‹ BackHN Continuity

Thread

Updates to Full Disk Access in macOS

309 points · 219 comments · notfirstpost

  1. eviks · · focus · HN ↗
    > We give developers powerful APIs to build incredible capabilities

    > Full Disk Access largely sidesteps these controls

    That's because you don't really. Just like you don't give users "powerfulf" controls, so instead they have to resort to dumb ones like "Full disk"

    For example, if you care about "mail, messages, and even browsing history", why isn't there a subset of "full disk access except for reading mail/messages/browsing history"? Or if vibe code have some basic disk sizing functionality to ask questions about your files, why can't it have a more granular "full disk read only access for file sizes only" so that your vibe coded disk visualization app can't destroy your data or your privacy

    > can only do so with very explicit user action.

    Which is in the same vein and is mostly useless, just another inconvenient bump

    1. thomas_witt · · focus · HN ↗
      I totally agree. It's a shame that the ACL stuff in UNIX-based systems hasn't been changed in the last 20 years (xattr doesn't count).
      1. nikanj · · focus · HN ↗
        Has it substantially changed since the 1970s introduction of user / group / others octal permissions?
        1. JdeBP · · focus · HN ↗
          Yes. The name that you should look up is Trusix.
          1. mmooss · · focus · HN ↗
            Trusted Unix Working Group (Trusix) Rationale for Selecting Access Control List Features for the Unix System

            <a href="https:&#x2F;&#x2F;irp.fas.org&#x2F;nsa&#x2F;rainbow&#x2F;tg020-a.htm" rel="nofollow">https:&#x2F;&#x2F;irp.fas.org&#x2F;nsa&#x2F;rainbow&#x2F;tg020-a.htm

            What is the signficance now of this 1989 report?

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.