Remix.run Logo
▲ lapcat 2 hours ago

The app-level setting is irrelevant if the app does not have Full Disk Access.

Muse cannot bypass built-in macOS protections. TCC does not work on "the honor system", any more than UNIX permissions. It doesn't matter how nefarious Meta happens to be. Operating system security is designed to be resistant to malware.

▲GeekyBear 2 hours ago | parent [-]

> The app-level setting is irrelevant if the app does not have Full Disk Access.

I'm just going to have to ignore you on this issue.

> Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges.

▲bigyabai 2 hours ago | parent | next [-]

One one of those privileges actually stops them from accessing the filesystem. Any agent, Meta or otherwise, can access iMessages without the connector in that configuration.

▲lapcat 2 hours ago | parent | prev [-]

> I'm just going to have to ignore you on this issue.

Sure, what do I know? After all, I'm only [checks notes] a 20 year veteran of Mac software development with multiple Apple-issued CVEs to my credit. ¯\_(ツ)_/¯

> > Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges.

Yes. Those two:

1. Full Disk Access

2. The Messages Setting in Muse

As I said, without the first, the second alone won't allow Muse to read your Messages db. Do you not understand why Singleton said that Muse needs both?

▲GeekyBear 2 hours ago | parent [-]

The entire story here is that Meta claimed that Muse would not access your messages without you granting it the second permission, even after your granted it the first.

Hence Apple's statement that the first permission was being abused to destroy any promises of user privacy.

▲lapcat 2 hours ago | parent [-]

> even after your granted it the first.

The problem here is that Aten claimed he did not grant the first, and moreover, you have been defending that claim of Aten's in these comments.

As soon as you admit that Aten did indeed grant the one permission, it's not much of a stretch to conclude that he also granted the second permission. It would be very odd, I think, to distrust Aten in the one case yet stubbornly take him at his word in the second.

Again, if even one other person in the entire world could reproduce Aten's alleged experience...

▲GeekyBear 2 hours ago | parent [-]

The story has always been:

Meta promised that they would not read a user's messages without an additional permission the user must enable inside of Muse, even after they granted Muse full disk access.

A journalist reported that Muse read his messages despite the fact that he did not grant permission for it to do so inside Muse. He never claimed he did not grant full disk access.

Apple announced that the full disk access permission was being abused.

▲lapcat an hour ago | parent [-]

> He never claimed he did not grant full disk access.

False. In fact he has claimed this multiple times:

"Full disk access off. Muse synced 187k lines form my messages chat db." https://www.threads.com/@jasonaten/post/DdezsMJFhBr

"I still haven’t gotten an answer as to how it was reading my messages with Full Disk Access turned off, but I’d be happy to dig into it with anyone from Meta that wants to help." https://www.inc.com/jason-aten/meta-keeps-apologizing-for-mu...

This is why he's not a reliable narrator.

And another false claim he made, "Also, that full disk access doesn’t say anything about your message database", which anyone can easily refute by opening System Settings and reading the text.