r/technology • • 12h ago

Artificial Intelligence Apple will limit Mac disk access as AI agents ‘substantially’ increase risk

https://www.theverge.com/tech/1004295/apple-limit-mac-disk-access-ai-agents
610 Upvotes

62 comments sorted by

204

u/SomeOrdinaryKangaroo 12h ago

People using codex with full permissions enabled will still find a way to accidentally wipe their data regardless in some way or another

47

u/teetaps 11h ago

It kinda reminds me of how they hid “this app is not from a trusted developer” deep in system settings… at first I was frustrated, but after I did it the first time, I googled what it meant and why it was set up that way and it taught me about disk permissions.

Sometimes putting friction intentionally is a good thing

11

u/TOGFIAVDF 10h ago

Yep. It might be annoying, but in less critical scenarios I've changed things I didn't mean to.

It's honestly smart to layer such sensitive things. Annoying, but smart.

1

u/retief1 1h ago

Honestly, they hid it way too deep imo. Like, when getting past the block was just "right click -> open", I'd keep the block enabled. I never once listened to it, because it only ever showed up when I was opening tiny indie games on itch, but it wasn't annoying enough to bother disabling.

Once they switched to the "go into system preferences" version, I just disabled the system entirely. The hassle vs value tradeoff simply wasn't there for me.

12

u/ketosoy 10h ago

I don’t have access to that drive.  I’ll write a Python script and tell the user to run it.

3

u/txdline 10h ago

People won't. AI will

-14

u/PantsOfAwesome 10h ago

This is only really a problem if you’re using the dirt-cheap, heavily neutered models that are designed to be as cheap and as “budget” as possible

70

u/PumpkinMyPumpkin 11h ago

They should just provide sandboxes for LLMs to work within. 

30

u/DeiviiD 9h ago

Or, maybe, just maybe, learn about VM/podman/docker.

That’s why vibecoders are just… dumb.

23

u/gplusplus314 8h ago

I work at a place where using a VM or Docker (which requires a VM on macOS) on our codebase is impossible. There’s no technical reason for this, it’s just due to poor technical decisions made by unqualified people hired and retained via nepotism.

2

u/DeiviiD 8h ago

And with AI that would increase 10000%.

AI it’s not the problem, it’s the people who used it and think they know as much as a decent IT departament.

You always have different envs to test and launch code. If your workplace is that messed up, I’m sorry.

2

u/gplusplus314 8h ago

At least I have a workplace. It could be worse.

2

u/Ok_Guide8084 2h ago

unnecessary jerk.

1

u/[deleted] 10h ago

[deleted]

3

u/BeowulfShaeffer 9h ago

My owner gave me full access to his box and nothing bad has happened. Well not to me, anyway.  Open your firewall, I’ll show you.

-5

u/RoomyRoots 9h ago

It's 2026. People that can't use VMs or containers are kinda wishing to get fucked.

12

u/DanielPhermous 5h ago

It's 2026. People who can't install mechanical interlocks on their heating system are kinda wishing to get fucked.

Which is to say: Don't expect everyone in the world to be expert in your chosen field. It's unreasonable, they have better things to do and looking down on them because of it says more about you than them.

18

u/_sharpmars 9h ago

Misleading headline. Full Disk Access won’t be limited, granting it will just be made more explicit:

https://developer.apple.com/news/?id=p6zjojqw

30

u/Tango00090 11h ago

Thats why windows is so goated, so many memory leaks that any agent trying to break free would rather kill itself

5

u/dashingThroughSnow12 11h ago

A misaligned Astra looks at Windows and says “no competing with this agent on destroying mankind.”

2

u/Glass_Extension_6529 11h ago

AI can never win against WINdows

24

u/No_Boysenberry4825 11h ago

They’re not wrong 

14

u/IntelArtiGen 11h ago

I wish Windows and Linux had better sandboxes available by default.

13

u/Mother_Idea_3182 11h ago

On Linux you have podman running as unprivileged user. Isn’t this enough?

8

u/fzammetti 9h ago

Containers are not security boundary, MOST ESPECIALLY with how capable models since Mythos have become. Even VMs may not be enough before too long.

5

u/Horat1us_UA 8h ago

Good thing most people don’t run unrestricted Mythos with sole task to break sandbox 

4

u/reflexive-polytope 11h ago

You get a bunch of files owned by strange UIDs in your home directory. It's awkward.

1

u/gplusplus314 8h ago

Plus seccomp…

1

u/IntelArtiGen 10h ago edited 10h ago

I'm not saying it doesn't exist, just that it's not easy enough to use for most people. By default most distros aren't made with sandboxes in mind. You install a software, it can access and do everything the user running it can do. And if you want a software to only have limited access to the system (read / write / network access etc.), it's not done in 3 clicks afaik. You need to run it with a specific command and understand how sandboxes work precisely.

I have something closer to Qubes OS in mind I assume. Even just per-app permissions is a lower-level example of this. As long as it's not just Everything or Nothing, which is the issue for Mac it seems. Obviously it's all very complicated and there are many vulnerabilities if it's not done correctly. You can be paid $250k if you find a sandbox escape in Chrome, and some people are paid that, even when you put a very high price and you have the best engineers on the planet, it's difficult to do a good sandbox.

3

u/RoomyRoots 9h ago

Chroot is older than people here. LXC can legaly drink in many countries.

2

u/muntaxitome 10h ago

Just run it inside docker

2

u/vlatheimpaler 7h ago

People spend $200/mo for Claude but won’t spend another $5/mo for some cloud machine to run it from..

1

u/pancakeQueue 3h ago

Linux has namespaces by default, just using them requires knowing the tools.

13

u/Hiply 11h ago

Yeah this needs to be an option baked into any current OS - and ideally some people releasing working code to apply those rules to OS's a generation or so older.

5

u/PoppingPillls 11h ago

I mena you could always run models in a virtual environment, less convenient but thats life.

6

u/Primary-Strike5187 11h ago

Maybe the atomic/immutable Linux distros are onto something…

2

u/The_All-Range_Atomic 9h ago

Isn't that what Android is? Malware and rogue agents can still fuck up your data partition, which would soft brick your device until you wipe it.

The only difference is having to reinstall the OS, but at that point it doesn't really matter.

1

u/Primary-Strike5187 8h ago

I believe android does have a read only root filesystem, and yes it’s not a perfect solution but it does make it much harder to do. It’s not an impenetrable wall but it’s better than no barrier of any kind.

2

u/dimag0g 8h ago

I'm not afraid the AI wrecks my OS, it's a matter of minutes to reinstall or revert to a working disk image. I'm not hosting Facebook at my home PC and can afford downtime.

The real value is in the data l'm working on, not the system.

1

u/Primary-Strike5187 7h ago

Sure but most people don’t store their data on a separate partition so if the system gets borked and they reinstall the OS it also wipes all their data. Read only root file systems protect against that by not letting the system get borked in the first place.

1

u/sailhard22 10h ago

As long as it doesn’t interfere with competent engineers trying to perform work

1

u/lyidaValkris 10h ago

So will I, but not using AI, let alone granting it any permissions whatsoever.

1

u/ChristianKl 8h ago

The security model of desktop OS's was bad before and having more rights management of your average app is good for security even outside of AI agents.

-3

u/Expensive_Finger_973 11h ago

Much like Gatekeeper this is just more hand holding in a futile attempt to protect people from themselves.

2

u/inotocracy 10h ago

Well we do have labels on shampoo instructing people not to drink it.

0

u/Medium_Banana4074 10h ago

WTF. It's annoying already.

How the hell is people's stupidity Apple's responsibility?

3

u/DanielPhermous 6h ago

Apple has to deal with people coming into the Genius Bar with problems. Minimising that load is clearly in their interest - and also in the interest of those customers.

0

u/natefrogg1 10h ago

Bets on the first container breakout, good luck Apple

-3

u/Ruined_Passion_7355 10h ago

I'm sick of tired of losing ownership over my computer, let alone because dumb ai bros give entire control of their computer to a probabilistic machine. They deserve it.

-5

u/moodygradstudent 11h ago

It makes sense, given how Mac storage isn't upgradable, and the system storage and firmware are on the same chips. I imagine Apple would have to cover more returns or warranty repairs if they didn't put in safeguards.

2

u/DanielPhermous 6h ago

What repairs? LLMs are not capable of physically damaging anything.

1

u/blow-down 1h ago

wtf are you talking about

-1

u/happyscrappy 11h ago

Full disk access is already limited and must be explicitly granted. I don't quite understand what this is saying and what will change.

I guess one change is that it should be impossible for an agent acting as a user to grant itself full disk access. But that restriction seems impossible because some people grant agents full access to their mouse and keyboard and so the agent can just click the box and authorise.

0

u/dimag0g 8h ago

I don't get what the advantage would be. AI tools already ask you before even reading your files, and a second time before writing to files or running a script. People who click through warnings without reading will just have to do it one more time, clicking on "yes, I pinky swear I want to give AI full access" with exactly the same level of risk as before.

2

u/DanielPhermous 6h ago edited 5h ago

The current permissions give access now and forever while LLMs are capricious toddlers with your work sometimes.

1

u/account22222221 5h ago

They do that, you know when they remember. Once every 15 times they do it without asking then say oops….

-1

u/redditrasberry 5h ago

Feels like a reaction to things like Muse and Dots taking advantage of full access to automate things. The question is, will Apple leverage it as anticompetitive measure (will their own tools get the same likely alarming warnings when the user tries to enable it as third party ones do?).

2

u/DanielPhermous 4h ago

will their own tools get the same likely alarming warnings when the user tries to enable it as third party ones do?

LLM agents are too unreliable for Apple to risk putting them in, except in very restricted ways. However, to answer your question, if they do and no trick has been discovered to make them reliable, yes, they will absolutely apply the same rules.

I mean, the Apple weather app on the iPhone gets the same warnings as any other ("This app is using your location...").

-7

u/Vapornater 11h ago

not sure how i feel about this. tbh i don't see much difference in a user breaking their mac vs an llm breaking their mac given both are usually caused by the user incompetence

-12

u/millanstar 11h ago edited 11h ago

Meaning Macs will not be it for AI development. And I dont need a company babysit what I do with my hardware, whats next? Limits on what do you install to the disk?...

-16

u/ttubehtnitahwtahw1 10h ago

Apple are just mad that it's not their ai, and that for the first time they aren't the leader in the space.