| ▲ | oofbey 5 hours ago | |||||||
Probably. But also the agents are finding flaws in the security model. Also Meta is actively encouraging users to grant them full permission, insisting with all their marketing might that it’s safe, which they know is a complete lie. Hard to blame the user when they’re being actively deceived like this. Other agent companies are more reserved and say things like “be careful” but Meta is the opposite. | ||||||||
| ▲ | judge2020 an hour ago | parent | next [-] | |||||||
I mean, it's not that the data isn't safe (they at least have modern user-level data protection similar to the other tech giants), nor will the agent generally do stuff you don't tell it to do. But I'm sure their stance was less "let's ask for granular per-category access whenever the user actually needs it" and more product-driven "we want the agent to have all the data and context it needs to become a successful product that gets people hooked, so let's ask for full disk access". | ||||||||
| ▲ | alistairSH 5 hours ago | parent | prev [-] | |||||||
I definitely didn't intend to blame the victims here, beyond trusting Meta in the first place. As for security models, it's probably long since time to sandbox all data and apps. More like mobile devices. Allow users to toggle that all off so they can use their computers for development etc, but the default state should force apps/tools to explicitly ask for permission to any folder, other app, API, CLI, etc. And ask for that permission regularly (or rather, reset the permission after some period of time). Or something like that (I haven't given it a great amount of thought). | ||||||||
| ||||||||