Apple can’t see a future where Mac isn’t like iPhone. They need a 30% cut of all software revenue, want a 30% cut of any AI tokens you use, and will steal 30% of your time as a software developer developing for your own account any way you can.
I do feel since I use hermes on my work windows computer and grok bot in the cloud on everything else that computer use is so useful and important, but I'm also worried that Apple will not be a good choice for that.
I think the observation Ben is making, is that Apple no longer has a grasp on the future purchases in the market. He makes it explicit with this quote: "I can, for the first time, envision a future where I don’t buy Apple by default." It used to be a given that we would refresh every 3-4 years, thats probably no longer guaranteed.
Observationally, I would argue we've all been expecting this for this for a long time. Every year Apple has raised the price of allegiance and every year we've paid it, waiting for products like the framework laptop or certain linux distros to become mature. We're still not there yet, but how much longer until there is real competition in the personal computer market?
“this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet”
We’ve known that improperly secured ports and non-firewalled machines get popped. When will people learn?
I know let’s put our power plants and water treatment out there with open ports too. Why should endusers have all the fun?
> The question, however, is whether what they are designed for is the future I am barreling towards, one where agentic abstraction both renders traditional interfaces relics
I think he was burying the lede but glad he finally posed the question.
I think it's a bigger risk factor for Apple than is generally assumed. If consumers get used to the freedom but endemic spying of products like Muse, Apple may have a hard time sticking to their privacy and security mandate.
I would argue that someone who would open a remote access port to the internet with no filtering is exactly the kind of person that Apple needs to protect from themselves
Yeah, it was neat that Claude found this, but Thompson showed an almost criminal lack of security awareness by having VNC/ARD open to the internet
What I find most surprising, is that I don't think we got any sort of timeline from Apple on this change and its very vague (which just fuels articles like this).
So did this initiative within Apple just start and we could be looking at this change coming in Mac 28?
I don't remember another time of an announcement like this from Apple of a major change with so little information, though I could be wrong or hint of when.
Regarding the concern, while I do hope that there is still a way to grant actual full disk access to some applications. Even Apple called out a non controversial need for something like that, backup software. I can also think of security scanning software, a lot of businesses have those deployed to corporate Mac's. I do also think that better controls around it, especially in this age of vibe coded apps that never actually think about security or actively hostile companies like meta.
Did the author have his Mac exposed to the internet and not behind a firewall? How did his screen sharing port 5900 get accessed if he was behind a physical firewall/home router?
Observation:
> Hopefully Apple has in mind a solution to this situation that will still enable knowledgeable power users to confirm agreement to a sufficiently scary warning and put their Macs in a state similar to what we have today. I worry. What alleviates my worst fears is the knowledge that every technical user at Apple itself needs to use their Mac as the powerful Unix workstation OS that it is. Some of us need dangerously powerful tools. Most Mac users, however, do not — and don’t realize they’re using a dangerously powerful Unix workstation with a very friendly (literal) face.
> This system is annoying but manageable on your primary Mac; it’s a disaster on a headless Mac running agents, for two reasons. First, agents write new programs all of the time, and in my case, those programs need access to devices on my network (SMB shares, for example, trigger a TCC warning). What I need is a permission layer for agents, not the programs they create; TCC is operating at the wrong level of abstraction.
Doesn’t that already exist? If I give Terminal.app access to the entire disk, CLI tools started by the app (indirectly: Terminal.app runs a shell, and the shell runs the tools) have that access, too.
And I don’t think that’s because Apple gives Terminal.app preferential access. Google tells me that works for iTerm, too.
Or would it mean agents need to do some special thing to launch tools?
What I took home from reading this article is Apple NOT deploying security updates as security updates. That to me is SO stupid on their part—coercing to the point updates by withholding important security updates.
Having 5900 hot to wan.. He wrote an article to tell the world that he doesn't understand basic networking.
I have a Macmini purposely for Codex to do whatever. Nothing personal on it. It’s been a productivity boost 1000x for me. I screen share in, give it some tasks, tell it to install software, run brew whatever, use QGIS and other complex software and email me screenshots. Astonishing.
But I’m worried because of this and other guardrails all of that will be impossible or much harder in the future.
> I understand that people are nervous about giving these agents access to one’s computer — as I noted, the Mac Mini in question has nothing on it except for Codex and Claude — but in this case you could make the case that I would have been in much more trouble had I not had an agent running persistently.
If the burglar breaks in through the cat door but she wakes you to let you know, did the cat make you more safe?
You don't want a backup vulnerable to "reading iMessage" either - maybe they should just encrypt these things at rest.
Couldn’t you give agents access to the screen sharing software to see the TCC prompts?
The vuln required "port 5900 was accessible from the Internet"
Why would anyone open up random ports (or even all ports) to the internet?
I'm missing a key point: why does the author say TCC is implicitly to blame for his Mac being hacked?
If the main to run Apple computers is their hardware, why not to run it with Linux. Aside from better filesystems (Theo tests were shocking to me, how bad FS you guys have), you would get better compartmenalization and I believe better security. What's missing?
Is the conclusion of this that Apple shouldn't add robust and hard to automate around privacy guards because we should all just do as he does - use a dedicated Mac mini for agents with no personal files on for privacy?
> Apple doesn’t seem too happy about agents
I don't get this reaction to Apple making Full Disk Access more explicit. Whether they're "happy" or "sad" about agents doesn't seem responsive at all.
Kinda seems like whenever you spend 10 seconds thinking about the average user, social media get angry.
I feel like this article was all over the place. Also, this person was really running a macOS box raw on the Internet, no firewall, nothing? :/
My rule: if a company, in any way, forces you, the user, within reason to do anything you don't want to do, or prevent you from doing anything you would want to do, then ditch that company ASAP.
The entire iOS/MacOS schism already says enough.
> Then there is the fact that macOS is a certified Unix system
They didn't renew Golden Gate's UNIX 03 certification this year:
“If Woody had only gone right to the police(used a vpn), this would not have happened.”
It’s not like a VPN is some arcane knowledge. I guarantee Claude would have told him or practically yelled at him if he asked how he could have secured his mac exposed to the open internet.
Glad he actually acknowledged it and is getting tailscale or similar.
> What I need is a permission layer for agents, not the programs they create; TCC is operating at the wrong level of abstraction.
Or... you are operating your computer at the wrong level of abstraction. It was made for use by a real intelligence.
Giving a text assumption engine root access to the world, "hey little clanker, heard you understand 10% of every topic, go nuts."
[dead]
[dead]
It is not about emotion; it is about platform control. Apple limits background autonomy under the label of security, while ensuring only their first-party system frameworks get unfettered ambient access. Standard playbook.
The sole fact that products from Apple and many other proprietary manufacturers receive so much attention on the discussion board called "Hacker News" is utterly ridiculous. A good example is the thread named "Turn off Apple Intelligence on macOS 27 and get its disk space back" with 600+ points and 400+ comments on the main page today.
What's worse is that a big part of the discussion here is just worshipping closed-source from a merely consumer perspective ('...wow! what a cool shiny UI feature to manage SSH keys for only 0.99$'), as if we were on the Tom's Guide forums. And some active members here even purchase browsers and seem to be very proud about it...
The full disk access permission is something you give to backup software.
If you give full-disk access to Meta software running on your main computer, Meta is not going to respect your privacy.
> Friday’s [full-disk access] announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.
https://arstechnica.com/security/2026/10/apple-changes-full-...
If you want to know why Apple is suddenly not happy about the way the full-disk access permission is being abused, look no further.