> We give developers powerful APIs to build incredible capabilities
> Full Disk Access largely sidesteps these controls
That's because you don't really. Just like you don't give users "powerfulf" controls, so instead they have to resort to dumb ones like "Full disk"
For example, if you care about "mail, messages, and even browsing history", why isn't there a subset of "full disk access except for reading mail/messages/browsing history"? Or if vibe code have some basic disk sizing functionality to ask questions about your files, why can't it have a more granular "full disk read only access for file sizes only" so that your vibe coded disk visualization app can't destroy your data or your privacy
> can only do so with very explicit user action.
Which is in the same vein and is mostly useless, just another inconvenient bump
I have a file search app that does its own indexing similar to Everything on Windows (<a href="https://lowtechguys.com/cling" rel="nofollow">https://lowtechguys.com/cling) and I only index paths.
I don't need file contents, I can skip showing file sizes and date modified on protected paths. Hell I can skip indexing Mail and Messages files altogether since they're pretty useless anyway. But how am I supposed to know beforehand which path will trigger a scary Cling wants to see your <private folder> when doing a simple traversal.
Similarly, window switchers like my rcmd app (<a href="https://lowtechguys.com/rcmd" rel="nofollow">https://lowtechguys.com/rcmd) need access to window titles to function properly, but for that, the app has to ask for Screen Recording permissions. I don't need to record anything, I just need the damn title text and users will be happy to give access to that, but not to recording the screen.
This goes on and on.
Want to register a more interesting hotkey like fn-letter? You have to act like a keylogger and ask for Input Monitoring.
Want to focus a specific window instead of activating the app and letting the OS decide which window comes forward? You need Accessibility permissions and full access to control the whole computer.
Want to paste some text into a text field? Accessibility Permissions.
Too granular permissions is hell. But there are these decade-old common use cases for macOS utilities that would make it much easier to keep permissions locked if they became their own permissions.
> Similarly, window switchers like my rcmd app (<a href="https://lowtechguys.com/rcmd" rel="nofollow">https://lowtechguys.com/rcmd) need access to window titles to function properly, but for that, the app has to ask for Screen Recording permissions. I don't need to record anything, I just need the damn title text and users will be happy to give access to that, but not to recording the screen.
Window titles can and often do contain very personal information. A window titled "Planned Parenthood | Official Site" in the hands of a bad actor or some relative-monitoring spyware could have disastrous consequences.
> Want to paste some text into a text field? Accessibility Permissions.
Only if you aren't relying on user-initiated pasting like right click ' cmd+v.
I fully support you on your's previous comment but here I need to remind you what it is you who understand the implication of that query. Regular Joe isn't. And even more importantly is what the vendor is not on R.J. side, it is on the advertising side[0] where the excessive knowledge about a user is the thing.
Like just 15 minuts ago I opened Untappd likr a bazillion times before and were present with 15 screens of toggles and like 250 entities at least. There were at least 10 permissions to give the consent to track the things I do outside the app.
So not only a detailed reason for the permission wouldn't work, it wouldn't be implemented in the first place,
eviks · · focus · HN ↗
> Full Disk Access largely sidesteps these controls
That's because you don't really. Just like you don't give users "powerfulf" controls, so instead they have to resort to dumb ones like "Full disk"
For example, if you care about "mail, messages, and even browsing history", why isn't there a subset of "full disk access except for reading mail/messages/browsing history"? Or if vibe code have some basic disk sizing functionality to ask questions about your files, why can't it have a more granular "full disk read only access for file sizes only" so that your vibe coded disk visualization app can't destroy your data or your privacy
> can only do so with very explicit user action.
Which is in the same vein and is mostly useless, just another inconvenient bump
alin23 · · focus · HN ↗
I don't need file contents, I can skip showing file sizes and date modified on protected paths. Hell I can skip indexing Mail and Messages files altogether since they're pretty useless anyway. But how am I supposed to know beforehand which path will trigger a scary Cling wants to see your <private folder> when doing a simple traversal.
Similarly, window switchers like my rcmd app (<a href="https://lowtechguys.com/rcmd" rel="nofollow">https://lowtechguys.com/rcmd) need access to window titles to function properly, but for that, the app has to ask for Screen Recording permissions. I don't need to record anything, I just need the damn title text and users will be happy to give access to that, but not to recording the screen.
This goes on and on.
Want to register a more interesting hotkey like fn-letter? You have to act like a keylogger and ask for Input Monitoring.
Want to focus a specific window instead of activating the app and letting the OS decide which window comes forward? You need Accessibility permissions and full access to control the whole computer.
Want to paste some text into a text field? Accessibility Permissions.
Too granular permissions is hell. But there are these decade-old common use cases for macOS utilities that would make it much easier to keep permissions locked if they became their own permissions.
judge2020 · · focus · HN ↗
Window titles can and often do contain very personal information. A window titled "Planned Parenthood | Official Site" in the hands of a bad actor or some relative-monitoring spyware could have disastrous consequences.
> Want to paste some text into a text field? Accessibility Permissions.
Only if you aren't relying on user-initiated pasting like right click ' cmd+v.
alin23 · · focus · HN ↗
justsomehnguy · · focus · HN ↗
Like just 15 minuts ago I opened Untappd likr a bazillion times before and were present with 15 screens of toggles and like 250 entities at least. There were at least 10 permissions to give the consent to track the things I do outside the app.
So not only a detailed reason for the permission wouldn't work, it wouldn't be implemented in the first place,