‹ BackHN Continuity

Thread

Updates to Full Disk Access in macOS

309 points · 219 comments · notfirstpost

  1. eviks · · focus · HN ↗
    > We give developers powerful APIs to build incredible capabilities

    > Full Disk Access largely sidesteps these controls

    That's because you don't really. Just like you don't give users "powerfulf" controls, so instead they have to resort to dumb ones like "Full disk"

    For example, if you care about "mail, messages, and even browsing history", why isn't there a subset of "full disk access except for reading mail/messages/browsing history"? Or if vibe code have some basic disk sizing functionality to ask questions about your files, why can't it have a more granular "full disk read only access for file sizes only" so that your vibe coded disk visualization app can't destroy your data or your privacy

    > can only do so with very explicit user action.

    Which is in the same vein and is mostly useless, just another inconvenient bump

    1. alin23 · · focus · HN ↗
      I have a file search app that does its own indexing similar to Everything on Windows (<a href="https:&#x2F;&#x2F;lowtechguys.com&#x2F;cling" rel="nofollow">https:&#x2F;&#x2F;lowtechguys.com&#x2F;cling) and I only index paths.

      I don&#x27;t need file contents, I can skip showing file sizes and date modified on protected paths. Hell I can skip indexing Mail and Messages files altogether since they&#x27;re pretty useless anyway. But how am I supposed to know beforehand which path will trigger a scary Cling wants to see your &lt;private folder&gt; when doing a simple traversal.

      Similarly, window switchers like my rcmd app (<a href="https:&#x2F;&#x2F;lowtechguys.com&#x2F;rcmd" rel="nofollow">https:&#x2F;&#x2F;lowtechguys.com&#x2F;rcmd) need access to window titles to function properly, but for that, the app has to ask for Screen Recording permissions. I don&#x27;t need to record anything, I just need the damn title text and users will be happy to give access to that, but not to recording the screen.

      This goes on and on.

      Want to register a more interesting hotkey like fn-letter? You have to act like a keylogger and ask for Input Monitoring.

      Want to focus a specific window instead of activating the app and letting the OS decide which window comes forward? You need Accessibility permissions and full access to control the whole computer.

      Want to paste some text into a text field? Accessibility Permissions.

      Too granular permissions is hell. But there are these decade-old common use cases for macOS utilities that would make it much easier to keep permissions locked if they became their own permissions.

      1. judge2020 · · focus · HN ↗
        &gt; Similarly, window switchers like my rcmd app (<a href="https:&#x2F;&#x2F;lowtechguys.com&#x2F;rcmd" rel="nofollow">https:&#x2F;&#x2F;lowtechguys.com&#x2F;rcmd) need access to window titles to function properly, but for that, the app has to ask for Screen Recording permissions. I don&#x27;t need to record anything, I just need the damn title text and users will be happy to give access to that, but not to recording the screen.

        Window titles can and often do contain very personal information. A window titled &quot;Planned Parenthood | Official Site&quot; in the hands of a bad actor or some relative-monitoring spyware could have disastrous consequences.

        &gt; Want to paste some text into a text field? Accessibility Permissions.

        Only if you aren&#x27;t relying on user-initiated pasting like right click &#x27; cmd+v.

        1. alin23 · · focus · HN ↗
          Of course, not saying those should be allowed by default. But being such often used in utilities, they would benefit from

              rcmd wants to read window titles. Allow? Deny?
          
          Instead of the scary and totally unnecessary screen recording permission.
          1. justsomehnguy · · focus · HN ↗
            I fully support you on your&#x27;s previous comment but here I need to remind you what it is you who understand the implication of that query. Regular Joe isn&#x27;t. And even more importantly is what the vendor is not on R.J. side, it is on the advertising side[0] where the excessive knowledge about a user is the thing.

            Like just 15 minuts ago I opened Untappd likr a bazillion times before and were present with 15 screens of toggles and like 250 entities at least. There were at least 10 permissions to give the consent to track the things I do outside the app.

            So not only a detailed reason for the permission wouldn&#x27;t work, it wouldn&#x27;t be implemented in the first place,

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.