Apple and a hacker's future

Apple and a Hacker’s Future

苹果与黑客的未来

My computer got hacked, which is always embarrassing to admit, because it was my fault; the vulnerability that was exploited is detailed in this Ars Technica story: Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. 我的电脑被黑了,承认这一点总是很尴尬,因为这是我的错;被利用的漏洞在 Ars Technica 的这篇报道中有详细说明:荷兰官员警告称,一个允许攻击者执行恶意代码的高危 macOS 漏洞正处于活跃利用状态。

“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum warned earlier this week. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.” “荷兰国家网络安全中心(NCSC)收到通知显示,在多个互联网可访问 5900 端口的系统上,观察到了对该漏洞的活跃滥用,”该机构本周早些时候警告称。“在所有这些案例中,受影响系统的 root 权限已被获取,并被植入了门罗币挖矿程序。”

The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. 该漏洞被追踪为 CVE-2026-65400,苹果已于上周为 macOS Tahoe、Sequoia 和 Sonoma 发布了补丁。该漏洞严重性评分为 7.1 分(满分 10 分),源于 macOS 屏幕共享功能中的一个错误,该错误允许远程方在机器开机时查看屏幕并控制键盘和鼠标。

A flaw in the “state management,” which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause. A video of the exploit in action can be found here. Details of CVE-2026-65400 became public at last week’s Black Hat security conference. “状态管理”(负责跟踪先前事件、用户交互、变量和其他系统状态)中的缺陷是根本原因。漏洞利用过程的视频可以在这里找到。CVE-2026-65400 的详细信息是在上周的 Black Hat 安全会议上公开的。

Apple said last week that CVE-2026-65400 “may” allow an attacker without credentials to gain access to a Mac. It’s unclear why Apple hedged, but softening language is common among most tech developers when disclosing vulnerabilities. Apple credited security firm Bynario for reporting the vulnerability. 苹果上周表示,CVE-2026-65400 “可能”允许没有凭据的攻击者访问 Mac。目前尚不清楚苹果为何措辞谨慎,但在披露漏洞时,大多数科技开发者使用缓和的语言是很常见的。苹果将该漏洞的报告归功于安全公司 Bynario。

The computer in question was my always-on Mac Mini that runs nothing but Claude and Codex; the first thing that makes this story interesting is that that was my saving grace. 出问题的电脑是我那台全天候运行的 Mac Mini,它除了运行 Claude 和 Codex 之外什么都不做;这个故事有趣的第一点在于,这恰恰成了我的救命稻草。

Agent Protection

智能体保护

I have discussed, in both Writing Things Down and in several episodes of Sharp Tech, Gecko, the agent that I have built for the people that work with me. It’s awesome, but purposely constrained in capability and in what it can access. My real agent is a dedicated Claude Code thread that writes down all of my ideas and tracks the status of the myriad of projects I’ve spun up over the last few months. 我曾在《Writing Things Down》以及《Sharp Tech》的几期节目中讨论过 Gecko,这是我为与我共事的人构建的智能体。它很棒,但在能力和访问权限上被刻意限制了。我真正的智能体是一个专门的 Claude Code 线程,它记录了我所有的想法,并跟踪我在过去几个月里启动的无数项目的状态。

There are a few reasons why I use Claude for this functionality, even though I’m not a big fan of Claude-speak: Claude in its Code harness seems to handle wide-ranging discussions better than Codex, and it follows my instructions about writing things down in the way I want to more gracefully. 我使用 Claude 来实现此功能有几个原因,尽管我不太喜欢 Claude 的说话方式:Claude 在其 Code 框架下似乎比 Codex 能更好地处理广泛的讨论,并且它能更优雅地按照我想要的方式执行关于记录事项的指令。

Code also has a persistent monitoring tool that I utilize as an inbox to capture interactions with a status board I built to visually track everything I have written down, as well as interactions with a Telegram bot (OpenAI’s new Dots achieve some of this functionality, which has been sorely needed in ChatGPT/Codex). Code 还有一个持久监控工具,我将其用作收件箱,以捕获与我构建的状态看板之间的交互,从而直观地跟踪我写下的所有内容,以及与 Telegram 机器人的交互(OpenAI 新推出的 Dots 实现了一些此类功能,这在 ChatGPT/Codex 中一直是非常迫切需要的)。

Said monitoring tool stands down every 30 minutes, so my agent restarts it on a schedule; that is what triggered an URGENT notification from Claude: Claude had more diagnostic information, unilaterally stopped executing all commands, and noted that my account could now run admin commands without a password, which it assumed was how the files were written; it then had a number of suggested next steps to address the problem. 上述监控工具每 30 分钟会停止一次,因此我的智能体会按计划重启它;正是这一点触发了 Claude 发出的“紧急”通知:Claude 拥有更多的诊断信息,单方面停止执行所有命令,并指出我的账户现在可以在没有密码的情况下运行管理命令,它推测文件就是这样被写入的;随后它提出了一些解决问题的后续步骤建议。

The one I ignored was its recommendation that I not invoke Claude anymore; in fact, I used Claude to root out the malware — we eventually found the exact four second period where it gained access — create a tool to watch for it in the future, and then wiped the Mac Mini. All of this happened before I found the Ars Technica article detailing the vulnerability, and it was pretty remarkable. 我忽略的一条建议是它建议我不要再调用 Claude;事实上,我利用 Claude 清除了恶意软件——我们最终找到了它获取访问权限的那精确的四秒钟——创建了一个用于未来监控的工具,然后抹除了这台 Mac Mini。所有这一切都发生在我发现 Ars Technica 关于该漏洞的详细报道之前,这非常了不起。

I understand that people are nervous about giving these agents access to one’s computer — as I noted, the Mac Mini in question has nothing on it except for Codex and Claude — but in this case you could make the case that I would have been in much more trouble had I not had an agent running persistently. 我理解人们对于授予这些智能体电脑访问权限感到紧张——正如我所提到的,那台 Mac Mini 上除了 Codex 和 Claude 之外什么都没有——但在这种情况下,你可以认为,如果我没有一个持续运行的智能体,我可能会陷入更大的麻烦。

Apple Protection

苹果保护

Apple doesn’t seem too happy about agents; last week the company’s developer site released a note entitled Updates to Full Disk Access in macOS; I’m going to quote it in full: 苹果似乎对智能体不太满意;上周,该公司的开发者网站发布了一篇题为《macOS 中全盘访问权限的更新》的说明;我将全文引用:

“We give developers powerful APIs to build incredible capabilities into their apps for Apple products, backed by a set of controls designed to protect users’ private data. Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac. Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.” “我们为开发者提供强大的 API,以便为苹果产品构建令人难以置信的功能,并辅以旨在保护用户隐私数据的一系列控制措施。全盘访问权限在很大程度上绕过了这些控制,以允许备份应用程序在 Mac 上正常运行。一些开发者正在以可能使用户面临风险的方式使用全盘访问权限,在用户不知情和不完全理解的情况下,暴露其系统上的所有内容——包括文件、邮件、信息,甚至浏览历史记录。对于通信应用程序,这还可能危及用户正在与之通信的人的隐私。”

“Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.” “展望未来,我们将引入额外的控制措施,以确保那些真正希望授予应用程序这种超高级别访问权限的用户,只能通过非常明确的用户操作来实现。解决这个问题至关重要。随着人工智能智能体变得越来越强大和自主,与这种访问级别相关的风险将大幅增加。我们致力于确保用户在授予此类访问权限之前清楚地了解这些风险,以便他们能够就自己的数据和隐私做出明智的决定。”

To say that I’m nervous about what Apple’s solution will entail is a massive understatement. There is one aspect in which the Mac is the perfect agent host: Apple has, for decades, invested in a combination of scriptability, automation, and accessibility APIs (these are very often the same thing) that makes it remarkably well-suited to computer use. 说我对苹果的解决方案将带来什么感到紧张,这简直是轻描淡写。Mac 在一个方面是完美的智能体宿主:几十年来,苹果在脚本化、自动化和辅助功能 API(这些通常是同一回事)的结合上进行了投资,这使得它非常适合计算机使用。

Then there is the fact that macOS is a certified Unix system; this means that agents — which are perfectly suited to the command line — have access to the entire universe of tooling built for Unix systems. And, of course, Mac hardware is amazing. The problem is 此外,macOS 是一个经过认证的 Unix 系统;这意味着智能体——它们非常适合命令行——可以访问为 Unix 系统构建的整个工具宇宙。当然,Mac 硬件也很棒。问题在于……