I’d argue this is a five alarm fire for macOS and Meta simply exploited it.
Permissionless action is about to skyrocket as an issue, but this particular scenario strikes me as incredibly unlikely. Would be interested to know if Muse can provide more meaningful data provenance/logs.
Scanning iMessage dbs as a passive part of full disk access (and not a messages grant), if true, is a little sketchy, regardless.
This is absolutely untrue, and impossible.
I haven't spoken directly with Aten, but I have second-hand information from someone who has spoken directly with Aten, and it turns out that he has two Macs and may have allowed Full Disk Access to Muse on one of them.
ParanoidShroom•52m ago
daishi55•45m ago
ryandrake•42m ago
This used to work when you could trust the software you ran on your system to have access to everything you have access to on your computer. I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.
Best solution is to simply not run software made by blatantly untrustworthy developers. Second best solution would be to run such software as a severely sandboxed user who basically doesn't have access to anything important on your system.
graemep•31m ago
> I'd argue that time has largely passed, for most third-party commercial developers and even for some OS vendors.
Agreed, but what can you do about your OS vendor?
red_admiral•19m ago
brigade•6m ago
Muse is not available in the macOS app store. Almost certainly because of the sandboxing requirements.
anonymousDan•15m ago