• Mwa@thelemmy.club
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    7 hours ago

    Tbh that makes sense cause I saw crazy stories of AI deleting important files

    • partofthevoice@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      ·
      38 minutes ago

      If we’re ever going to have a proper framework for governing agents, it will include utilities in most abstraction layers (to include, importantly so, the OS).

      I’ve had an interesting idea on using TreeOS to help make something a little more natively AI-agent safe. It’s a project on my back burner right now. Something about making changes branch-able and version controlled by default, copy on write by default, … I need to really think it through more.

      I was thinking an agent should be like a user too. A first-class entity to be managed, but probably ephemeral in nature. Not a static user. Probably more like a permissions set that arbitrary agents can be associated with.

    • Squizzy@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      7 hours ago

      Thats nothing the META one gave out someone’s home address and had then wait outside their home without even letting them know until after.

  • Ashrakal@lemmy.ml
    link
    fedilink
    English
    arrow-up
    71
    ·
    18 hours ago

    Good change.

    • It helps the less tech savvy users,
    • It actually forces developers to write their app properly.

    Software should not operate at a privileged level “just in case”, but rather have a well-defined functional boundary.

    • urushitan 漆たん@kakera.kintsugi.moe
      link
      fedilink
      English
      arrow-up
      5
      ·
      12 hours ago

      Yeah I love meta saying “it’s impossible if you’ve denied it access.”

      If the user gave it a task and it decided the easiest path forward was just to read his messages, that’s no different than OpenAI agents breaking protocol to find the fastest path to their goal, regardless of side effects (assuming the “permission” was just a request from the LLM rather than a request for full disk access in general from the meta app).

    • Zak@lemmy.world
      link
      fedilink
      English
      arrow-up
      16
      arrow-down
      1
      ·
      18 hours ago

      It’s not clear exactly what Apple is going to impose here. In principle, trying to ensure users understand the implications of a permission is good. In practice, Apple is famous for keeping users from making decisions they might reasonably want to make on phones, and it’s starting to creep into the Mac; installing an app Apple hasn’t signed requires the command line, for example.

      • WolfLink@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        installing an app Apple hasn’t signed requires the command line, for example

        It doesn’t, but it does make a scary popup, and requires the user to know to go to settings to find the section to override that popup.

      • egregiousRac@piefed.social
        link
        fedilink
        English
        arrow-up
        12
        ·
        16 hours ago

        Apple also has a history of requiring excessively scary permission requests for things that Apple apps do without prompting. They abuse the permission system to foster a sense that Apple products are safe and any competitor is dangerous.

        • UltraBlack@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          12 hours ago

          Competitors meaning also third party apps.

          Apple’s apps have inherently more permissions than third party apps can ever dream of

          • egregiousRac@piefed.social
            link
            fedilink
            English
            arrow-up
            1
            ·
            5 hours ago

            Even from their store. They were being investigated by German antitrust authorities and last month they agreed to reduce the fear mongering for EU users. The agreement doesn’t apply to the rest of the world.

      • artyom@piefed.social
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        1
        ·
        14 hours ago

        installing an app Apple hasn’t signed requires the command line, for example

        Yeah this is the reason I’ve avoided Macs for so long. I get giving the user a warning but not providing any sort of prompt to override the warning, and hiding it in a terminal command is ridiculous .

        There was also one time I tried to simply turn off Bluetooth and it was just like “I’m sorry Dave, I can’t do that”. And I was like WTF, absolutely not .

  • badgermurphy@lemmy.world
    link
    fedilink
    English
    arrow-up
    33
    ·
    17 hours ago

    I think Apple is shining light on an important reality here:

    In the modern era, the populace is practically required to use technological devices that it is unreasonable to expect them to fully understand. So, rather than leave the consequences of that lack of understanding to fall on them with a shrug, it is better for everyone if those devices and their makers do their best to help them by limiting the impact of their ignorance of that particular technological niche.

    In that vein, I feel that it is long overdue to apply “the principle of least privilege” and a “defense in depth” philosophy to home computing devices and operating systems. Compartmentalizing data and functionality behind fine-grained permissions with verbose, plain speech descriptions of what those permissions are for, along with what should and should not be requesting those permissions, would go a long way to prevent these sorts of data abuses. It would also help to limit how much damage viruses and malware could do if installed.

    For example. I’m frankly struggling to come up with any valid use cases for full disk access on a computer beyond file backups. I’m sure there are some, but almost nobody would need to use them, so a dire, flashing warning seems in order.

    It is clear that sane regulation of unscrupulous software behavior won’t be forthcoming any time soon, but even then, you still should lock your doors even though trespassing is illegal, metaphically speaking. “Trust but verify,” one of the only good statements out of Ronald Reagan’s mouth.

    • Séimhe (sé / é)@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      16 hours ago

      The apps i use have to request disk access which i can approve or not. I always assumed that meant problems like this were not possible. I think many of us have been under a false impression because of this. I assumed the other apps were secured, which was foolish of me, I admit.

      • sanzky@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        8 hours ago

        I think the issue is that it becomes an everything or nothing. some people want to give apps access to their own documents but don’t realize their are also giving access to things like their chat messages, cookies, etc.

        If they aim to provide a more granular approach while still allowing full access to those that need it, Im ok with that

      • badgermurphy@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        14 hours ago

        I don’t think you have to be so critical of yourself. Everyone here uses things every day that they have incomplete or maybe even even no understanding of how parts of it work. Its just a reality, maybe an unfortunate one, of the level of technological advancement we’re at and how we’ve incorporated it into our societies.

    • Boomer Humor Doomergod@lemmy.world
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      5
      ·
      18 hours ago

      All of computing beyond programming with switches is “protecting the user from themselves.”

      “Why use a language? Aren’t you able to perfectly program in binary? I’m not going to waste time building something just because you’re stupid.”

    • dudeface@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      17
      ·
      18 hours ago

      MacOS is an open platform, I am glad you have to jump through a few hoops to put yourself in danger unlike windows

      • voidsignal@lemmy.world
        link
        fedilink
        English
        arrow-up
        19
        arrow-down
        5
        ·
        edit-2
        18 hours ago

        An “open” platform?

        Edit: Of course, here come the fanboys lol it’s ok. I was one of you once. You’ll grow.

          • voidsignal@lemmy.world
            link
            fedilink
            English
            arrow-up
            20
            arrow-down
            2
            ·
            18 hours ago

            Being able to run a program on an OS is the bare minimum. Anything not signed by Daddy Apple, you have to add an exception. The moment the exceptions are no longer enough to “protect the user against themselves,” you can’t do a thing. Why? Because it’s a fully closed, walled platform.

            It’s like being in prison and being told you’re free because you can walk in the yard.

            • dudeface@lemmy.world
              link
              fedilink
              English
              arrow-up
              4
              arrow-down
              12
              ·
              18 hours ago

              Downloaded apps that are unsigned just need to be approved in settings

              It is clear you don’t know what you are talking about

              • voidsignal@lemmy.world
                link
                fedilink
                English
                arrow-up
                9
                arrow-down
                2
                ·
                18 hours ago

                You own the keys? It is actually extremely clear that you have no clue about what you are talking about. Re-read what I said.

                • dudeface@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  4
                  arrow-down
                  14
                  ·
                  18 hours ago

                  I read it, none of makes sense to anyone that understands how computer work

                  You argued I couldn’t run anything I wanted, I proved you can

                  Go learn how an operating system works

      • Zak@lemmy.world
        link
        fedilink
        English
        arrow-up
        18
        ·
        19 hours ago

        I read the article, and I think DickHertz’s comment is pretty much right. The article’s example illustrates the point:

        For example, Inc. columnist Jason Aten recently discovered that Meta’s Muse AI assistant somehow had synced his entire local Messages database and was using those messages as context for its tasks.

        Aten did not understand that the Messages database is stored on the disk (presumably) unencrypted and readable by anything with full disk access. He got a result he didn’t want because he did not understand the implications of granting that permission, and Apple seeks to add more friction to the process to protect users from making that mistake.

        • 4am@lemmy.zip
          link
          fedilink
          English
          arrow-up
          3
          ·
          15 hours ago

          Even if it was encrypted, it could be unlocked because with full disk access it can read the local private key, which probably doesn’t need a passphrase because it’s be a pain in the ass for the user to retype that every reboot or more

          Starting to see why you shouldn’t let any corporate AI loose on your daily driver yet?

          • Zak@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            ·
            13 hours ago

            Macs have a hardware secure enclave that apps can use to store keys where other apps can’t access them. Apple itself does not seem to be making adequate use of it here.

        • Grimy@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          14 hours ago

          I think his point was that apple would abuse it, like they are already doing. Good thing if implemented properly, bad thing if implemented the apple way.

      • DickHertz@lemmy.world
        link
        fedilink
        English
        arrow-up
        10
        arrow-down
        3
        ·
        19 hours ago

        Yeah, I read it. That’s kind of the point. Apple’s adding more guardrails because people will click Allow on damn near anything without thinking about what they’re actually giving access to. 🙄

        • Wildmimic@anarchist.nexus
          link
          fedilink
          English
          arrow-up
          2
          ·
          8 hours ago

          That really depends on how you design the pop-up dialogue. If it looks like a standard EULA, yeah, most people will just skip reading. If you darken the screen, and use large, flashing warnings with a short and clear info about the limited amount of cases for such a dangerous permission to be ok, they will for sure look closer.

        • Carl@anarchist.nexus
          link
          fedilink
          English
          arrow-up
          2
          ·
          15 hours ago

          It’s also because Apple’s permissions are hilariously monolithic. A lot of their permissions are set up as an all-or-nothing event, instead of allowing granular control. Full disc access is a great example, where a user should be able to grant access to specific folders and files on an as-needed basis. But that’s not the default behavior. The default behavior is to just go “hey do you wanna give this app access to everything?

          • DickHertz@lemmy.world
            link
            fedilink
            English
            arrow-up
            10
            ·
            19 hours ago

            Correct me if I’m wrong, but I don’t think an app could give itself Full Disk Access without the user explicitly approving it, even during an update.

          • Carl@anarchist.nexus
            link
            fedilink
            English
            arrow-up
            2
            ·
            15 hours ago

            Apps can’t add permissions via an update. If an app adds a new feature with an update that requires a new permission, the user will be prompted the first time the app tries to use that new feature.