<- Back
Comments (93)
- eviks> We give developers powerful APIs to build incredible capabilities> Full Disk Access largely sidesteps these controlsThat's because you don't really. Just like you don't give users "powerfulf" controls, so instead they have to resort to dumb ones like "Full disk"For example, if you care about "mail, messages, and even browsing history", why isn't there a subset of "full disk access except for reading mail/messages/browsing history"? Or if vibe code have some basic disk sizing functionality to ask questions about your files, why can't it have a more granular "full disk read only access for file sizes only" so that your vibe coded disk visualization app can't destroy your data or your privacy> can only do so with very explicit user action.Which is in the same vein and is mostly useless, just another inconvenient bump
- liuliuI don’t quite understand why people complains this is bad for AI agents. Local Code (https://releases.drawthings.ai/p/public-beta-of-local-code-b...) doesn’t require full disk access, when you ask the agent to deal with some files it doesn’t have access to, the built-in ‘permit’ tool will trigger the OS folder grant interface and that information will be recorded both by Apple and by the app so it can be revoked later if you want. That allows you to not give full disk access to the app to be useful.
- moecablesIMHO, it's good to add more specific controls for this. After reading this, I went and checked my list of app with full disk access:- Ghostty (fine, it's my terminal)- Alfred (fine, I use it for searching everywhere)Then I have a few turned off:- Spotify (why does it need full disk access) ??- Gemini (nope, don't need it to know everything about my computer)
- mrkpdlI would like the ability to see which specific folders I have granted access to on an app by app basis. And edit. It’s not clear to me how you revoke an app’s individual folder access after you have granted it.
- post_breakOne update away to revoking Full Disk Access in the future. This commercial has come full circle: https://www.youtube.com/watch?v=VuqZ8AqmLPY
- PeanutOSThis week, I formatted my entire Mac fleet (an iMac Pro and four MacBooks), and now neither AI agent runs natively. I am using LIMA (https://lima-vm.io) to isolate them in a sandbox, exposing only a repository. I lose some integration, but the peace of mind is worth it.
- Kim_BruningAm I getting old? "full disk access" used to be something that's supposed to be normal; if you're the owner of the machine.
- etatesterWhat we need is true application isolation even in the command line. Treat Terminal as privileged access, not something any app can just command. Sandbox non-app store apps as well.
- zmmmmmIt's fine if there is a super streamlined flow for access that works with legacy apps and runs in user-mode. Otherwise this might seriously hurt MacOS as a viable development platform.
- VCFundedGenYerIf it worked as intended, they wouldn't be in this predicament.That feature was so stupidly nonfunctional before. Some apps got stopped by it, others didn't. Often you'd be able to install an app from homebrew and it had full ride access to the disk, while App Store apps had to request consent for any folder whatsoever. It was completely random.
- profmonocle> we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so"Extraordinary" is a funny word choice. It was completely ordinary for most of the history of personal computing that any app you ran under your normal user account could see everything you had.(I'm not saying this is a bad thing. As long as they allow informed users to continue to do whatever they please, I'm all for it.)
- jameskrausOh no, even more permission prompts on macOS. It's already almost unusable due to the existing ones.
- plantain"Updates to-" instills such a deep-rooted fear in me. I know whatever follows is about to suck.
- pkulakI feel like this isn't going to be a simple permission popup. Probably along the lines of getting an "unapproved" binary to run, where you have to stop what you're doing and wade through settings, trying to find the right toggle 6 nodes deep in the tree.
- tapvtI dislike restrictions out of instinct, but to be fair, I've had permissions request popups on my Mac that were the first sign of software, which I had actually written, maybe had some bugs allowing it to work outside of its intended bailiwick.
- tekacsApple, as always, seem extremely determined to make sure that they protect things on your computer from being accessed by you.Apple Intelligence is a great example of this. Everything can funnel up to Siri, but neither you nor any other app on your computer can see what is fed to it by all of the APIs that would provide it data. So anyone who adds support for it is enabling Apple to do their usual slow broken thing with Siri and not enabling any other way you might want to use software or AI with that data.
- techscruggsEveryday, we get one step closer to the year of the Linux desktop.
- big_toast"Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac"Huh? Seems like a disingenuous statement. I hope they update that sentence with something more accurate.However, I've wanted much more granularity and pervasive permissions so I'm glad they're adding them.
- rwzWhen I give something a "Full Disk Access" permission, I expect it to have full access to what's on my disk, including "files, mail, messages, and even (gasp) browsing history"! Who are those mysterious people who expect their browsing history to be magically excluded from something called Full fucking Disk Access?
- russellbeattieMaybe it's just my pet peeve, but it's less about my documents and mail and more about programs, tools and AI harnesses deciding they can fill hidden dotfile folders at root with whatever they want (which they do indiscriminately). I don't just hate that there's tons of untracked caches and temp file data that isn't easily discoverable, but more specifically, I don't want all that crap in my root directory.Who decided that hidden folders are a good thing anyways? .agent, .agents, .aws, .bun, .cache, .cargo, .claude, .codex , .config, .docker, .gemini, etc. I just end up having to show hidden folders all the time, which defeats the point.It's gotten truly ridiculous. I want the OS to strictly enforce my root directory. There should be a few global preference files in there for like .zsh, and everything else organized in proper, unhidden folders.
- ls-a[dead]
- jonathanstrangeIf there is one thing I absolutely despise with all of my heart, then it's mega corporations patronizing their paying customers.
- lapcatMy understanding is that Meta Muse simply opens the System Settings Full Disk Access pane, and the user has to enable it themselves using System Settings, which says, "Allow the applications below to access data like Mail, Messages, Safari..." and which requires an administrator password to change.Thus, I'm not sure what more Apple can do here, but I'm definitely afraid of what they're going to do.