folder access while it’ll allow programs like Backblaze Backup To specify full disk access.

        2. chrisjj · · focus · HN ↗
          > Trying to prevent programs running on a computer from having full control of it just promotes a false sense of security.

          Why would that stop at your computer's network socket?

      2. chrisjj · · focus · HN ↗
        > artificial intelligence systems that have no concept of morality

        Their problem is not lack of morality. It is simply being unreliable, untrustworthy and unsafe.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.