Skip links

Apple Revises Full-Disk Access Permissions to Prevent AI Agent Misuse

Apple has announced updates to its macOS privacy settings aimed at preventing third-party application developers from improperly accessing user message histories. This decision was made following a recent incident where technology columnist Jason Aten revealed that Meta‘s AI agent, Muse, sent him an unsolicited notification referencing a private conversation he had via Apple Messages.

Aten expressed his surprise at this breach, noting that he had not granted permission for Muse to access his messages and assumed they were secure. This incident ignited widespread discussions on social media, with many emphasizing that while AI assistants can be beneficial, they resemble powerful tools that require careful handling to prevent potential misuse.

Responses from the Tech Community

Following these revelations, David Singleton, Meta’s Chief Technology Officer, offered a counter-narrative. He asserted that for Muse to access Apple Messages, users are required to manually enable two specific permissions: full-disk access, which is a system-level permission, and a Messages connector setting within the Muse application.

Singleton stated, “The Messages integration in the Muse Mac app is opt in. Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.” His comments suggested that if Aten’s messages were accessed, it would imply he had inadvertently authorized these permissions, placing the responsibility on the user rather than the platform itself.

Security expert Patrick Wardle voiced skepticism regarding Singleton’s claims. He pointed out that with full-disk access, any non-root file, including browsing histories, cookies, and chat logs, can be accessed. When questioned about how Muse could read messages despite claims of restricted access, Meta’s public relations reiterated Singleton’s previous statement without further clarification.

Editor’s Take

This development is significant for users as it highlights ongoing concerns regarding privacy in an era increasingly dominated by AI technologies. The need for transparency around permissions is paramount to maintain user trust. For businesses and developers, this serves as a cautionary reminder about the importance of adhering to stringent privacy standards when designing AI systems. As the industry evolves, balancing functionality and security will be essential to ensure user safety.

Source: arstechnica.com

Leave a comment