‹ BackHN Continuity

Thread

Updates to Full Disk Access in macOS

309 points · 219 comments · notfirstpost

  1. post_break · · focus · HN ↗
    One update away to revoking Full Disk Access in the future. This commercial has come full circle: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=VuqZ8AqmLPY" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=VuqZ8AqmLPY
    1. etatester · · focus · HN ↗
      Please do. Too many applications have too much access. Why do people not realize they installed literal Trojan horses that visit websites and execute commands found on them (prompt injection)?
      1. spaqin · · focus · HN ↗
        Accessing any website is basically Remote Code Execution, but for some reason starting up a browser isn&#x27;t a CVE.
        1. etatester · · focus · HN ↗
          Good example because all that code is indeed run sandboxed, which is exactly what we need in native apps as well. &quot;Any website&quot; cannot access anything on my computer without explicit and often temporary permission.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.