logoalt Hacker News

danaris • today at 11:40 AM • 2 replies • view on HN

Counterpoint:

https://pxlnv.com/blog/macos-full-disk-access-restrictions/

> ...the uses of Full Disk Access go well beyond the category of backup apps, and it is worrisome to see Apple give it such a limited frame. I have given that permission to disk management utilities, Sketch, Terminal, and other apps I do not want to be throwing permissions requests as I move around my drives. Is Apple suggesting this capability could be limited in the future to backup applications alone? I do not like that.

If Full Disk Access were, in future, to be something that I could not grant to (for instance) the Terminal, because it is not a backup app, that would severely limit my ability to do work on a Mac, both as hobbyist and as computer professional.

I agree that the agent situation is a fairly serious concern; I just don't want to see Apple throw the baby out with the proverbial bathwater.


Replies

GeekyBear • today at 11:52 AM

From Apple's statement, there doesn't seem to be any plan to remove the full disk access permission.

They want unsophisticated users to understand that they would be granting unlimited access to all of their personal data if they grant software that permission.

> We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.

➕ show 1 reply
snazz • today at 12:40 PM

I hope what they offer is the ability to set more granular rules, like allowing my Borg backup script to access the whole disk, but not any random Git precommit hook (for example). Given that practically all of the existing restrictive security features on macOS (for example, SIP) can be disabled, I feel confident that Apple will make hobbyist and professional use cases still possible, just requiring some extra scary messages. I’m ok with that trade off.