| ▲ | Kim_Bruning 9 hours ago | |||||||||||||
Am I getting old? "full disk access" used to be something that's supposed to be normal; if you're the owner of the machine. | ||||||||||||||
| ▲ | concinds 9 hours ago | parent | next [-] | |||||||||||||
> Am I getting old? I think so. I don't know where this "ownership" debate came from. My ownership of my machine depends on strict, broad + fine grained control over what third-party devs (who are not me) get to do with my machine. Our interests are incompatible and hostile, in an era where most "native apps" ship analytics and marketing SDKs, or are videcoded. If macOS didn't offer these controls I would run every apps in a browser where it's sandboxed. This isn't the 90s. This change is a reaction to a viral story from a tech reporter who shipped all his texts to Meta without meaning to, which tells you there's a consent and transparency issue for nontechnical users. I don't think anyone in the industry has figured out a proper solution. Unless you never interact with nontechnical people, it impacts your privacy indirectly no matter what you do. Though as technical user I hope we can get more fine-grained control and auditing. | ||||||||||||||
| ||||||||||||||
| ▲ | Grombobulous 2 hours ago | parent | prev | next [-] | |||||||||||||
I am old, too, old enough to remember sending personal data over plain http with no encryption and needing to do a full wipe of Windows 98/XP machines on a periodic schedule just to keep viruses and malware off of them. The idea that application A can just have full blown disk access and slurp up your tax returns or something was always a pretty crazy security posture. It just so happened that an honor system kind of almost sort of worked for a while. You can’t really do an honor system when people are running artificial intelligence systems that have no concept of morality with full disk access. | ||||||||||||||
| ||||||||||||||
| ▲ | etatester 9 hours ago | parent | prev | next [-] | |||||||||||||
This isn't 1980 anymore. The internet is super hostile and everyone wants to extract data. You're still free to allow every app on your computer full access, I won't. I am very glad that none of the hundreds of apps installed across my phone and Mac can access my photos and cameras without permission. | ||||||||||||||
| ||||||||||||||
| ▲ | jeremyjh 9 hours ago | parent | prev | next [-] | |||||||||||||
I’m 50 and I think it’s crazy we ever thought it was acceptable to give every app you run full access to all the files on your computer by default. | ||||||||||||||
| ▲ | VCFundedGenYer 9 hours ago | parent | prev | next [-] | |||||||||||||
macOS has been revoking access to stuff like this over the past decade. Things like unfettered access to modifying the OS went away with Gatekeeper and System Integrity Protection. "root" access is no longer true root on any Mac, and the user is treated like a prisoner. The UAC-esque prompts that come up in macOS would make Vista-era MS so jealous. | ||||||||||||||
| ||||||||||||||
| ▲ | GeekyBear 9 hours ago | parent | prev | next [-] | |||||||||||||
TFA: > Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. If you think an app from (say) Facebook can be trusted with unrestricted access to your whole machine, you're at least a bit naive. | ||||||||||||||
| ▲ | pjmlp 9 hours ago | parent | prev | next [-] | |||||||||||||
Only on systems without proper user management, or if the owner is logged in as the administrator. | ||||||||||||||
| ||||||||||||||
| ▲ | rock_artist 9 hours ago | parent | prev | next [-] | |||||||||||||
being a nerd here, sudo - yes, but indeed I thought the entire UNIX design of everything is files and there are permissions, groups, etc, should be sufficient. But I think the "new world" is, we are over stimulated (eg. agents ask us 'permissions' for a long command) so we might give a sudo not fully aware of it where a big bold UX message box after a 'pseudo' sudo would better catch our eyes. So it seems this is about adding additional layers over already existing ones in a way? | ||||||||||||||
| ||||||||||||||
| ▲ | comboy 5 hours ago | parent | prev | next [-] | |||||||||||||
Do you run every process as root? | ||||||||||||||
| ▲ | 6 hours ago | parent | prev | next [-] | |||||||||||||
| [deleted] | ||||||||||||||
| ▲ | charcircuit 4 hours ago | parent | prev | next [-] | |||||||||||||
The software running isn't the owner though. | ||||||||||||||
| ▲ | fragmede 9 hours ago | parent | prev | next [-] | |||||||||||||
And despite hyperbole about Apple locking down macOS, ending the era of personal computing, it's hidden behind a toggle in settings. https://www.xkcd.com/1200/ applies, and in the era of downloading random programs off the Internet and cryptocurrency, random programs should have to jump through an extra hoop before getting access to everything. Imo Apple went a bit overboard with granularity, but it's not 1990 and the Windows 98 (lack of) security model doesn't work, and neither does Unix permissions either. | ||||||||||||||
| ▲ | smith7018 9 hours ago | parent | prev [-] | |||||||||||||
I'm sure it'll be a permission the user can toggle. So they won't be taking away the ability for apps to see all the files but they'll be adding an extra layer of security so users can choose what an app can see. They're being light on details at the moment though. | ||||||||||||||
| ||||||||||||||