frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Apple Pass Designer

https://developer.apple.com/pass-designer/
182•soheilpro•1h ago•108 comments

Court agrees with EFF: Utah's VPN law demands a technical impossibility

https://www.eff.org/deeplinks/2026/10/court-agrees-eff-utahs-vpn-law-demands-technical-impossibility
361•hn_acker•22h ago•157 comments

A 12-year sequence of telescope images of a star and four planets orbiting

https://bsky.app/profile/theplanetaryguy.com/post/3mwucf5ert22f
89•mariuz•9h ago•17 comments

Greg Kroah-Hartman – Security in the LLM Age [video]

https://www.youtube.com/watch?v=NnV_cWeoo5Q
108•usernomdeguerre•18h ago•19 comments

From the creator of Redis; run LLM locally with ds4

https://dwarfstar.sh/
63•fibo•2h ago•5 comments

With most information hidden, the game Stratego had stumped AI until now

https://arstechnica.com/science/2026/10/ai-finally-beat-the-best-stratego-player-in-history-and-d...
96•PaulHoule•6h ago•29 comments

Loss of cell identity drives human aging: Two new papers

https://erictopol.substack.com/p/loss-of-cell-identity-drives-human
99•bookofjoe•1d ago•24 comments

Show HN: Made an open-source Lego AI generator

https://github.com/anteloc/ldraw-nova
24•antelocnova•1h ago•10 comments

Mike Tomlin spent 12 years building a Minecraft city

https://www.nytimes.com/athletic/7648198/2026/10/01/mike-tomlin-minecraft-nfl-coach/
108•CoryOndrejka•1d ago•27 comments

One month coding with GLM 5.3 Flash

https://wagtail.org/blog/one-month-on-glm-53-flash/
59•ThibWeb•5h ago•36 comments

Venice’s failed war against Constantinople led to the first bond market

https://bigthink.com/books/a-fabulous-debt/
41•RickJWagner•7h ago•8 comments

Muse Gadgets

https://gadgets.muse.ai
23•anant•1h ago•15 comments

Sites in ChatGPT

https://chatgpt.com/features/sites/
143•polvi•22h ago•168 comments

Blogging with Gleam, Org-Mode and Pandoc

https://byzantine-systems.github.io/blogging-with-gleam-org-mode-and-pandoc/
30•schonfinkel•9h ago•5 comments

The Legend of von Neumann (1973) [pdf]

https://gwern.net/doc/math/1973-halmos.pdf
217•suopspaces•7h ago•123 comments

FLUX 3 Image

https://bfl.ai/models/flux-3-image
218•minimaxir•1d ago•52 comments

Anatomy of a Lean proof for software engineers

https://agostbiro.net/posts/2026-10-anatomy-of-a-lean-proof/
39•abiro•1d ago•0 comments

STS-51-F Abort-to-Orbit (1985)

https://en.wikipedia.org/wiki/STS-51-F
18•schoen•4h ago•5 comments

GrapheneOS has fixed the Android 17 QPR1 kernel performance regression

https://discuss.grapheneos.org/d/42511-grapheneos-has-fixed-the-massive-android-17-qpr1-kernel-pe...
56•Cider9986•1h ago•12 comments

The first packet sent via RFC1149 avian carrier is up for auction at Christie's

https://onlineonly.christies.com/s/fine-printed-books-manuscripts-science/carrier-pigeon-internet...
20•peter_hansteen•8h ago•1 comments

Our Project Suncatcher prototype satellite is in orbit

https://blog.google/innovation-and-ai/models-and-research/google-research/project-suncatcher-prot...
30•pantalaimon•9h ago•30 comments

How accurately calibrated is Jev?

https://maximumeffort.substack.com/p/jev-is-poorly-calibrated
35•dblack12705•5h ago•11 comments

Show HN: Giving Opus 5.5 a simulated paint canvas

https://stillwet.art/
155•alstonite•20h ago•53 comments

F.02 Decommission

https://www.figure.ai/news/f-02-decommission
34•ad_hockey•10h ago•8 comments

Show HN: Pyxel – A Python retro game engine with built-in art and sound editors

https://github.com/kitao/pyxel
37•kitao•21h ago•4 comments

On social reality in China

https://www.lesswrong.com/posts/b5cSYh4emQb2qrGmK/on-social-reality-in-china
80•thicTurtlLverXX•9h ago•77 comments

What if we stopped using GPUs? [video]

https://www.youtube.com/watch?v=xc2FTBGRSJo
20•sandslash•2h ago•4 comments

"The only intuitive interface is the nipple" (2012)

https://www.greenend.org.uk/rjk/misc/nipple.html
19•ibobev•1h ago•21 comments

Three AI agents, two countries, and one uneven world wide web

https://royapakzad.substack.com/p/multilingual-ai-agents
6•effects•21m ago•0 comments

100 years of student radio history in the DLARC college radio collections

https://blog.archive.org/2026/10/02/100-years-of-student-radio-history-in-the-dlarc-college-radio...
18•HieronymusBosch•8h ago•4 comments
Open in hackernews

Updates to Full Disk Access in macOS

https://developer.apple.com/news/?id=p6zjojqw
64•notfirstpost•1h ago

Comments

post_break•1h ago
One update away to revoking Full Disk Access in the future. This commercial has come full circle: https://www.youtube.com/watch?v=VuqZ8AqmLPY
steve-atx-7600•26m ago
Need some Vaseline for your slope?
jeremyjh•23m ago
You could say that about anything, in any OS. Windows is one update away from insulting the user whenever they login. MacOS is one update away from mining crypto for Apple. Android is one update away from sending spam to all your contacts.
cung•21m ago
Hah! I had forgotten this ad. Using a mac nowadays is definitely just like Windows Vista in this ad.
etatester•21m ago
Please do. Too many applications have too much access. Why do people not realize they installed literal Trojan horses that visit websites and execute commands found on them (prompt injection)?
lapcat•1h ago
My understanding is that Meta Muse simply opens the System Settings Full Disk Access pane, and the user has to enable it themselves using System Settings, which says, "Allow the applications below to access data like Mail, Messages, Safari..." and which requires an administrator password to change.

Thus, I'm not sure what more Apple can do here, but I'm definitely afraid of what they're going to do.

708733454927516•29m ago
"I have a bad feeling about this..."
VCFundedGenYer•13m ago
No, that's not what happened.

In reality, the "full disk access" restriction system never actually worked right. I'm positive Apple is just trying to save face here and quietly fix it while saying they're "tighting" it

lapcat•9m ago
This is a baseless conspiracy theory. Provide proof. No, the confused ramblings of one journalist who is trying to save his own face for granting FDA to Muse does not count as proof.
jameskraus•55m ago
Oh no, even more permission prompts on macOS. It's already almost unusable due to the existing ones.
whartung•26m ago
Folks like to cite how capability OSes are a great thing, and I certainly appreciate the concept, and, no, MacOS, is not a capability OS.

However, it feels like one to the User. Having to get constantly prompted to grant permissions they don't even necessarily understand to random programs.

There's been chatter about how system like iOS are not "document based", they're app based. Many apps do not present their data as "files", users don't know where their data resides, just that the app knows and that's their window.

I don't know where an application on MacOS can "save their files" if they don't have "Full Disk Access". I don't know if they get some directory "for free" that they can use much like iOS does.

Then, of course, there's the Apple Document model where data auto saves to Somewhere. You have versioned files you can work with. But until you actually "save" the file to "the disk", its living in some unannounced space. My TextEdit app has dozens of "Untitled-XX" files that are...somewhere.

And its great! There's a peace of just having "stacks of stuff" that you can leave "unmanaged". "Where would you like to save your work?" "Oh, great, cognitive load just exploded as need to think about the minutia of data organization, when, mostly I just "don't want to lose this".

But, the constant prompting is exhausting, to me. Again, I have to "think about it". I need to question everything, when I really just want to Get Stuff Done.

And, in time, we become blind to these prompts. "ok, Ok, OK!! GO ALREADY! JUST WORK!!".

Exhausting.

VCFundedGenYer•19m ago
It's really gotten out of hand. Trying to literally plug something in results in at least one (sometimes multiple) prompts being like "are you SUUUUURE you want this plugged in?"
big_toast•54m ago
"Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac"

Huh? Seems like a disingenuous statement. I hope they update that sentence with something more accurate.

However, I've wanted much more granularity and pervasive permissions so I'm glad they're adding them.

lapcat•42m ago
> Huh? Seems like a disingenuous statement. I hope they update that sentence with something more accurate.

Right, the classic use case for FDA is Terminal app, not backups. I don't think backup apps even need FDA, because they use the Apple ASR tool that already has special permissions.

big_toast•23m ago
Even developing bog standard apps. MacOS without FDA is the death of creativity and productivity.

The permissions/security model should've expanded faster. There's huge benefits to being able to install arbitrary software and not worry about giving it access to everything.

But it would never cover everything to do with a computer.

mcmcmc•15m ago
EDR and RMM are two major ones for corporate managed Macs
rwz•51m ago
When I give something a "Full Disk Access" permission, I expect it to have full access to what's on my disk, including "files, mail, messages, and even (gasp) browsing history"! Who are those mysterious people who expect their browsing history to be magically excluded from something called Full fucking Disk Access?
bix6•43m ago
Most people don’t know what a disk is.
swiftcoder•21m ago
The problem isn't people who intend to provide full disk access. It's the people who unthinkingly grant full disk access to, for instance, Codex, because the AI asked them to.
moecables•46m ago
IMHO, it's good to add more specific controls for this. After reading this, I went and checked my list of app with full disk access:

- Ghostty (fine, it's my terminal)

- Alfred (fine, I use it for searching everywhere)

Then I have a few turned off:

- Spotify (why does it need full disk access) ??

- Gemini (nope, don't need it to know everything about my computer)

coderbants•14m ago
Terminal is a significant risk though and I’d still really like to see macOS improve the APIs around filesystem access.

Granting terminal full disk access grants arbitrary scripts full disk access. There’s a lot you can do with ACLs and the permissions system, but it’s not reflected in the UI for settings.

Then there’s allowing access to documents, downloads, desktop, external disks. This should really allow the user to select a path or paths for applications, because these options are way too broad (especially external disks).

jonathanstrange•44m ago
If there is one thing I absolutely despise with all of my heart, then it's mega corporations patronizing their paying customers.
techscruggs•44m ago
Everyday, we get one step closer to the year of the Linux desktop.
etatester•16m ago
Any day now
Kim_Bruning•41m ago
Am I getting old? "full disk access" used to be something that's supposed to be normal; if you're the owner of the machine.
smith7018•36m ago
I'm sure it'll be a permission the user can toggle. So they won't be taking away the ability for apps to see all the files but they'll be adding an extra layer of security so users can choose what an app can see. They're being light on details at the moment though.
tekacs•29m ago
But this is what it is currently. At the moment, not only is it a toggle, but unlike almost all other permissions, you can't just request the permission.

You have to send the user to the system settings pane for it and have them manually toggle it on there.

It's hard to imagine how it could be more explicit than it is currently. I imagine they have something draconian planned.

pjmlp•35m ago
Only on systems without proper user management, or if the owner is logged in as the administrator.
concinds•31m ago
> Am I getting old?

I think so.

I don't know where this "ownership" debate came from. My ownership of my machine depends on strict, broad + fine grained control over what third-party devs (who are not me) get to do with my machine. Our interests are incompatible and hostile, in an era where most "native apps" ship analytics and marketing SDKs, or are videcoded. If macOS didn't offer these controls I would run every apps in a browser where it's sandboxed. This isn't the 90s.

This change is a reaction to a viral story from a tech reporter who shipped all his texts to Meta without meaning to, which tells you there's a consent and transparency issue for nontechnical users. I don't think anyone in the industry has figured out a proper solution. Unless you never interact with nontechnical people, it impacts your privacy indirectly no matter what you do. Though as technical user I hope we can get more fine-grained control and auditing.

mrkpdl•36m ago
I would like the ability to see which specific folders I have granted access to on an app by app basis. And edit. It’s not clear to me how you revoke an app’s individual folder access after you have granted it.
kccqzy•33m ago
I have been wanting this for years.

For those who haven’t heard of this, sandboxed apps can request access to a file or folder and persist such access using a security-scoped bookmark. The user however does not know whether the app chooses to persist this bookmark or not; in other words the user does not know whether in each case they are granting a one-time access or persistent access.

lapcat•24m ago
This is unrelated to Full Disk Access, though.

There are already folder-specific permissions for every app, including non-sandboxed apps: Desktop, Documents, Downloads. FDA is "everything else". The user has to specifically grant each of those permissions via a system dialog.

With sandboxed apps, you grant access to a file outside the sandbox via a system dialog, open or save. But with non-sandboxed apps, if there were separate permissions for each specific folder, there would have to be separate permission dialogs for each of those folders, and then macOS would become even more of a permissions dialog hell than it already is.

pkulak•33m ago
I feel like this isn't going to be a simple permission popup. Probably along the lines of getting an "unapproved" binary to run, where you have to stop what you're doing and wade through settings, trying to find the right toggle 6 nodes deep in the tree.
busymom0•19m ago
I am a developer and recently I was troubleshooting an issue with my macOS app where it was working fine on newer macOS but failing on older one only when I archived it (last step before submitting an app for Apple approval). So I'd archive it on my new macOS and airdrop to old macOS and try to run it. Every single time, it'd tell me it was unsafe and ask me whether I'd like to delete it. I'd have to dig through multiple settings screens to "open anyway", enter my password to get it to finally run. What a nightmare not being able to easily run my own app despite having same developer account and Apple ID.
tekacs•31m ago
Apple, as always, seem extremely determined to make sure that they protect things on your computer from being accessed by you.

Apple Intelligence is a great example of this. Everything can funnel up to Siri, but neither you nor any other app on your computer can see what is fed to it by all of the APIs that would provide it data. So anyone who adds support for it is enabling Apple to do their usual slow broken thing with Siri and not enabling any other way you might want to use software or AI with that data.

tapvt•31m ago
I dislike restrictions out of instinct, but to be fair, I've had permissions request popups on my Mac that were the first sign of software, which I had actually written, maybe had some bugs allowing it to work outside of its intended bailiwick.
VCFundedGenYer•25m ago
If it worked as intended, they wouldn't be in this predicament.

That feature was so stupidly nonfunctional before. Some apps got stopped by it, others didn't. Often you'd be able to install an app from homebrew and it had full ride access to the disk, while App Store apps had to request consent for any folder whatsoever. It was completely random.

etatester•22m ago
What we need is true application isolation even in the command line. Treat Terminal as privileged access, not something any app can just command. Sandbox non-app store apps as well.
JakaJancar•11m ago
Just use an iPad?
russellbeattie•1m ago
[delayed]
VCFundedGenYer•23m ago
macOS has been revoking access to stuff like this over the past decade. Things like unfettered access to modifying the OS went away with Gatekeeper and System Integrity Protection. "root" access is no longer true root on any Mac, and the user is treated like a prisoner. The UAC-esque prompts that come up in macOS would make Vista-era MS so jealous.
littlecranky67•16m ago
root access is also no longer true root access on a lot of linux distros that are immutable, and container-esque like interfaces such as namespaces + cgroups also limit roots power.
rock_artist•20m ago
being a nerd here, sudo - yes, but indeed I thought the entire UNIX design of everything is files and there are permissions, groups, etc, should be sufficient.

But I think the "new world" is, we are over stimulated (eg. agents ask us 'permissions' for a long command) so we might give a sudo not fully aware of it where a big bold UX message box after a 'pseudo' sudo would better catch our eyes.

So it seems this is about adding additional layers over already existing ones in a way?

lokar•11m ago
The UNIX model assumed each human had one user. It did not provide a flexible way to sub-divide that scope for each program running as that user.

It has been extended, but not in a way that non-technical users can really use.

jeremyjh•19m ago
I’m 50 and I think it’s crazy we ever thought it was acceptable to give every app you run full access to all the files on your computer by default.
etatester•18m ago
This isn't 1980 anymore. The internet is super hostile and everyone wants to extract data. You're still free to allow every app on your computer full access, I won't. I am very glad that none of the hundreds of apps installed across my phone and Mac can access my photos and cameras without permission.
GeekyBear•17m ago
TFA:

> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding.

If you think an app from (say) Facebook can be trusted with unrestricted access to your whole machine, you're at least a bit naive.

fragmede•16m ago
And despite hyperbole about Apple locking down macOS, ending the era of personal computing, it's hidden behind a toggle in settings. https://www.xkcd.com/1200/ applies, and in the era of downloading random programs off the Internet and cryptocurrency, random programs should have to jump through an extra hoop before getting access to everything. Imo Apple went a bit overboard with granularity, but it's not 1990 and the Windows 98 (lack of) security model doesn't work, and neither does Unix permissions either.