logoalt Hacker News

Updates to Full Disk Access in macOS

286 points • by notfirstpost • yesterday at 7:37 PM • 201 comments • view on HN

Comments

eviks • today at 4:30 AM

> We give developers powerful APIs to build incredible capabilities

> Full Disk Access largely sidesteps these controls

That's because you don't really. Just like you don't give users "powerfulf" controls, so instead they have to resort to dumb ones like "Full disk"

For example, if you care about "mail, messages, and even browsing history", why isn't there a subset of "full disk access except for reading mail/messages/browsing history"? Or if vibe code have some basic disk sizing functionality to ask questions about your files, why can't it have a more granular "full disk read only access for file sizes only" so that your vibe coded disk visualization app can't destroy your data or your privacy

> can only do so with very explicit user action.

Which is in the same vein and is mostly useless, just another inconvenient bump

➕ show 3 replies
ghusto • today at 4:06 PM

I have to have my machine further crippled in order protect people who don't know what they're doing on a computer.

I don't think there's anything wrong with people not knowing how to use a computer properly. In fact, I wouldn't expect a normal person to, why should they? So what I would love to see is normies be given iPads, and my computer left the hell alone.

It's like if we over-simplified all the controls in a cockpit because someone who likes playing flying games finds it too difficult to fly a real plane.

➕ show 1 reply
moecables • yesterday at 8:14 PM

IMHO, it's good to add more specific controls for this. After reading this, I went and checked my list of app with full disk access:

- Ghostty (fine, it's my terminal)

- Alfred (fine, I use it for searching everywhere)

Then I have a few turned off:

- Spotify (why does it need full disk access) ??

- Gemini (nope, don't need it to know everything about my computer)

➕ show 8 replies
cwizou • today at 1:06 PM

Some of the restrictions have already been implemented in macOS 27 by restricting access to (at least some ?) containers even with Full Disk Access on.

One niche issue resulting from this : it broke the ability to access my own screensaver settings and files from it's settings app, because those settings live inside a container for a system extension that belongs to Apple (because Apple still hasn't publicly released it's "modern" screensaver api, it's still old style plugins run by a legacy extension).

Several screensaver developers I know got bitten by this and there's no proper workaround, you just have to use "/Users/Shared" and hope that doesn't go away any time soon.

In my case it silently broke migration for Aerial from 3.X to 4.X in Golden Gate (where I moved away from the legacyScreenSaver extension to the new undocumented wallpaperextension format). I did move to "/Users/Shared" earlier this year but some people will inevitably get caught by this if they didn't update, and there's no recourse, FDA doesn't work, you can't even ask for access, nothing works. And since it's a silent fail, I didn't even notice before this week.

➕ show 1 reply
mrkpdl • yesterday at 8:24 PM

I would like the ability to see which specific folders I have granted access to on an app by app basis. And edit. It’s not clear to me how you revoke an app’s individual folder access after you have granted it.

➕ show 1 reply
post_break • yesterday at 7:57 PM

One update away to revoking Full Disk Access in the future. This commercial has come full circle: https://www.youtube.com/watch?v=VuqZ8AqmLPY

➕ show 6 replies
liuliu • yesterday at 11:50 PM

I don’t quite understand why people complains this is bad for AI agents. Local Code (https://releases.drawthings.ai/p/public-beta-of-local-code-b...) doesn’t require full disk access, when you ask the agent to deal with some files it doesn’t have access to, the built-in ‘permit’ tool will trigger the OS folder grant interface and that information will be recorded both by Apple and by the app so it can be revoked later if you want. That allows you to not give full disk access to the app to be useful.

➕ show 3 replies
JamesSwift • today at 6:47 PM

Great, cant wait for the inevitable "Are you sure you want to grant full disk access" prompts every week for eternity until the user is exasperated and revokes access.

Kim_Bruning • yesterday at 8:19 PM

Am I getting old? "full disk access" used to be something that's supposed to be normal; if you're the owner of the machine.

➕ show 19 replies
PeanutOS • today at 1:02 AM

This week, I formatted my entire Mac fleet (an iMac Pro and four MacBooks), and now neither AI agent runs natively. I am using LIMA (https://lima-vm.io) to isolate them in a sandbox, exposing only a repository. I lose some integration, but the peace of mind is worth it.

lxgr • today at 10:16 AM

I think macOS 27 has already shipped a version of this. I remember seeing a prompt for Firefox requesting access to Google Chrome data (presumably to import bookmarks/history?) recently.

If that's the direction things are moving in, I welcome the change. Fine-grained folder access controls (rather than only full iOS-like sandboxing or full disk access) make me much less hesitant to try new apps or have agents access more parts of my system.

But they really need to solve the issue of low-level utilities triggering dozens of permission prompts when walking $HOME. Having to approve or decline Documents, Downloads, Google Drive etc. directory access, all separately, is extremely annoying.

➕ show 2 replies
drnick1 • today at 6:21 PM

I don't understand why this is a problem at all. AFAIK macOS is UNIX, so you can create user accounts and run programs as separate users. This is what I routinely do on Linux to run coding tools or other programs that should not have "full disk access," in particular to the files and mounts of my main user.

➕ show 3 replies
etatester • yesterday at 8:38 PM

What we need is true application isolation even in the command line. Treat Terminal as privileged access, not something any app can just command. Sandbox non-app store apps as well.

➕ show 4 replies
zmmmmm • today at 12:04 AM

It's fine if there is a super streamlined flow for access that works with legacy apps and runs in user-mode. Otherwise this might seriously hurt MacOS as a viable development platform.

➕ show 1 reply
jameskraus • yesterday at 8:05 PM

Oh no, even more permission prompts on macOS. It's already almost unusable due to the existing ones.

➕ show 2 replies
VCFundedGenYer • yesterday at 8:34 PM

If it worked as intended, they wouldn't be in this predicament.

That feature was so stupidly nonfunctional before. Some apps got stopped by it, others didn't. Often you'd be able to install an app from homebrew and it had full ride access to the disk, while App Store apps had to request consent for any folder whatsoever. It was completely random.

pkulak • yesterday at 8:27 PM

I feel like this isn't going to be a simple permission popup. Probably along the lines of getting an "unapproved" binary to run, where you have to stop what you're doing and wade through settings, trying to find the right toggle 6 nodes deep in the tree.

➕ show 2 replies
tekacs • yesterday at 8:29 PM

Apple, as always, seem extremely determined to make sure that they protect things on your computer from being accessed by you.

Apple Intelligence is a great example of this. Everything can funnel up to Siri, but neither you nor any other app on your computer can see what is fed to it by all of the APIs that would provide it data. So anyone who adds support for it is enabling Apple to do their usual slow broken thing with Siri and not enabling any other way you might want to use software or AI with that data.

➕ show 2 replies
lstroud • today at 3:58 PM

Is it really that surprising that in a world where we are redefining the meaning of user, that our user based file system security controls will have to change?

hn-ai-podcasts • today at 7:21 AM

Above all, we need a true privilege separation API at the application level. Why is the only way to sandbox my code editor to run it in a Linux VM on the Mac? And that’s solely to mitigate supply-chain attacks.

The simple root/user separation has long since ceased to be secure because, on a desktop machine, all sensitive information is, by definition, accessible to the user; having root privileges ultimately offers little advantage when it comes to exfiltrating data.

robertk08 • today at 4:35 PM

Just a reaction to Muse accesing that one guys iMessage history without permission.

kkcidncisncjdnc • today at 2:12 PM

Now if only any of these controls would let me stop Adobe from creating a “Adobe” folder in my iCloud-synced Documents folder, that would be swell.

I simply do not understand how Adobe manages to bypass every single toggle available there. I can block access to every folder on my computer but the moment I open any Adobe app, they recreate that goddamned folder.

Why? How? Fucking hell Adobe. It’s 2026, you just don’t store cache and setting files in the fucking Documents folder.

profmonocle • today at 12:55 AM

> we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so

"Extraordinary" is a funny word choice. It was completely ordinary for most of the history of personal computing that any app you ran under your normal user account could see everything you had.

(I'm not saying this is a bad thing. As long as they allow informed users to continue to do whatever they please, I'm all for it.)

tapvt • yesterday at 8:29 PM

I dislike restrictions out of instinct, but to be fair, I've had permissions request popups on my Mac that were the first sign of software, which I had actually written, maybe had some bugs allowing it to work outside of its intended bailiwick.

tiku • today at 4:46 AM

Any tips on the screenshot utility not getting disk access? Must be related because since macOS 27 it gets a no write permission error.

nottorp • today at 8:22 AM

So this will make building apps from source outside macports/homebrew even more annoying?

techscruggs • yesterday at 8:16 PM

Everyday, we get one step closer to the year of the Linux desktop.

➕ show 2 replies
plantain • today at 3:03 AM

"Updates to-" instills such a deep-rooted fear in me. I know whatever follows is about to suck.

greatgib • today at 12:21 PM

Don't be naive, them telling you this in advance and straw man arguments like:

   For communication apps, this can also compromise the privacy of the people users are communicating with.
Let me think that they try to sugarcoat a coming change that has the purpose of transforming your computer as an ipad where you have no access to most of it except what is approved by apple.

For the "greater good" as usual.

Just look how deceptive is the Apple post "full disk access" is not even a thing. You have access to your user files and that is all. You need sudo to have more rights.

A normal copilot/Claude/facebook like app shouldn't ask you for such a right except exceptionally for a very good reason.

So when they speak about backup apps, that are the one that could need sudo to backup the whole system, is to tell you that soon only notarized apple approved and app store delivered apps will be allowed to do that, but certainly not you willingly. Maybe not in version 1 but in version 2 for sure.

Then, like for iOS, they could have proprietary apps like Netflix, Facebook and co storing data on your device that you will not have access to.

rwz • yesterday at 8:09 PM

When I give something a "Full Disk Access" permission, I expect it to have full access to what's on my disk, including "files, mail, messages, and even (gasp) browsing history"! Who are those mysterious people who expect their browsing history to be magically excluded from something called Full fucking Disk Access?

➕ show 4 replies
dbg31415 • today at 6:52 AM

Man, I just want Discord to have the ability to do overlays on Mac like it can on PC so I can see who is talking when I’m playing video games. Where is that API update?

big_toast • yesterday at 8:06 PM

"Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac"

Huh? Seems like a disingenuous statement. I hope they update that sentence with something more accurate.

However, I've wanted much more granularity and pervasive permissions so I'm glad they're adding them.

➕ show 2 replies
swozey • today at 5:48 PM

I totally had pi+qwen3.6-a35b wipe out my entire USB das yesterday migrating it from ntfs drivepool to apfs, 10tb since I'm done with windows. Been joking about qwen wiping out my laptop for a year now and was comfortable enough to just let it look at my storage and it immediately formatted. lmao.

I had 3 duplicate files on each drive and it was impatient and rushing and didn't keep one drive around before formatting them all.

Completely saved me the week of migrating files project I was dreading, thanks. Nothing invaluable but an insane amount of downloading to do and I'm on 5g in the woods.

Sometimes its just draw dropping at how stupid these can be, basically giving a 6yo RHCSE root access.

lapcat • yesterday at 8:00 PM

My understanding is that Meta Muse simply opens the System Settings Full Disk Access pane, and the user has to enable it themselves using System Settings, which says, "Allow the applications below to access data like Mail, Messages, Safari..." and which requires an administrator password to change.

Thus, I'm not sure what more Apple can do here, but I'm definitely afraid of what they're going to do.

➕ show 2 replies
russellbeattie • yesterday at 8:59 PM

Maybe it's just my pet peeve, but it's less about my documents and mail and more about programs, tools and AI harnesses deciding they can fill hidden dotfile folders at root with whatever they want (which they do indiscriminately). I don't just hate that there's tons of untracked caches and temp file data that isn't easily discoverable, but more specifically, I don't want all that crap in my root directory.

Who decided that hidden folders are a good thing anyways? .agent, .agents, .aws, .bun, .cache, .cargo, .claude, .codex , .config, .docker, .gemini, etc. I just end up having to show hidden folders all the time, which defeats the point.

It's gotten truly ridiculous. I want the OS to strictly enforce my root directory. There should be a few global preference files in there for like .zsh, and everything else organized in proper, unhidden folders.

➕ show 2 replies
ls-a • yesterday at 8:31 PM

[dead]

jonathanstrange • yesterday at 8:15 PM

If there is one thing I absolutely despise with all of my heart, then it's mega corporations patronizing their paying customers.