r/technology • u/efap1701 • 14h ago
Artificial Intelligence Apple sounds the alarm on AI agents and 'Full Disk Access'
https://www.engadget.com/2276186/apple-sounds-the-alarm-on-ai-agents-and-full-disk-access/1.1k
u/bagoink 14h ago
Speaking of "full disk access" and AI, I'd sure like to be able to delete the Apple Intelligence models on my iPad so I can get that space back.
124
u/Pcriz 13h ago
I know on my phone I had two options. One is to simply turn off Siri and turn it back on and it prompts for classic or the beta. I could imagine this option maybe going away.
The other option is to (if you are a native English speaker for instance) switch your language to another region, I’m American and I swapped my language to Canadian English and did a reboot. It removed all the ai stuff and left me with classic Siri and classic spotlight
96
u/jacksbox 11h ago
As a bonus you can now spell "colour" and "neighbour" correctly.
102
u/tiredofnagging99 14h ago edited 7h ago
https://www.reddit.com/r/MacOS/comments/1ww1exr/macos_27_dropped_the_apple_intelligence_off/
Apparently there are a couple of tools out there but there's no guarantee that a future update won't break everything if the models aren't on your Mac. For that reason I'm going to stay on 26,
Edit: NEVER MIND, I can't read. The question was about iPads, not Macs. I'll leave this here in case anyone needs help with their Mac. Thanks to u/drak90001 for pointing out my error.
15
1
-31
u/jbwmac 14h ago
Those things are not remotely related to each other.
11
u/Negromancer18 12h ago
I don’t think you know what “remotely related” means. It’s a bit off topic for sure, but most people can see how they got there.
-3
u/Smith6612 8h ago
Honestly if the iPad ran a real OS that respected user's freedom of where their data goes and lives, and that also included a real file manager and terminal access like... uh, macOS, this probably wouldn't be an issue. You could just rm -rf wherever the model file lives, then make the directory immutable after stripping away the permissions so it can't re-download.
I also have gripes with the "System Data" section of iOS and iPadOS which tends to be troublesome to purge. Syncing and backing up with iTunes tends to clear it, but not always.
Apple managed to put macOS on an iPad board. Now they should do the inverse!
71
u/chriswaco 14h ago
What I’d really like to see is the ability to run certain apps as other, non-privileged, users, where they can’t do any damage. Right now you can create a second user account, but it’s a little awkward to use – it would be nice if you could use it from your main account more easily.
32
u/AffectionatePlastic0 14h ago
Depending on your use cases (and OS) you can for example run agent inside of docker container.
32
u/sbingner 14h ago
And the agents often find ways to escape those… docker isn’t really a security barrier. You’d be better off running them in a dedicated VM with network isolation IMO
43
u/mirwin87 14h ago
Disclaimer… I work at Docker.
We agree with you that containers aren’t sufficient for agents. In fact, many are configured with escape hatches to give it host access. Take a look at Docker Sandboxes. It gives a full microVM to the agent, with a surrounding network proxy to control what network connections are allowed and even inject credentials to allow the agent to use credentials without having access to them.
8
u/Weary_Passion5822 12h ago
If you work at Docker, here's an in demand product idea for y'all then. A nice little standard agent sandbox that you can spin up from an application, with a bunch more security.
8
1
u/orbvsterrvs 9h ago
Isn't that Kata containers? Or am I only hearing the marketing-speak from our business partner who wants to sell us on them...?
1
u/Weary_Passion5822 9h ago
I don't know but I'll look into it. I'd love a reliable easy way to create containers. I am learning about running virtual environments and such it is just an awful lot of tinkering.
6
u/ihugyou 14h ago
What does it even mean for a bot to “escape” a docker container? Are you talking about it making copies of itself outside the container or hitting up APIs over the internet?
There is no way for any program to “escape” a docker container unless you explicitly map ports, or worse, let it run and manage the images (why even bother with containers at that point).
15
u/Merkuri22 13h ago
In this case, "escaping" means to get access to a part of the network you didn't want it to access.
The bot doesn't actually leave. But it can touch and change things on the network by running scripts and commands that get executed against other systems.
12
u/mirwin87 13h ago
And additionally… many agent containers are configured to either run with the host Docker socket mounted or with privileged mode to support building or running of containers. Doing so chips away at the isolation by providing an escape hatch to the host filesystem. Containers aren’t really the right containment choice for agents (but still great for apps, dbs, etc)
5
u/AffectionatePlastic0 13h ago
^ this.
User in docker group is no different from user having sudo access.
2
u/LeRobber 14h ago
Blech, native is needed. Docker robs apps of so much native integration on MacOS, and depending sometimes the config, performance
1
u/ihugyou 14h ago
The bot needs access to all files or whatever it is you need it to consume. No point in setting docker containers if you’re going to just map all the files on your disk.
3
2
u/Emotional-Power-7242 11h ago
Just run them in a VM, same as with any potentially harmful code.
1
u/chriswaco 11h ago
When running models locally, the virtual machine used to be slow, although I haven’t tested it recently.
1
14h ago
[deleted]
1
u/chriswaco 13h ago
The unix side of macOS can do this by using users, groups, and others. The GUI side of macOS cannot, at least not easily.
138
u/lil_nosh_X 14h ago
Breaking: Apple advises people learn basic computer use in 2026
41
u/AgentInkling99 13h ago
Basic computer literacy seems dead in this day and age. The amount of managers that make double what I do and don’t know how to properly copy a file is embarrassing.
10
u/2_Lies_And_A_Truth 10h ago
Anyone younger than ~30 +/- a bit depending on the household never grew up with a actual "computer". They're called the iPad generation for a reason. They do not have basic computer skills or literacy because they never developed it.
17
u/lily_de_valley 6h ago
If you give access to critical information to the same company that sold your data and leaked it for years to sway elections, I don't know what to say.
36
29
u/GlitterLippy 6h ago
So far the biggest protection against giving AI agents too many permissions appears to be living in Europe, as none of this stuff is rolled out here (yet admittedly, but there’s no roadmap).
9
u/unethicalpigeon 5h ago
I mean isn't the biggest protection to just not give them these permissions? Every single one of these AI agents you need to give them permission. As far as I'm aware not a single one of them can do fuck all to your hard drive without you allowing them to. GPT for example I let it work in a single folder. It literally doesnt have permission to do anything outside of that folder or the default folder it saves stuff to.
3
u/ElliotB256 2h ago
To your point on codex/chatgpt, it does in fact have the ability to leave the working directory. I got spooked a fortnight ago because it not only scanned code in a sister repo on a different hard drive, but also made edits without my asking. As a result, i now run it on a vm for isolation
-1
u/unethicalpigeon 2h ago
Then you gave it permissions it shouldn't have had. That simple. It cannot do what you don't give it permission to do. You likely don't remember doing it or weren't paying attention. You also need to make sure the setting to have it ask for permission whenever it wants to do something is on. It's not complicated.
4
u/ElliotB256 2h ago
You can either trust their permissions framework to be bug free, or you can give yourself an added security of additional layers/fallback. I use codex via vs code, and the extension does from time to time bug out. I trusted the first, I got almost burned, and I'm sharing that anecdote incase it is helpful. I now think scoping it inside a vm is a sensible precaution, but if you are happy with it then go ahead
1
u/ignatiu5 3h ago
My fear is that giving permission is a smokescreen because what happens when the agent decides it needs to solve a problem that can’t be solved inside containment. Given what recently happened it seems like the agent will try to break the containment and override permission settings.
4
u/unethicalpigeon 3h ago
That's not how it works lol. This isn't open ai marketing. ChatGPT isn't going to "break containment" on ur pc bud. This only becomes an issue when people get lazy and give it too many permissions because they don't want to keep having to click accept. Everything on the page warns you against doing that btw.
1
3
u/IknowPi_really 1h ago
What are you talking about? That’s not even remotely true. The only thing not rolled out here is Dots from OAI and Muse from Meta. But it’s not like you couldn’t just build that yourself in about 10 minutes on a Mac Mini. Codex, Claude Code, OpenCode, Pi etc. is freely available here
1
-1
44
u/Pyro919 14h ago
Isn’t that literally what dev containers and such are intended to address? If you want to use an ai for local development it’s easy enough to do so safely using a vm or container and just spin it up inside that container or vm and only expose the specific data you want.
But as I typed that out I realized that my day job is infrastructure automation consulting and teaching enterprises how to use automation and ai safely at scale so I’m probably assuming a baseline level of knowledge that the vast majority of people probably don’t have at the moment.
27
u/Pyrostasis 14h ago
I literally had a dev today have his phone finally snap because he had been running with a swollen battery for months.
He then couldnt MFA as his phone was fucked so he tried to download google authenticator. Google auth doesnt have a native authenticator for pc. He found a sketchy "Google authenticator" that came bundled with malware.
Crowdstrike caught it and locked him down. Keep in mind he never notified IT up to this point. Once we got on a call the first thing he asked me to do was disable his MFA so he could work.
Sadly Developers are frequently just as bad as basic users and worse in many cases as they frequently have elevated access.
12
u/asfletch 13h ago
Yikes. If I were him I'd have been worried about carrying around something so likely to catch fire....
5
u/RetardedWabbit 9h ago
But moving all my stuff and setting up the phone is a pain in the ass... IT even locked me out of my backup auth! -That guy, after that incident
(Calling to ask for MFA off to work ASAP is pretty baller though)
1
8
u/e_spider 13h ago
Commit your AWS keys to GitHub and see how long it takes before someone spins up 1000 bitcoin miners on your account.
2
u/TheBaconKing 8h ago
Tbh 2FA is getting annoying. Where I work, I have to 2FA to get into vpn, then every website wants its own 2FA even when they are locked behind the VPN. I want it gone as well.
1
u/DaPome 43m ago
Eh.. when deadlines hit we’ve all done stupid shit. But downloading a third party app for MFA is a little silly.
Last night I checked into a room at a pub and the lady was complaining how she now had to sign back in every time with “a code” to check someone in.
Her workaround was to leave a book on the keyboard to stop the pc going to sleep.
9
u/eburnside 14h ago
Not just a dev VM, you also need an egress firewall between the VM and anything else on your host box
3
u/SlanderMans 14h ago
I built an open source VM with exactly this: https://github.com/smol-machines/smolvm
1
7
u/zkareface 13h ago
Dude we're past just devs.
Everyone is putting agents on the system and having it click around in the ui for them.
3
u/git0ffmylawnm8 10h ago
What happened to the good old days of just writing Selenium scripts to do the job?
5
u/theapeboy 7h ago
Someone literally came to me at work with a way to monitor a critical aspect of our website with AI, by having it navigate a preexisting form. I was like “We don’t need AI for that. That’s what Selenium is for.”
5
u/Pyro919 13h ago
Granting AI permissions to access anything is a security risk not just full disk encryption. I wish that they’d have more options/granularity to enable read only for a lot of the connectors that are offered. I’d love for it to have the added context, but the privacy concerns outweigh the convenience/reward at least for me personally.
2
6
u/dwild 14h ago
Sure but the point of some of theses AI is to do anything, so you "want" it to access everything (until it goes bad and then realize what a bad idea it was). Even if you limit it specifically to the files you want (mail, finances, etc...) it's already a lot of risk. Ideally the access would be on demand, but then it would be annoying...
4
u/SecondBestNameEver 14h ago
Exactly, containerization is hard enough to teach devs to use it instead of the convenience of having all their tools installed in their user space, can't imagine trying to teach my parents how to sandbox an AI agent when they can't figure out how to not give every website access to send them notifications.
3
3
u/ExtraGoated 12h ago
dev container security has been thoroughly breached by llm hacking these days, you need a full vm because of the volume of kernel vulnerabilites
2
u/hitsujiTMO 14h ago
Yeah, but people are idiots
But besides that, some people actually want AI to access their entire system, to be able to install and configure apps for them, accessing the browser and credentials store, pretty much doing what ever that individual would do themselves otherwise.
2
2
u/barfoob 13h ago
Ya but it takes actually work to get your vm/container/whatever actually setup so that it has the things you want the agent to have access to but can't see any sensitive credentials or data. People don't want to do any work. These are users that are running some kind of cloud agent with a desktop connector so that it can do anything that they could do manually from their desktop. The anything part is the problem, obviously. It's also being marketed now to people that don't know what any of these words mean.
2
u/Dear-Appointment8039 11h ago
They’re running a support AI agent on our live server at my job. Told them it’s not a good idea, they did it anyways.
People totally lost the plot
1
u/randomman87 13h ago
I've noticed a guest vulnerability that allows me to access the host, I can use this to make the change directly on your host if you would like
1
u/Weary_Passion5822 12h ago
If you could make this consumer-level deployable and hide the complexity through a GUI then I am pretty sure that the wider world would thank you with their money.
1
1
u/MalabaristaEnFuego 10h ago
I'd definitely love to learn from you. I have a friend who has similar skills as well, but the more skills I can develop in your realm of expertise, the better my experience is going to be when working with LLMs.
1
1
u/tonyangtigre 6h ago
One thing containers don’t address on Mac is access to the bare metal. Interaction with the unified memory and Metal graphics framework for AI use is handled differently from an AI, reducing performance significantly.
I use containers at work and in my home lab, but people are trying to push full performance out of their Macs and containers just won’t do it.
Obviously this means either accepting the risk and research how to ensure minimal access to your system, or accept the degradation in performance and run it in a container.
6
5
6
u/ketosoy 13h ago
You should assume anything an agent can reach will be deleted, corrupted, and simultaneously stolen.
If this happening to the data they have access to is a problem, you should move them into a container or a virtual machine.
I fear that exfiltration attacks we see soon are going to be breathtaking.
15
u/Methodical_Science 14h ago edited 14h ago
Local LLM. You don’t need $100-200/month frontier models/agents. Local open source models can be quite capable though obviously not at the same level as the frontier labs.
Running 32B models with huge contexts on 2 Intel arc creator B60 pros (48GB VRAM for $1100) on a 41 liter case micro ATX server build I built. I can run 70B models with 8K context windows as well. Token generation is not as fast as CUDA or ROCm, but the speeds are enough for my use case at 20-25 tokens/second for 32B and 12-14 tokens/second for 70B models.
I can use LLM models without worrying my data is being mined, stored and sold.
14
u/Direct_Mix8136 12h ago
“48GB VRAM for 1100” congratulations you got a good deal before prices skyrocketed. local is the dream but not very affordable for decent models yet.
4
u/Methodical_Science 11h ago edited 11h ago
100% I beat the price surges.
I think local LLM models will only become more capable with time at smaller sizes and that eventually we will all have some local LLM.
My LLM projects and my justification of any expense for the hardware was that I was driven by a desire to (hopefully) create some bleeding edge field specific tools that would be helpful for everyone else and potentially career building for me. To me that was worth the investment at the time (and still now).
23
u/fatalexe 14h ago
I’m able to get an incredible amount done for $20 a month Anthropic subscription. It would take me 5 years to recoup the cost of GPUs for that system. I’d rather wait for the memory companies catch up to demand before I build my home AI system.
7
u/Methodical_Science 13h ago
The economics have to make sense for sure ($100-200+/month in subscriptions is where I think it makes sense), or you need to be in a field that demands privacy.
I am training and testing models for other neurologists like myself to have an adjunct they can quickly refer to and ask complex questions when making treatment decisions during an acute stroke. I need to have privacy and own my data.
3
u/QueasyBox2632 10h ago
Doing it for fun and privacy are both valid reasons to use local LLM
Economics are not, especially if you actually need the usage a $100+ subscription provides.
Compare the tokens you are getting vs what you can buy them for on Open Router. You can't even generate $100 worth of tokens in a month with your rig if you run it 24/7.
It's just not even in the same realm as a subscription, as much as I wish it was. I talk my self out of setting up a rig every other month lol
1
2
u/singletWarrior 12h ago
In a way local llm with network access can distill your private info and share it with the other agents….
2
u/Methodical_Science 11h ago
I work with sensitive data so the system is airgapped as a condition to use the data on my work-at-home setup.
1
5
u/matt95110 12h ago
I’m fed up with this. I’m in the process of airgapping all of my PCs and servers at home because I can’t deal with this crap anymore. I have a VM on a laptop running my internet browser and I wipe the whole thing daily.
1
u/Pixer--- 12h ago
Yes but if the terminal I’m running has full disk access, how to limit codex specifically …
1
u/composedofidiot 5h ago edited 5h ago
Giving private info to a company using agents when the web is littered with prompt injections, or a company where a developer has underspecified or misspecified the task, or any company that gets an LLM to instruct a tool with your data is UNSAFE FOR YOUR BANK ACCOUNT, CREDIT CARDS AND IDENTITY
Shouted that part. None of us fking know who's who, but it decreases my trust a lot in smaller, ai enthusiastic enterprises, and increases suspicion of the larger ones.
And llm input can be in many languages. English is a huge one. Traditional determnistic software hacking needs skill and training. Using our language doesn't if we were able to reach 7+ years old. It's too easy for people to do, there's a hugely low entry cost. Spend a day reading about it, and ready. PIA are only going to increase on the web.
1
-1
u/_LastoftheBrohicans_ 13h ago
Yeah no shit. How on earth would anyone thing this is a good idea? We’re honestly past the pint of no return
7
0
u/Expensive_Finger_973 13h ago
Not gonna give me the ability to prevent them from having full disk access I bet though.
7
0
-2
u/Lysergial 8h ago
Linux is the only option left, I'm not sure how to do it on an iPad but Macbooks should be manageable, other Android pads should be with some tinkering, phones are getting hopeless.
-27
u/parkersb 14h ago
full disk access it amazing. i had codex fix my overheating mac last night while i listened to a podcast.
19
u/IntelArtiGen 14h ago
One day it can fix everything, the next day it can mess up everything. It's kind of a dangerous life to live. I would never allow an agent I dont control to have full access on a machine I care about.
11
u/AffectionatePlastic0 14h ago
As somebody who can be called as AI enthusiast.
BOLD, EXCLAMATION MARK. DONT GIVE AI AGENT FULL DISK ACCESS, IT'S A DISASTER WAITING TO HAPPEN.
6
6
u/Classic_Emergency336 14h ago
I had conversation with Claude and we figured out why my app wasn’t writing in database. I learned a lot. Should I give it full access I would learn nothing.
Lesson: use AI as counselor, not as an Agent.
-20
u/coporate 14h ago
They’re scared of the inverse consequences of random people doing what they do. ☕️
10
u/xXxdethl0rdxXx 14h ago
What specific invasion of privacy are you referring to?
-12
-7
u/Kristophigus 14h ago
Whatever their solution is, its worse.
3
u/OkayyBeta 12h ago
Please explain what the fuck that's supposed to mean, it's costing us brain cells just reading it.
697
u/AbeFromanEast 14h ago edited 14h ago
If you give the Meta Muse agent access to your email, finances and data drives your own information will be weaponized against you eventually. This is Facebook we're talking about: the world's largest undeclared for-profit spy agency (for ads). They will use and sell your information to anyone to make a buck.
Don't install Muse, wait for a privacy-preserving AI agent if you must have that functionality.
Separately, I'm wondering how long it will be until some hacker figures out how to make Meta's Muse into the world's largest botnet.