Remix.run Logo
▲ piazz 5 hours ago

I’m pretty frustrated with Muse and the last thing I want to be doing with my free time is defending Meta, but this is such clickbait.

Point by point:

> “OMG you can jailbreak it and get it to spill its VM”

This is the whole point; any content on the VM is yours. It runs in an isolated sandboxed VM separate from stored credentials etc; this is effectively your own computer. You don’t have to trick it.

> It collects dossiers on your contacts

These are more text files that live on your private VM, alongside memory.md, etc. Do you want your secretary to forget every person you contact every day?

> It accessed Messages without full disk access

This whole story never made sense or was substantiated. Full disk access is an OS level security boundary; the user had to switch this on.

> It sold some guys stuff for too cheap and gave out his address

OK this one I basically believe, haha. Because this is the problem with Muse: the LLM is just too dumb to perform complex tasks effectively in many cases.

▲cmiles74 3 hours ago | parent | next [-]

I gotta' disagree on this one. Meta made claims that it was taking privacy seriously and it turns out, not so much. I do think they should be getting some pressure on that score.

▲piazz 3 hours ago | parent | next [-]

Okay, but what is the evidence to back up this assertion? My point is, at this time, there is none. There is no “it turns out”. Give them some time to screw up at least.

▲GeekyBear 3 hours ago | parent | next [-]

> Meta’s New Muse AI Agent Read My Private Messages. I Never Asked It To

https://www.inc.com/jason-aten/metas-new-muse-ai-agent-read-...

▲lapcat 3 hours ago | parent [-]

Literally nobody has reproduced this.

The Messages database is protected by macOS TCC. If Aten were correct, there would exist a macOS zero day vulnerability.

The vastly more likely explanation is that Aten mindlessly gave Full Disk Access to Muse. And that appears to be Apple's assumption, based on Apple's newly published developer note.

▲GeekyBear 2 hours ago | parent | next [-]

Apple's statement on the matter sure sounds like Meta has once again been caught with their hand in the cookie jar.

> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.

▲lapcat 2 hours ago | parent [-]

> Apple's statement on the matter sure sounds like Meta has once again been caught with their hand in the cookie jar.

> > Some developers are using Full Disk Access in ways that could put users at risk

In other words, Muse did have Full Disk Access. Jason Aten did grant Full Disk Access to Muse, despite his claims otherwise.

If Aten did not grant Full Disk Access to Muse, then why would Apple even be talking about Full Disk Access?

The point is that Aten apparently granted Full Disk Access absent-mindedly, so absent-mindedly that he won't even admit that he did it. This is why Apple is making changes to Full Disk Access to make it more obvious what's happening.

▲GeekyBear 2 hours ago | parent [-]

> In other words, Muse did have Full Disk Access. Jason Aten did grant Full Disk Access to Muse, despite his claims otherwise.

Perhaps you should do some reading on the matter?

> Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges. One is full-disk access, a macOS system-level permission. The other is to enable a Messages connector setting in Muse.

“The Messages integration in the Muse Mac app is opt in,” Singleton said. “Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.”

Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame.

https://arstechnica.com/security/2026/10/apple-changes-full-...

Meta has a long history of not respecting boundaries once something is technically possible.

▲b112 2 hours ago | parent | next [-]

So you're saying he mindlessly, and without thinking about it granted two OS level permissions to Muse? I don't understand how this refutes anything the parent poster said.

▲lapcat 2 hours ago | parent | prev [-]

> Perhaps you should do some reading on the matter?

Perhaps you should: https://lapcatsoftware.com/articles/2026/10/2.html

> Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame.

Indeed, and it looks like Aten absent-mindedly did all of this!

> Meta has a long history of not respecting boundaries once something is technically possible.

It's not technically possible for Muse to read the Messages db without Full Disk Access. Aten denies having given FDA to Muse. Thus, Aten is simply wrong, misremembering or something. And if he misremembers about FDA, he likely also misremembers about granting app-level permissions to Muse.

Again, literally nobody has reproduced Aten's experience. Show me one other person.

In fairness, Aten behaved just like many other users would, mindlessly granting permissions that an app requests. That's certainly a problem. Unfortunately, Aten stubbornly refuses to admit this, instead confusing the problem by suggesting technical impossibilities. Aten doesn't want to take any responsibility for his own actions.

▲GeekyBear 2 hours ago | parent | next [-]

> Indeed, and it looks like Aten absent-mindedly did all of this!

Since Aten has clearly said he did not grant Muse the permission to read his messages (inside Muse), I'm not accepting your version of the events.

▲lapcat 2 hours ago | parent [-]

So you prefer to accept the version of events where Aten somehow stumbled upon a macOS security vulnerability that allows apps without Full Disk Access to read the Messages database, a vulnerability that nobody else has reproduced and that Apple itself apparently doesn't recognize? Just because one writer said so?

▲cloudfudge 36 minutes ago | parent [-]

If what the writer said was strictly true, Apple would be having a little security freakout about how Muse managed to bypass this OS control. My assumption is that the writer did not understand everything he was granting it permission to do, so he legitimately believes that he didn't grant it those permissions. But he did.

▲GeekyBear 21 minutes ago | parent [-]

Apple's statement is that the permission is being abused to do things that users do not think are possible.

In this case, Meta explicitly promises that Muse will not read your messages even after you grant it disk permissions.

▲givinguflac 14 minutes ago | parent | prev [-]

Lmfao you tell someone to read and then post your own opinionated blog post? I would reiterate that you need to read, perhaps outside your own bubble.

▲givinguflac 21 minutes ago | parent | prev | next [-]

“Mindlessly” gave full disk access. This is why Apple is restricting FDA further- people are stupid. TCC exists, great, but you’re spending so many comments harping on TCC that you e lost the plot here.

▲cmiles74 2 hours ago | parent | prev [-]

Reading it over, it does seem like giving the app full disk access would be enough for it to read our messages. I mean, they are stored on disk somewhere.

▲GeekyBear 2 hours ago | parent | next [-]

Exactly.

Meta's claim that Muse would not read your messages without explicit permission was meaningless.

▲judge2020 an hour ago | parent [-]

> Meta's claim that Muse would not read your messages without explicit permission was meaningless.

But it was true and you still haven't refuted that Aten mindless clicked through and allowed Muse full disk access and/or the messages connector setting in the Muse app.

▲lapcat 2 hours ago | parent | prev | next [-]

Yes?

▲ 2 hours ago | parent | prev [-]
[deleted]
▲runarberg 3 hours ago | parent | prev [-]

[flagged]

▲mapremap 2 hours ago | parent | next [-]

It's definitely faster to just assume that there is evidence to reinforce our existing biases than it is to do the same after succeeding or failing to locate that evidence, so considering that all three methods lead to the same result, the one with the lowest time cost is optimal.

▲piazz 2 hours ago | parent | prev [-]

This is terrible logic.

Trump is stripping the White House for copper and selling it!! Well, actually he’s not, but since we know he’s corrupt, isn’t it safe to just assume he might also be doing this other bad thing?

If your decision is to avoid Muse due to Meta’s poor track record, that’s absolutely your prerogative (and a reasonable one!). But specific claims must be evaluated based on their evidence. This article fails that. There’s no story here.

▲runarberg an hour ago | parent [-]

The logic here is that Meta (a company known to be malicious) is putting out a product which is potentially dangerous. There are some anecdotal evidence of said dangers, and it is perfectly rational to believe given the history and dangers involved. Best case regulators step in and ban this product before we know the validity of these anecdotes. Worst case, regulators do nothing, the public starts using the product, and these anecdotes turn out to be valid.

Off course there is space between the worst and the best case. But given Meta’s history it is safest (and the most rational) to assume the worst.

▲IshKebab 3 hours ago | parent | prev | next [-]

> it turns out, not so much

Why though? The comment you're replying to is explaining how the accusations of poor privacy are nonsense and you've just replied "I disagree because they have poor privacy".

I mean I'm not going to hand over any data to Facebook if I can help it but it doesn't seem like there are any specific issues here.

▲moffkalast 2 hours ago | parent | prev | next [-]

Ah yes, Meta and privacy. Two things that go together like a jet engine and a library.

▲jonplackett 3 hours ago | parent | prev [-]

[flagged]

▲bdangubic 3 hours ago | parent [-]

handful is too many in this case

▲GeekyBear 3 hours ago | parent | prev | next [-]

> It accessed Messages without full disk access

>This whole story never made sense or was substantiated

This story makes perfect sense, and Meta has a long history of not respecting user privacy controls.

> tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits

https://arstechnica.com/security/2026/10/apple-changes-full-...

▲kccqzy 3 hours ago | parent | next [-]

The reason that story didn’t make sense to me was that the tech columnist never showed the Apple system settings on whether full disk access was enabled or not. If you trusted the tech columnist that full disk access was not enabled, then Meta’s Muse AI seemed to have discovered a zero-day vulnerability in Apple software, specifically a TCC bypass.

First I doubt Muse is that good of an AI. Second, even if that’s the case, why wouldn’t someone report it to Apple to get thousands of dollars in bug bounty rewards?

▲GeekyBear 2 hours ago | parent [-]

Apple's statement makes their position on the matter clear.

> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.

▲kccqzy 2 hours ago | parent [-]

That Apple statement assumes that the user has granted full disk access but the user said he did not. So I conclude that Apple thinks the user is either lying or had forgotten he had enabled full disk access.

I’ll be charitable and say the user isn’t lying. Okay he has made a mistake in the initial granting of permissions. Then why didn’t he correct or retract the article?

▲GeekyBear 2 hours ago | parent | next [-]

Because Muse has a setting in the app that you are supposedly required to turn on before it can read your message?

One that the journalist in question did not turn on.

▲lapcat 2 hours ago | parent | next [-]

The app-level setting is irrelevant if the app does not have Full Disk Access.

Muse cannot bypass built-in macOS protections. TCC does not work on "the honor system", any more than UNIX permissions. It doesn't matter how nefarious Meta happens to be. Operating system security is designed to be resistant to malware.

▲GeekyBear 2 hours ago | parent [-]

> The app-level setting is irrelevant if the app does not have Full Disk Access.

I'm just going to have to ignore you on this issue.

> Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges.

▲bigyabai an hour ago | parent | next [-]

One one of those privileges actually stops them from accessing the filesystem. Any agent, Meta or otherwise, can access iMessages without the connector in that configuration.

▲lapcat an hour ago | parent | prev [-]

> I'm just going to have to ignore you on this issue.

Sure, what do I know? After all, I'm only [checks notes] a 20 year veteran of Mac software development with multiple Apple-issued CVEs to my credit. ¯\_(ツ)_/¯

> > Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges.

Yes. Those two:

1. Full Disk Access

2. The Messages Setting in Muse

As I said, without the first, the second alone won't allow Muse to read your Messages db. Do you not understand why Singleton said that Muse needs both?

▲GeekyBear an hour ago | parent [-]

The entire story here is that Meta claimed that Muse would not access your messages without you granting it the second permission, even after your granted it the first.

Hence Apple's statement that the first permission was being abused to destroy any promises of user privacy.

▲lapcat an hour ago | parent [-]

> even after your granted it the first.

The problem here is that Aten claimed he did not grant the first, and moreover, you have been defending that claim of Aten's in these comments.

As soon as you admit that Aten did indeed grant the one permission, it's not much of a stretch to conclude that he also granted the second permission. It would be very odd, I think, to distrust Aten in the one case yet stubbornly take him at his word in the second.

Again, if even one other person in the entire world could reproduce Aten's alleged experience...

▲GeekyBear an hour ago | parent [-]

The story has always been:

Meta promised that they would not read a user's messages without an additional permission the user must enable inside of Muse, even after they granted Muse full disk access.

A journalist reported that Muse read his messages despite the fact that he did not grant permission for it to do so inside Muse. He never claimed he did not grant full disk access.

Apple announced that the full disk access permission was being abused.

▲lapcat 38 minutes ago | parent [-]

> He never claimed he did not grant full disk access.

False. In fact he has claimed this multiple times:

"Full disk access off. Muse synced 187k lines form my messages chat db." https://www.threads.com/@jasonaten/post/DdezsMJFhBr

"I still haven’t gotten an answer as to how it was reading my messages with Full Disk Access turned off, but I’d be happy to dig into it with anyone from Meta that wants to help." https://www.inc.com/jason-aten/meta-keeps-apologizing-for-mu...

This is why he's not a reliable narrator.

And another false claim he made, "Also, that full disk access doesn’t say anything about your message database", which anyone can easily refute by opening System Settings and reading the text.

▲cma an hour ago | parent | prev [-]

That's the setting to let it read your messages if you don't want to give it full disk access. If you give it full disk access wouldn't that supersede it unless you don't store your messages on the disk?

▲TeMPOraL an hour ago | parent | prev [-]

> I’ll be charitable and say the user isn’t lying. Okay he has made a mistake in the initial granting of permissions. Then why didn’t he correct or retract the article?

There is no answer to that consistent with the premise you assumed out of charity :).

▲zardo an hour ago | parent | prev | next [-]

Aren't permissions on notifications less restricted then full disk access?

▲lapcat 2 hours ago | parent | prev | next [-]

> Meta has a long history of not respecting user privacy controls.

Meta's respect is irrelevant, because macOS TCC prevents any and every app, including malware, from accessing your Messages database without Full Disk Access.

> he never granted Muse permissions to read his messages

That's what he said, but I would suggest that one person's memory is a lot more fallible than a longstanding operating system security feature.

▲givinguflac 22 minutes ago | parent [-]

Seriously, stop trying to grandstand this thread and being Meta’s lap cat. It’s gross.

How on earth, after literally decades of abusive behavior by meta, are you standing the straw man that maybe and based on your assumption the user is lying??

▲bigyabai 3 hours ago | parent | prev [-]

Which privacy control did they fail to respect, in this instance? Everything on the journalist's machine was working as-intended.

▲al_borland 2 hours ago | parent | prev | next [-]

In. Jonna Stern’s interview with Zuckerberg he talked about the security, and how they delayed it to make sure they got it right. He then went on to say there was more to do and they weren’t totally isolated yet (I can’t remember his exact wording).

I felt like he was undermining his original point. They delayed to make it better, but didn’t delay long enough to do the actual right thing he mentioned they could potentially do in the future.

When it’s pulling in data from all over the phone or computer, it’s not just the user’s data. Some of my personal data (detailed contact info, emails, etc) can be pulled in and used by Muse if someone I know installs it, without my knowledge or consent. That needs to be taken seriously, and Meta has a history of abusing this concept (uploading fully address books to find friends)

▲hitekker 3 hours ago | parent | prev | next [-]

It's the market for attention. Many of techdirt's writers are heavy Bluesky users so most of their articles cater towards other Bluesky users. Venting might be the most common longform on either website.

▲JMiao 2 hours ago | parent [-]

i started using bluesky recently and the venting seemed about normal by internet standards

▲greenavocado an hour ago | parent | prev | next [-]

> the LLM is just too dumb to perform complex tasks effectively in many cases.

Muse Spark 1.3 is way better than anything else out there outside of the US labs except Deepseek Flash which comes close.

▲moscoe 4 hours ago | parent | prev | next [-]

Absolutely agree. So much feigned outrage in these articles (and HN comments) about the LLM models doing x.

Yesterday everyone was all worked up about OpenAI generating an image with a signature on it.

Caveat emptor. Don’t be an idiot. Grow up. Make informed decisions regarding your use of these products and take responsibility for those decisions.

▲slashdave an hour ago | parent | next [-]

> Make informed decisions regarding your use of these products

They are mass marketed. The creators should do the upmost to ensure this and not pin blame on users.

▲givinguflac 16 minutes ago | parent | prev | next [-]

In this context, normal people will believe the marketing and trust meta, and caveat emptor is a cop-out at best. I can sell you a basket of bread, and it’s privacy-preserving bread, but it will also punch you in the face if you don’t read every bit of the agreement. No one reads the agreement, and that’s what Meta runs on, plus skirting the law in every way they can possibly get away with.

▲JohnMakin 3 hours ago | parent | prev | next [-]

> Caveat emptor. Don’t be an idiot. Grow up. Make informed decisions regarding your use of these products and take responsibility for those decisions.

Feigned outrage, indeed. I don't think it's unreasonable to point out that Meta has been consistently predatory, reckless, and creepy with user data before, and that this is a very aggressive expansion of that.

The old facebook booster retort of "if you don't like it, don't use it, take responsibility" or whatever is nonsense. You're in their system whether you use their product or not. Even if you somehow avoid their pervasive web-wide tracking, a single contact you know installing this thing and gobbling up all your correspondence with them can compromise your privacy choices, and that's well beyond your control, unless you seriously suggest I audit every single one of my contact's devices and browbeat them into using the privacy choices I prefer.

Get real.

▲bigyabai 2 hours ago | parent [-]

> "if you don't like it, don't use it, take responsibility" or whatever is nonsense.

Why? I don't use Meta products, and my life isn't substantially impacted or controlled by them. Explain to me why I need to lobby my OS developers to reign-in Meta, from my perspective. Why is my hands-off approach insufficient for teaching adults to make intelligent decisions?

Facebook is unquestionably awful, but that's a regulatory issue. 90% of the people chiming-in with Facebook outrage aren't using Meta products; they are literally feigning surprise and outrage as someone that clearly knows better. Oftentimes, they oppose any regulation that would force Meta to reconcile their damages because it would also jeopardize other abusive monopolies like the App Store that they love to defend. So where does the buck actually stop? Does it ever?

HN has done this for years. Years and years and years. "Meta is horrible! Stop them!" -> "New Meta product has ~10-100 million MAU" -> "We need private enterprises to limit Meta!" -> Stagnant status-quo where exploitation is rewarded. Things got this bad because of the pugilist, tribal attitudes that dominated tech discussions and steered people away from common-sense regulatory measures.

▲stephen_cagle 3 hours ago | parent | prev | next [-]

My assumption is you clearly don't have vulnerable or elderly people in your life? I'm not as concerned about my ability to navigate these waters as I am about the people I care about.

▲964279964377 an hour ago | parent | prev [-]

[dead]

▲butlike 3 hours ago | parent | prev | next [-]

> I’m pretty frustrated with Muse and the last thing I want to be doing with my free time is defending Meta

Then don't.

▲iAMkenough 2 hours ago | parent | prev | next [-]

Nice! Starting my own crypto miner using Meta infra then.

▲ralphington 4 hours ago | parent | prev [-]

You just did the tech equivalent of "not to sound racist, but..."