Remix.run Logo
▲ GeekyBear 3 hours ago

Apple's statement on the matter sure sounds like Meta has once again been caught with their hand in the cookie jar.

> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.

▲lapcat 3 hours ago | parent [-]

> Apple's statement on the matter sure sounds like Meta has once again been caught with their hand in the cookie jar.

> > Some developers are using Full Disk Access in ways that could put users at risk

In other words, Muse did have Full Disk Access. Jason Aten did grant Full Disk Access to Muse, despite his claims otherwise.

If Aten did not grant Full Disk Access to Muse, then why would Apple even be talking about Full Disk Access?

The point is that Aten apparently granted Full Disk Access absent-mindedly, so absent-mindedly that he won't even admit that he did it. This is why Apple is making changes to Full Disk Access to make it more obvious what's happening.

▲GeekyBear 3 hours ago | parent [-]

> In other words, Muse did have Full Disk Access. Jason Aten did grant Full Disk Access to Muse, despite his claims otherwise.

Perhaps you should do some reading on the matter?

> Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges. One is full-disk access, a macOS system-level permission. The other is to enable a Messages connector setting in Muse.

“The Messages integration in the Muse Mac app is opt in,” Singleton said. “Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.”

Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame.

https://arstechnica.com/security/2026/10/apple-changes-full-...

Meta has a long history of not respecting boundaries once something is technically possible.

▲b112 3 hours ago | parent | next [-]

So you're saying he mindlessly, and without thinking about it granted two OS level permissions to Muse? I don't understand how this refutes anything the parent poster said.

▲lapcat 3 hours ago | parent | prev [-]

> Perhaps you should do some reading on the matter?

Perhaps you should: https://lapcatsoftware.com/articles/2026/10/2.html

> Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame.

Indeed, and it looks like Aten absent-mindedly did all of this!

> Meta has a long history of not respecting boundaries once something is technically possible.

It's not technically possible for Muse to read the Messages db without Full Disk Access. Aten denies having given FDA to Muse. Thus, Aten is simply wrong, misremembering or something. And if he misremembers about FDA, he likely also misremembers about granting app-level permissions to Muse.

Again, literally nobody has reproduced Aten's experience. Show me one other person.

In fairness, Aten behaved just like many other users would, mindlessly granting permissions that an app requests. That's certainly a problem. Unfortunately, Aten stubbornly refuses to admit this, instead confusing the problem by suggesting technical impossibilities. Aten doesn't want to take any responsibility for his own actions.

▲GeekyBear 3 hours ago | parent | next [-]

> Indeed, and it looks like Aten absent-mindedly did all of this!

Since Aten has clearly said he did not grant Muse the permission to read his messages (inside Muse), I'm not accepting your version of the events.

▲lapcat 3 hours ago | parent [-]

So you prefer to accept the version of events where Aten somehow stumbled upon a macOS security vulnerability that allows apps without Full Disk Access to read the Messages database, a vulnerability that nobody else has reproduced and that Apple itself apparently doesn't recognize? Just because one writer said so?

▲cloudfudge an hour ago | parent [-]

If what the writer said was strictly true, Apple would be having a little security freakout about how Muse managed to bypass this OS control. My assumption is that the writer did not understand everything he was granting it permission to do, so he legitimately believes that he didn't grant it those permissions. But he did.

▲GeekyBear an hour ago | parent [-]

Apple's statement is that the permission is being abused to do things that users do not think are possible.

In this case, Meta explicitly promises that Muse will not read your messages even after you grant it disk permissions.

▲lapcat 3 minutes ago | parent [-]

> In this case, Meta explicitly promises that Muse will not read your messages even after you grant it disk permissions.

There's no reason to doubt this claim. The only person in the world who has claimed that Muse disrespects its own internal setting is the same person who claimed that he didn't grant Full Disk Access to Muse.

Ironically, Aten's own screenshot appears to show that he toggled the internal setting from "Off" to "Read only". In my own testing, it's "Off" by default, and the only way to change the internal setting is to enable Full Disk Access first.

Thus, the likeliest scenario is that Aten unthinkingly granted Full Disk Access to Muse, granted the Messages app permission, then had a change of heart, disabled Full Disk Access, and then forgot what he had done. Later, when he noticed that Muse had some of his messages, he went back and checked, and saw the FDA was disabled, forgetting that he had toggled it on and off.

▲givinguflac an hour ago | parent | prev [-]

Lmfao you tell someone to read and then post your own opinionated blog post? I would reiterate that you need to read, perhaps outside your own bubble.