• Zak@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      4 days ago

      I read the article, and I think DickHertz’s comment is pretty much right. The article’s example illustrates the point:

      For example, Inc. columnist Jason Aten recently discovered that Meta’s Muse AI assistant somehow had synced his entire local Messages database and was using those messages as context for its tasks.

      Aten did not understand that the Messages database is stored on the disk (presumably) unencrypted and readable by anything with full disk access. He got a result he didn’t want because he did not understand the implications of granting that permission, and Apple seeks to add more friction to the process to protect users from making that mistake.

      • 4am@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        4 days ago

        Even if it was encrypted, it could be unlocked because with full disk access it can read the local private key, which probably doesn’t need a passphrase because it’s be a pain in the ass for the user to retype that every reboot or more

        Starting to see why you shouldn’t let any corporate AI loose on your daily driver yet?

        • Zak@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          3 days ago

          Macs have a hardware secure enclave that apps can use to store keys where other apps can’t access them. Apple itself does not seem to be making adequate use of it here.

    • DickHertz@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      4 days ago

      Yeah, I read it. That’s kind of the point. Apple’s adding more guardrails because people will click Allow on damn near anything without thinking about what they’re actually giving access to. 🙄