Thus, I'm not sure what more Apple can do here, but I'm definitely afraid of what they're going to do.
In reality, the "full disk access" restriction system never actually worked right. I'm positive Apple is just trying to save face here and quietly fix it while saying they're "tighting" it
However, it feels like one to the User. Having to get constantly prompted to grant permissions they don't even necessarily understand to random programs.
There's been chatter about how system like iOS are not "document based", they're app based. Many apps do not present their data as "files", users don't know where their data resides, just that the app knows and that's their window.
I don't know where an application on MacOS can "save their files" if they don't have "Full Disk Access". I don't know if they get some directory "for free" that they can use much like iOS does.
Then, of course, there's the Apple Document model where data auto saves to Somewhere. You have versioned files you can work with. But until you actually "save" the file to "the disk", its living in some unannounced space. My TextEdit app has dozens of "Untitled-XX" files that are...somewhere.
And its great! There's a peace of just having "stacks of stuff" that you can leave "unmanaged". "Where would you like to save your work?" "Oh, great, cognitive load just exploded as need to think about the minutia of data organization, when, mostly I just "don't want to lose this".
But, the constant prompting is exhausting, to me. Again, I have to "think about it". I need to question everything, when I really just want to Get Stuff Done.
And, in time, we become blind to these prompts. "ok, Ok, OK!! GO ALREADY! JUST WORK!!".
Exhausting.
Huh? Seems like a disingenuous statement. I hope they update that sentence with something more accurate.
However, I've wanted much more granularity and pervasive permissions so I'm glad they're adding them.
Right, the classic use case for FDA is Terminal app, not backups. I don't think backup apps even need FDA, because they use the Apple ASR tool that already has special permissions.
The permissions/security model should've expanded faster. There's huge benefits to being able to install arbitrary software and not worry about giving it access to everything.
But it would never cover everything to do with a computer.
- Ghostty (fine, it's my terminal)
- Alfred (fine, I use it for searching everywhere)
Then I have a few turned off:
- Spotify (why does it need full disk access) ??
- Gemini (nope, don't need it to know everything about my computer)
Granting terminal full disk access grants arbitrary scripts full disk access. There’s a lot you can do with ACLs and the permissions system, but it’s not reflected in the UI for settings.
Then there’s allowing access to documents, downloads, desktop, external disks. This should really allow the user to select a path or paths for applications, because these options are way too broad (especially external disks).
You have to send the user to the system settings pane for it and have them manually toggle it on there.
It's hard to imagine how it could be more explicit than it is currently. I imagine they have something draconian planned.
I think so.
I don't know where this "ownership" debate came from. My ownership of my machine depends on strict, broad + fine grained control over what third-party devs (who are not me) get to do with my machine. Our interests are incompatible and hostile, in an era where most "native apps" ship analytics and marketing SDKs, or are videcoded. If macOS didn't offer these controls I would run every apps in a browser where it's sandboxed. This isn't the 90s.
This change is a reaction to a viral story from a tech reporter who shipped all his texts to Meta without meaning to, which tells you there's a consent and transparency issue for nontechnical users. I don't think anyone in the industry has figured out a proper solution. Unless you never interact with nontechnical people, it impacts your privacy indirectly no matter what you do. Though as technical user I hope we can get more fine-grained control and auditing.
For those who haven’t heard of this, sandboxed apps can request access to a file or folder and persist such access using a security-scoped bookmark. The user however does not know whether the app chooses to persist this bookmark or not; in other words the user does not know whether in each case they are granting a one-time access or persistent access.
There are already folder-specific permissions for every app, including non-sandboxed apps: Desktop, Documents, Downloads. FDA is "everything else". The user has to specifically grant each of those permissions via a system dialog.
With sandboxed apps, you grant access to a file outside the sandbox via a system dialog, open or save. But with non-sandboxed apps, if there were separate permissions for each specific folder, there would have to be separate permission dialogs for each of those folders, and then macOS would become even more of a permissions dialog hell than it already is.
Apple Intelligence is a great example of this. Everything can funnel up to Siri, but neither you nor any other app on your computer can see what is fed to it by all of the APIs that would provide it data. So anyone who adds support for it is enabling Apple to do their usual slow broken thing with Siri and not enabling any other way you might want to use software or AI with that data.
That feature was so stupidly nonfunctional before. Some apps got stopped by it, others didn't. Often you'd be able to install an app from homebrew and it had full ride access to the disk, while App Store apps had to request consent for any folder whatsoever. It was completely random.
But I think the "new world" is, we are over stimulated (eg. agents ask us 'permissions' for a long command) so we might give a sudo not fully aware of it where a big bold UX message box after a 'pseudo' sudo would better catch our eyes.
So it seems this is about adding additional layers over already existing ones in a way?
It has been extended, but not in a way that non-technical users can really use.
> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding.
If you think an app from (say) Facebook can be trusted with unrestricted access to your whole machine, you're at least a bit naive.
post_break•1h ago
steve-atx-7600•26m ago
jeremyjh•23m ago
cung•21m ago
etatester•21m ago