logoalt Hacker News

Kim_Bruning • yesterday at 8:19 PM • 19 replies • view on HN

Am I getting old? "full disk access" used to be something that's supposed to be normal; if you're the owner of the machine.


Replies

concinds • yesterday at 8:29 PM

> Am I getting old?

I think so.

I don't know where this "ownership" debate came from. My ownership of my machine depends on strict, broad + fine grained control over what third-party devs (who are not me) get to do with my machine. Our interests are incompatible and hostile, in an era where most "native apps" ship analytics and marketing SDKs, or are videcoded. If macOS didn't offer these controls I would run every apps in a browser where it's sandboxed. This isn't the 90s.

This change is a reaction to a viral story from a tech reporter who shipped all his texts to Meta without meaning to, which tells you there's a consent and transparency issue for nontechnical users. I don't think anyone in the industry has figured out a proper solution. Unless you never interact with nontechnical people, it impacts your privacy indirectly no matter what you do. Though as technical user I hope we can get more fine-grained control and auditing.

➕ show 2 replies
Grombobulous • today at 3:40 AM

I am old, too, old enough to remember sending personal data over plain http with no encryption and needing to do a full wipe of Windows 98/XP machines on a periodic schedule just to keep viruses and malware off of them.

The idea that application A can just have full blown disk access and slurp up your tax returns or something was always a pretty crazy security posture. It just so happened that an honor system kind of almost sort of worked for a while.

You can’t really do an honor system when people are running artificial intelligence systems that have no concept of morality with full disk access.

➕ show 2 replies
etatester • yesterday at 8:42 PM

This isn't 1980 anymore. The internet is super hostile and everyone wants to extract data. You're still free to allow every app on your computer full access, I won't. I am very glad that none of the hundreds of apps installed across my phone and Mac can access my photos and cameras without permission.

➕ show 3 replies
jeremyjh • yesterday at 8:40 PM

I’m 50 and I think it’s crazy we ever thought it was acceptable to give every app you run full access to all the files on your computer by default.

➕ show 1 reply
iamcalledrob • today at 6:34 AM

Remember: it's not your machine, it's Apple's. You just get the privilege of using it.

pjmlp • yesterday at 8:25 PM

Only on systems without proper user management, or if the owner is logged in as the administrator.

➕ show 1 reply
II2II • today at 5:49 AM

I don't know what to think about this.

When I hopped onto the Linux bandwagon in the 1990's, the community was touting its amazing security because any damage done was compartmentalized to a particular account. (Of course, that ignores root escalations. Of course, few Linux users cared about that back then because it was an obscure operating system.) In contrast, Macintosh and Windows (non-NT) security was non-existent.

These days, I find increasing security measures both burdensome and restrictive. That said, it is also necessary. We have long left the era when one could trust supposedly reputable software vendors -- never mind random developers.

GeekyBear • yesterday at 8:43 PM

TFA:

> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding.

If you think an app from (say) Facebook can be trusted with unrestricted access to your whole machine, you're at least a bit naive.

watt • today at 9:23 AM

You misunderstand. The software that has full access to disk, and can do anything without you knowing it, is the owner of the machine.

rock_artist • yesterday at 8:40 PM

being a nerd here, sudo - yes, but indeed I thought the entire UNIX design of everything is files and there are permissions, groups, etc, should be sufficient.

But I think the "new world" is, we are over stimulated (eg. agents ask us 'permissions' for a long command) so we might give a sudo not fully aware of it where a big bold UX message box after a 'pseudo' sudo would better catch our eyes.

So it seems this is about adding additional layers over already existing ones in a way?

➕ show 1 reply
VCFundedGenYer • yesterday at 8:37 PM

macOS has been revoking access to stuff like this over the past decade. Things like unfettered access to modifying the OS went away with Gatekeeper and System Integrity Protection. "root" access is no longer true root on any Mac, and the user is treated like a prisoner. The UAC-esque prompts that come up in macOS would make Vista-era MS so jealous.

➕ show 1 reply
happosai • today at 8:38 AM

Basically, the security model has changed:

https://xkcd.com/1200/

Also, if you are really old, you may remember how unhappy people were when wheel group appeared, and not everyone could "su" to root anymore. Giving everyone root was supposed to be normal!

comboy • today at 12:03 AM

Do you run every process as root?

tonymet • today at 3:50 PM

this is mostly a benefit to the owner. Every security feature , including firewalls, authorization ACLS, etc could potentially be used to reduce the owners rights, but they’ve all been necessary .

I’m with you on ownership, but push against signed code restrictions especially with bootloaders, and closed drivers.

charcircuit • today at 1:15 AM

The software running isn't the owner though.

bigstrat2003 • today at 5:32 AM

No, you're not getting old. Tech companies are getting more and more paternalistic, refusing to treat users as adults who can make their own decisions. It's profoundly irritating.

fragmede • yesterday at 8:43 PM

And despite hyperbole about Apple locking down macOS, ending the era of personal computing, it's hidden behind a toggle in settings. https://www.xkcd.com/1200/ applies, and in the era of downloading random programs off the Internet and cryptocurrency, random programs should have to jump through an extra hoop before getting access to everything. Imo Apple went a bit overboard with granularity, but it's not 1990 and the Windows 98 (lack of) security model doesn't work, and neither does Unix permissions either.

➕ show 1 reply
smith7018 • yesterday at 8:23 PM

I'm sure it'll be a permission the user can toggle. So they won't be taking away the ability for apps to see all the files but they'll be adding an extra layer of security so users can choose what an app can see. They're being light on details at the moment though.

➕ show 1 reply