Apple changes full-disk access permissions to curb abuse from AI agents

Apple changes full-disk access permissions to curb abuse from AI agents

苹果更改“全盘访问”权限,以遏制人工智能代理的滥用行为

Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories. Friday’s announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. 苹果公司表示,正在更改其 macOS 隐私设置,以防止第三方应用开发者滥用权限访问用户的消息记录。在上周五发布此公告的两周前,科技专栏作家 Jason Aten 曾表示,Meta 推出的新型通用人工智能代理 Muse 向他发送了一条未经请求的通知,其中引用了他与同事在 Apple Messages(苹果信息)中的对话内容。

Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully. Aten 表示,他从未授予 Muse 读取其消息的权限,并一直认为这些内容是受保护的。上周,社交媒体上引发了广泛讨论,许多人对此表示认同,并指出这一事件表明,当人工智能助手被授予访问日历、电子邮件、消息、购物账户及其他资源的权限时,它们就像圆锯或其他电动工具一样——虽然可能很有用,但如果使用不当,可能会造成严重的损害。

He said/she said: Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges. One is full-disk access, a macOS system-level permission. The other is to enable a Messages connector setting in Muse. “The Messages integration in the Muse Mac app is opt in,” Singleton said. “Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.” 各执一词:Meta 首席技术官 David Singleton 加入了这场争论,并给出了看似有力的反驳。他表示,Muse 若要访问 Apple Messages,用户必须手动授予其两项权限:一是 macOS 系统级的“全盘访问”(Full Disk Access)权限,二是启用 Muse 中的“消息连接器”(Messages connector)设置。“Muse Mac 应用中的消息集成是可选的,”Singleton 说道,“只有在授予 macOS 系统级全盘访问权限并启用消息连接器的情况下,你的 Muse 才能读取消息内容。”

Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame. Earlier this week, I spoke to macOS security expert Patrick Wardle, who questioned Singleton’s denial. His reasoning: “From a technical point of view, with FDA (full-disk access), any (non-root file), is readable, browsing history, browser cookies, chats, etc etc etc.” Singleton 的暗示很明确:Muse 只有在 Aten 同时开启了这两项设置的情况下才能读取他的消息。如果是这样,那么这位专栏作家只能怪自己,而绝非 Meta 的责任。本周早些时候,我采访了 macOS 安全专家 Patrick Wardle,他对 Singleton 的否认提出了质疑。他的理由是:“从技术角度来看,拥有全盘访问权限(FDA)后,任何非根目录文件都是可读的,包括浏览历史记录、浏览器 Cookie、聊天记录等等。”

I asked Meta how Muse couldn’t read messages when the app had full disk access, while every other app with that privilege could. Meta PR’s only response was to requote Singleton saying: “The Messages integration in the Muse Mac App is opt-in. Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.” 我询问 Meta,既然 Muse 拥有全盘访问权限,为什么它不能读取消息,而其他拥有该权限的应用却可以。Meta 公关部门的唯一回应是重复了 Singleton 的话:“Muse Mac 应用中的消息集成是可选的。只有在授予 macOS 系统级全盘访问权限并启用消息连接器的情况下,你的 Muse 才能读取消息内容。”

Now, Apple is setting the record straight. In explaining why it was going to make changes to the FDA permission setting, the company wrote: Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with. 现在,苹果公司正在澄清事实。在解释为何要更改全盘访问权限设置时,该公司写道:一些开发者正在以可能使用户面临风险的方式使用“全盘访问”权限,在用户不知情或不完全理解的情况下,暴露其系统中的所有内容——包括文件、邮件、消息,甚至浏览历史记录。对于通信类应用而言,这还可能危及用户通信对象的隐私。

The statement went on: As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy. 声明继续写道:随着人工智能代理变得越来越强大和自主,与此类访问权限相关的风险将大幅增加。我们致力于确保用户在授予此类访问权限之前清楚地了解这些风险,以便他们能够就自己的数据和隐私做出明智的决定。

Apple didn’t name Meta, Muse, or any other app or developer by name. Even though there are no known reports of other apps abusing FDA to read messages and browsing history, it’s certainly possible Friday’s statement wasn’t referring to the Muse incident. Then again, the timing of the announcement—coming on the heels of a major social media uproar—makes the possibility likely. And at a minimum, Apple’s statements seem to contradict Singleton’s denial that it’s not possible for Muse to read Messages content without the connector enabled. Meta PR didn’t respond to questions sent Friday. 苹果没有点名 Meta、Muse 或任何其他应用或开发者。尽管目前尚无其他应用滥用全盘访问权限来读取消息和浏览历史的报道,但周五的声明确实有可能并非专门针对 Muse 事件。不过,该公告发布的时间点——紧随社交媒体上的轩然大波之后——使得这种可能性很大。至少,苹果的声明似乎反驳了 Singleton 关于“若未启用连接器,Muse 就不可能读取消息内容”的否认。Meta 公关部门未回应周五发送的置评请求。

Apple’s announcement came 11 days after Wardle disclosed a Muse configuration that allowed any app or code running on a Mac—including commands injected through the increasingly effective ClickFix attacks—to take full control of the AI assistant. From there, the attacker could access the same resources Muse could. It also comes after Amazon blocked Muse from its platform because, Amazon said, all such apps “should operate openly and respect service provider decisions about whether or not to participate.” 苹果的公告是在 Wardle 披露 Muse 的一种配置 11 天后发布的。该配置允许在 Mac 上运行的任何应用或代码(包括通过日益有效的 ClickFix 攻击注入的命令)完全控制该人工智能助手。攻击者由此可以访问 Muse 所能访问的所有资源。此外,在此之前,亚马逊也封禁了 Muse,理由是所有此类应用“都应公开运作,并尊重服务提供商关于是否参与的决定”。

Taken together, the events suggest that Muse may not be worthy of the extraordinary access it must have to work as billed by Meta. People who use the assistant should configure permissions carefully, though as Aten’s experience suggests, that precaution only goes so far. 综上所述,这些事件表明,Muse 可能并不值得拥有其正常运行所需的那些特殊权限。使用该助手的人应谨慎配置权限,尽管正如 Aten 的经历所表明的那样,这种预防措施的作用也是有限的。