Remix.run Logo
▲ Updates to Full Disk Access in macOS(developer.apple.com)
154 points by notfirstpost 9 hours ago | 91 comments
▲eviks 2 minutes ago | parent | next [-]

> We give developers powerful APIs to build incredible capabilities

> Full Disk Access largely sidesteps these controls

That's because you don't really. Just like you don't give users "powerfulf" controls, so instead they have to resort to dumb ones like "Full disk"

For example, if you care about "mail, messages, and even browsing history", why isn't there a subset of "full disk access except for reading mail/messages/browsing history"? Or if vibe code have some basic disk sizing functionality to ask questions about your files, why can't it have a more granular "full disk read only access for file sizes only" so that your vibe coded disk visualization app can't destroy your data or your privacy

> can only do so with very explicit user action.

Which is in the same vein and is mostly useless, just another inconvenient bump

▲liuliu 5 hours ago | parent | prev | next [-]

I don’t quite understand why people complains this is bad for AI agents. Local Code (https://releases.drawthings.ai/p/public-beta-of-local-code-b...) doesn’t require full disk access, when you ask the agent to deal with some files it doesn’t have access to, the built-in ‘permit’ tool will trigger the OS folder grant interface and that information will be recorded both by Apple and by the app so it can be revoked later if you want. That allows you to not give full disk access to the app to be useful.

▲wpm 4 hours ago | parent [-]

If anything in a world with agents, these TCC dialogs just need to have an "allow once", just like Location Services has on iOS, and just like most harnesses have, a la "Do you want to allow $AGENT to run the following command?" A. Yes. B. Yes and don't ask for $command, C. No but instead just asking "Do you want to allow Claude Desktop access to files and folders on your Desktop?" A. Once. B. Always C. No

I think the issue comes in with terminal emulators and CLI harnesses. TCC permissions are inherited from the "responsible" process, so if you grant Terminal.app or ghostty.app FDA, you've granted zsh or bash or python or any goddamned thing you can run in a shell FDA.

▲liuliu 32 minutes ago | parent [-]

It is! The directory grant is once and the sandboxed app can save the bookmark for the future access. As a agent program, you can display this so users can revoke / temporarily disable access for a period of time: https://developer.apple.com/documentation/foundation/nsurl/s...

Agree, I think for CLI harness, there is no good alternative, you either have access permit per terminal app (which is not ideal), or I guess that is what Apple means they will "address" it?

▲moecables 8 hours ago | parent | prev | next [-]

IMHO, it's good to add more specific controls for this. After reading this, I went and checked my list of app with full disk access:

- Ghostty (fine, it's my terminal)

- Alfred (fine, I use it for searching everywhere)

Then I have a few turned off:

- Spotify (why does it need full disk access) ??

- Gemini (nope, don't need it to know everything about my computer)

▲coderbants 8 hours ago | parent | next [-]

Terminal is a significant risk though and I’d still really like to see macOS improve the APIs around filesystem access.

Granting terminal full disk access grants arbitrary scripts full disk access. There’s a lot you can do with ACLs and the permissions system, but it’s not reflected in the UI for settings.

Then there’s allowing access to documents, downloads, desktop, external disks. This should really allow the user to select a path or paths for applications, because these options are way too broad (especially external disks).

▲jshier 5 hours ago | parent | next [-]

This is why I use Terminal as my primary terminal, and iTerm as my AI terminal. iTerm gets no permissions, I move specific things to Terminal to do it. Plus I can then style them to optimize for the different usages. And iTerm has better harness hooks anyway.

I would still like to see not only more granular permissions, but single use permissions. Once I grant iTerm access to Documents for whatever reason, it always has such permission. I would be nice to limit that to a single use, or a single harness session.

▲ashishb 5 hours ago | parent | prev [-]

> Granting terminal full disk access grants arbitrary scripts full disk access.

Indeed, I run all dev tools including coding agents inside sandbox now

https://github.com/ashishb/amazing-sandbox

▲king_geedorah 2 hours ago | parent | prev | next [-]

Spotify has (had? I no longer use it) a feature that would allow you to make local media available as part of your library anywhere so long as your machine was on and connected to the internet. I would imagine that feature requires disk access under these sandbox / permission models.

Edit: I should say, the model it was created with (select a folder, all media in that folder is mirrored) requires such permissions. One could imagine designs that don’t.

▲0c3ca83 4 hours ago | parent | prev | next [-]

- Ghostty (fine, it's my terminal)

But your terminal shouldn't be accessing any files; you just need to be able to launch /bin/zsh or whatever you use as your shell. The shell needs to be able to access files, but its container doesn't.

Of course, you could go farther. For example, on OpenBSD, even /bin/ksh has been somewhat sandboxed; it can see most of the file system, but the things it can do have been limited:

  if (pledge("stdio rpath wpath cpath fattr flock getpw proc "
      "exec tty id", NULL) == -1) {
▲rolosa 4 hours ago | parent | next [-]

If you try to ls / for example it's going to pop up a request to access your disk, multiple times. It's rather annoying.

▲0c3ca83 2 hours ago | parent [-]

Why would ghostty try to access your disk when you run 'ls /'? ghostty isn't opening any files -- ls is.

▲dcrazy 2 hours ago | parent [-]

The TCC system attributes the access to Ghostty because that’s the thing the user understands as the app they are interacting with. Otherwise every `posix_spawn()` and `system()` call would result in a new TCC prompt attributed to an inscrutable name.

▲saagarjha 4 hours ago | parent | prev [-]

macOS attributes shell commands to their parent app bundle.

▲0c3ca83 2 hours ago | parent | next [-]

That seems like a massive hole in the model that would make it very hard to lock down multi-process/privsep programs like sshd.

▲saagarjha 2 hours ago | parent [-]

Sandboxing something like that is challenging, yes. But probably not for this reason you can always disclaim responsibility for your process.

▲0c3ca83 2 hours ago | parent [-]

It really isn't; the program just needs to be able to declare what it expects it should be able to do, and what it expects its children should be able to do. The latter doesn't need to be a subset of the former.

▲dcrazy 2 hours ago | parent | next [-]

That “just” is doing a LOT of work.

▲0c3ca83 2 hours ago | parent [-]

It's already done on OpenBSD, and linux has the pieces to do it, though it's far more fragile and complicated. I'm not speaking hypothetically here, I've implemented code that works this way.

▲dcrazy an hour ago | parent [-]

You are minimizing the difference in scope between the audience and applications of OpenBSD and those of macOS.

macOS has had a capabilities model for over a decade called App Sandboxing. It would be entirely impractical to expect app authors to correctly declare their permissions up front and for users to audit them. Hence the permissions granted to sandboxed apps are pre-determined by the OS, and can be extended through explicit user interaction.

▲saagarjha 2 hours ago | parent | prev [-]

This is really hard to do in general

▲0c3ca83 2 hours ago | parent [-]

It's done on the majority of the OpenBSD base system, as well as important ports like Chrome and Firefox. Linux also has the parts to do this, though it's more fragile and complicated.

▲joshspankit 4 hours ago | parent | prev [-]

Indeed. It’s very inconvenient to ‘cd` and have to do the whole permission dance to read a file

▲musicale an hour ago | parent | prev | next [-]

But how is Gemini going to repair your filesystem and restore lost or deleted data?

▲smcleod 4 hours ago | parent | prev [-]

I wouldn't allow your terminal full disk access, that's quite a risk vector.

▲mrkpdl 8 hours ago | parent | prev | next [-]

I would like the ability to see which specific folders I have granted access to on an app by app basis. And edit. It’s not clear to me how you revoke an app’s individual folder access after you have granted it.

▲kccqzy 8 hours ago | parent [-]

I have been wanting this for years.

For those who haven’t heard of this, sandboxed apps can request access to a file or folder and persist such access using a security-scoped bookmark. The user however does not know whether the app chooses to persist this bookmark or not; in other words the user does not know whether in each case they are granting a one-time access or persistent access.

▲lapcat 8 hours ago | parent [-]

This is unrelated to Full Disk Access, though.

There are already folder-specific permissions for every app, including non-sandboxed apps: Desktop, Documents, Downloads. FDA is "everything else". The user has to specifically grant each of those permissions via a system dialog.

With sandboxed apps, you grant access to a file outside the sandbox via a system dialog, open or save. But with non-sandboxed apps, if there were separate permissions for each specific folder, there would have to be separate permission dialogs for each of those folders, and then macOS would become even more of a permissions dialog hell than it already is.

▲post_break 9 hours ago | parent | prev | next [-]

One update away to revoking Full Disk Access in the future. This commercial has come full circle: https://www.youtube.com/watch?v=VuqZ8AqmLPY

▲jeremyjh 8 hours ago | parent | next [-]

You could say that about anything, in any OS. Windows is one update away from insulting the user whenever they login. MacOS is one update away from mining crypto for Apple. Android is one update away from sending spam to all your contacts.

▲DaiPlusPlus 3 hours ago | parent [-]

I think it’s the threshold of them getting-away-with-it without too many people wielding pitchforks.

▲etatester 8 hours ago | parent | prev | next [-]

Please do. Too many applications have too much access. Why do people not realize they installed literal Trojan horses that visit websites and execute commands found on them (prompt injection)?

▲troupo 42 minutes ago | parent [-]

Because tgst's how computers have worked and should work forever? Without a corporate unerlord randomly restricting access to useful functionality and without inane permission popups for every action?

▲cung 8 hours ago | parent | prev | next [-]

Hah! I had forgotten this ad. Using a mac nowadays is definitely just like Windows Vista in this ad.

▲steve-atx-7600 8 hours ago | parent | prev | next [-]

Need some Vaseline for your slope?

▲nozzlegear 5 hours ago | parent | prev [-]

Inshallah

▲PeanutOS 3 hours ago | parent | prev | next [-]

This week, I formatted my entire Mac fleet (an iMac Pro and four MacBooks), and now neither AI agent runs natively. I am using LIMA (https://lima-vm.io) to isolate them in a sandbox, exposing only a repository. I lose some integration, but the peace of mind is worth it.

▲Kim_Bruning 8 hours ago | parent | prev | next [-]

Am I getting old? "full disk access" used to be something that's supposed to be normal; if you're the owner of the machine.

▲concinds 8 hours ago | parent | next [-]

> Am I getting old?

I think so.

I don't know where this "ownership" debate came from. My ownership of my machine depends on strict, broad + fine grained control over what third-party devs (who are not me) get to do with my machine. Our interests are incompatible and hostile, in an era where most "native apps" ship analytics and marketing SDKs, or are videcoded. If macOS didn't offer these controls I would run every apps in a browser where it's sandboxed. This isn't the 90s.

This change is a reaction to a viral story from a tech reporter who shipped all his texts to Meta without meaning to, which tells you there's a consent and transparency issue for nontechnical users. I don't think anyone in the industry has figured out a proper solution. Unless you never interact with nontechnical people, it impacts your privacy indirectly no matter what you do. Though as technical user I hope we can get more fine-grained control and auditing.

▲cosmic_cheese 11 minutes ago | parent [-]

Exactly. Third party software must be to some degree treated adversarially. Yes, even FLOSS software, as that can become subject to things like supply chain attacks. Giving any random program one downloads carte blanche access is as insane as leaving one's doors unlocked and open 24/7. It's inviting serious trouble.

▲Grombobulous an hour ago | parent | prev | next [-]

I am old, too, old enough to remember sending personal data over plain http with no encryption and needing to do a full wipe of Windows 98/XP machines on a periodic schedule just to keep viruses and malware off of them.

The idea that application A can just have full blown disk access and slurp up your tax returns or something was always a pretty crazy security posture. It just so happened that an honor system kind of almost sort of worked for a while.

You can’t really do an honor system when people are running artificial intelligence systems that have no concept of morality with full disk access.

▲etatester 8 hours ago | parent | prev | next [-]

This isn't 1980 anymore. The internet is super hostile and everyone wants to extract data. You're still free to allow every app on your computer full access, I won't. I am very glad that none of the hundreds of apps installed across my phone and Mac can access my photos and cameras without permission.

▲DaiPlusPlus 3 hours ago | parent | next [-]

My concern is that eventually Apple will require all apps (including non-App Store) to be specially approved by Apple in order to get full-disk-access, even if the end-user wants to allow it; like how there are no third-party iPhone/iPad backup apps.

▲NoMoreNicksLeft an hour ago | parent | prev [-]

>You're still free to allow every app on your computer full access, I won't.

Sure. Do I have to reboot the machine and put in special commands in the UEFI? Will the next OS update then revert that on me anyway? Will they silo all the data on a per-app database, then make the machine unjailbreakable?

I have little confidence that I am still free to do this much longer.

▲jeremyjh 8 hours ago | parent | prev | next [-]

I’m 50 and I think it’s crazy we ever thought it was acceptable to give every app you run full access to all the files on your computer by default.

▲VCFundedGenYer 8 hours ago | parent | prev | next [-]

macOS has been revoking access to stuff like this over the past decade. Things like unfettered access to modifying the OS went away with Gatekeeper and System Integrity Protection. "root" access is no longer true root on any Mac, and the user is treated like a prisoner. The UAC-esque prompts that come up in macOS would make Vista-era MS so jealous.

▲littlecranky67 8 hours ago | parent [-]

root access is also no longer true root access on a lot of linux distros that are immutable, and container-esque like interfaces such as namespaces + cgroups also limit roots power.

▲GeekyBear 8 hours ago | parent | prev | next [-]

TFA:

> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding.

If you think an app from (say) Facebook can be trusted with unrestricted access to your whole machine, you're at least a bit naive.

▲pjmlp 8 hours ago | parent | prev | next [-]

Only on systems without proper user management, or if the owner is logged in as the administrator.

▲rock_artist 8 hours ago | parent | prev | next [-]

being a nerd here, sudo - yes, but indeed I thought the entire UNIX design of everything is files and there are permissions, groups, etc, should be sufficient.

But I think the "new world" is, we are over stimulated (eg. agents ask us 'permissions' for a long command) so we might give a sudo not fully aware of it where a big bold UX message box after a 'pseudo' sudo would better catch our eyes.

So it seems this is about adding additional layers over already existing ones in a way?

▲lokar 8 hours ago | parent [-]

The UNIX model assumed each human had one user. It did not provide a flexible way to sub-divide that scope for each program running as that user.

It has been extended, but not in a way that non-technical users can really use.

▲comboy 4 hours ago | parent | prev | next [-]

Do you run every process as root?

▲charcircuit 3 hours ago | parent | prev | next [-]

The software running isn't the owner though.

▲fragmede 8 hours ago | parent | prev | next [-]

And despite hyperbole about Apple locking down macOS, ending the era of personal computing, it's hidden behind a toggle in settings. https://www.xkcd.com/1200/ applies, and in the era of downloading random programs off the Internet and cryptocurrency, random programs should have to jump through an extra hoop before getting access to everything. Imo Apple went a bit overboard with granularity, but it's not 1990 and the Windows 98 (lack of) security model doesn't work, and neither does Unix permissions either.

▲smith7018 8 hours ago | parent | prev [-]

I'm sure it'll be a permission the user can toggle. So they won't be taking away the ability for apps to see all the files but they'll be adding an extra layer of security so users can choose what an app can see. They're being light on details at the moment though.

▲tekacs 8 hours ago | parent [-]

But this is what it is currently. At the moment, not only is it a toggle, but unlike almost all other permissions, you can't just request the permission.

You have to send the user to the system settings pane for it and have them manually toggle it on there.

It's hard to imagine how it could be more explicit than it is currently. I imagine they have something draconian planned.

▲etatester 8 hours ago | parent | prev | next [-]

What we need is true application isolation even in the command line. Treat Terminal as privileged access, not something any app can just command. Sandbox non-app store apps as well.

▲kccqzy 8 hours ago | parent | next [-]

Whenever I ask Claude to vibecode macOS native apps for me, I always request the apps to be sandboxed. Agents know how to sandbox the apps; just ask. And you can verify it without reading any code.

▲JakaJancar 8 hours ago | parent | prev [-]

Just use an iPad?

▲zmmmmm 4 hours ago | parent | prev | next [-]

It's fine if there is a super streamlined flow for access that works with legacy apps and runs in user-mode. Otherwise this might seriously hurt MacOS as a viable development platform.

▲profmonocle 4 hours ago | parent | prev | next [-]

> we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so

"Extraordinary" is a funny word choice. It was completely ordinary for most of the history of personal computing that any app you ran under your normal user account could see everything you had.

(I'm not saying this is a bad thing. As long as they allow informed users to continue to do whatever they please, I'm all for it.)

▲jameskraus 8 hours ago | parent | prev | next [-]

Oh no, even more permission prompts on macOS. It's already almost unusable due to the existing ones.

▲whartung 8 hours ago | parent | next [-]

Folks like to cite how capability OSes are a great thing, and I certainly appreciate the concept, and, no, MacOS, is not a capability OS.

However, it feels like one to the User. Having to get constantly prompted to grant permissions they don't even necessarily understand to random programs.

There's been chatter about how system like iOS are not "document based", they're app based. Many apps do not present their data as "files", users don't know where their data resides, just that the app knows and that's their window.

I don't know where an application on MacOS can "save their files" if they don't have "Full Disk Access". I don't know if they get some directory "for free" that they can use much like iOS does.

Then, of course, there's the Apple Document model where data auto saves to Somewhere. You have versioned files you can work with. But until you actually "save" the file to "the disk", its living in some unannounced space. My TextEdit app has dozens of "Untitled-XX" files that are...somewhere.

And its great! There's a peace of just having "stacks of stuff" that you can leave "unmanaged". "Where would you like to save your work?" "Oh, great, cognitive load just exploded as need to think about the minutia of data organization, when, mostly I just "don't want to lose this".

But, the constant prompting is exhausting, to me. Again, I have to "think about it". I need to question everything, when I really just want to Get Stuff Done.

And, in time, we become blind to these prompts. "ok, Ok, OK!! GO ALREADY! JUST WORK!!".

Exhausting.

▲umpalumpaaa 2 hours ago | parent [-]

Sandboxed Mac apps have access to their own container which includes directories like Documents/ and a temporary directory and more where they can save anything just like on iOS.

▲dcrazy 2 hours ago | parent [-]

That’s not quite how macOS sandboxing works. Users expect to be able to save and open (non-iCloud Drive) files in ~/Documents, not in a containerized silo. If the app uses NSOpenPanel/NSSavePanel, those work with the system to grant the app a sandbox extension to the location the user chooses in the open or save panel.

▲VCFundedGenYer 8 hours ago | parent | prev [-]

It's really gotten out of hand. Trying to literally plug something in results in at least one (sometimes multiple) prompts being like "are you SUUUUURE you want this plugged in?"

▲plantain an hour ago | parent | prev | next [-]

"Updates to-" instills such a deep-rooted fear in me. I know whatever follows is about to suck.

▲VCFundedGenYer 8 hours ago | parent | prev | next [-]

If it worked as intended, they wouldn't be in this predicament.

That feature was so stupidly nonfunctional before. Some apps got stopped by it, others didn't. Often you'd be able to install an app from homebrew and it had full ride access to the disk, while App Store apps had to request consent for any folder whatsoever. It was completely random.

▲pkulak 8 hours ago | parent | prev | next [-]

I feel like this isn't going to be a simple permission popup. Probably along the lines of getting an "unapproved" binary to run, where you have to stop what you're doing and wade through settings, trying to find the right toggle 6 nodes deep in the tree.

▲busymom0 8 hours ago | parent [-]

I am a developer and recently I was troubleshooting an issue with my macOS app where it was working fine on newer macOS but failing on older one only when I archived it (last step before submitting an app for Apple approval). So I'd archive it on my new macOS and airdrop to old macOS and try to run it. Every single time, it'd tell me it was unsafe and ask me whether I'd like to delete it. I'd have to dig through multiple settings screens to "open anyway", enter my password to get it to finally run. What a nightmare not being able to easily run my own app despite having same developer account and Apple ID.

▲fragmede 6 hours ago | parent [-]

Staple and notarize it, and then invoke the xattr -d quarantine command on it.

▲dcrazy an hour ago | parent [-]

You don’t need to kill the quarantine bit if you notarize and staple. If you do still get prompted, the dialog will have an Open button on it.

▲tapvt 8 hours ago | parent | prev | next [-]

I dislike restrictions out of instinct, but to be fair, I've had permissions request popups on my Mac that were the first sign of software, which I had actually written, maybe had some bugs allowing it to work outside of its intended bailiwick.

▲tekacs 8 hours ago | parent | prev | next [-]

Apple, as always, seem extremely determined to make sure that they protect things on your computer from being accessed by you.

Apple Intelligence is a great example of this. Everything can funnel up to Siri, but neither you nor any other app on your computer can see what is fed to it by all of the APIs that would provide it data. So anyone who adds support for it is enabling Apple to do their usual slow broken thing with Siri and not enabling any other way you might want to use software or AI with that data.

▲happyopossum 5 hours ago | parent [-]

> protect things on your computer from being accessed by you

This has nothing to do with your access to the disk and everything to do with 3rd party deceiving unhindered access to everything about your life because you installed something like Muse.

▲techscruggs 8 hours ago | parent | prev | next [-]

Everyday, we get one step closer to the year of the Linux desktop.

▲etatester 8 hours ago | parent [-]

Any day now

▲big_toast 8 hours ago | parent | prev | next [-]

"Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac"

Huh? Seems like a disingenuous statement. I hope they update that sentence with something more accurate.

However, I've wanted much more granularity and pervasive permissions so I'm glad they're adding them.

▲lapcat 8 hours ago | parent [-]

> Huh? Seems like a disingenuous statement. I hope they update that sentence with something more accurate.

Right, the classic use case for FDA is Terminal app, not backups. I don't think backup apps even need FDA, because they use the Apple ASR tool that already has special permissions.

▲big_toast 8 hours ago | parent | next [-]

Even developing bog standard apps. MacOS without FDA is the death of creativity and productivity.

The permissions/security model should've expanded faster. There's huge benefits to being able to install arbitrary software and not worry about giving it access to everything.

But it would never cover everything to do with a computer.

▲mcmcmc 8 hours ago | parent | prev [-]

EDR and RMM are two major ones for corporate managed Macs

▲rwz 8 hours ago | parent | prev | next [-]

When I give something a "Full Disk Access" permission, I expect it to have full access to what's on my disk, including "files, mail, messages, and even (gasp) browsing history"! Who are those mysterious people who expect their browsing history to be magically excluded from something called Full fucking Disk Access?

▲bix6 8 hours ago | parent | next [-]

Most people don’t know what a disk is.

▲vorpalhex 3 hours ago | parent [-]

Then tell them to stop trying to use a computer, give them an apple juice and let them go back to eating their favorite color of crayon.

▲swiftcoder 8 hours ago | parent | prev [-]

The problem isn't people who intend to provide full disk access. It's the people who unthinkingly grant full disk access to, for instance, Codex, because the AI asked them to.

▲russellbeattie 8 hours ago | parent | prev | next [-]

Maybe it's just my pet peeve, but it's less about my documents and mail and more about programs, tools and AI harnesses deciding they can fill hidden dotfile folders at root with whatever they want (which they do indiscriminately). I don't just hate that there's tons of untracked caches and temp file data that isn't easily discoverable, but more specifically, I don't want all that crap in my root directory.

Who decided that hidden folders are a good thing anyways? .agent, .agents, .aws, .bun, .cache, .cargo, .claude, .codex , .config, .docker, .gemini, etc. I just end up having to show hidden folders all the time, which defeats the point.

It's gotten truly ridiculous. I want the OS to strictly enforce my root directory. There should be a few global preference files in there for like .zsh, and everything else organized in proper, unhidden folders.

▲jonathanstrange 8 hours ago | parent | prev | next [-]

If there is one thing I absolutely despise with all of my heart, then it's mega corporations patronizing their paying customers.

▲lapcat 9 hours ago | parent | prev [-]

My understanding is that Meta Muse simply opens the System Settings Full Disk Access pane, and the user has to enable it themselves using System Settings, which says, "Allow the applications below to access data like Mail, Messages, Safari..." and which requires an administrator password to change.

Thus, I'm not sure what more Apple can do here, but I'm definitely afraid of what they're going to do.

▲VCFundedGenYer 8 hours ago | parent | next [-]

No, that's not what happened.

In reality, the "full disk access" restriction system never actually worked right. I'm positive Apple is just trying to save face here and quietly fix it while saying they're "tighting" it

▲lapcat 8 hours ago | parent [-]

This is a baseless conspiracy theory. Provide proof. No, the confused ramblings of one journalist who is trying to save his own face for granting FDA to Muse does not count as proof.

▲708733454927516 8 hours ago | parent | prev [-]

"I have a bad feeling about this..."