Forgot your password?
typodupeerror

Comment Re:Correct. And oh, no. (Score 1) 51

It's not. Full disk access is sticky. When you grant it, the app has it until you go into settings and revoke it.

You're interpreting it in the context of typing "sudo" on the command-line granting a one-time permission. And the original statement from Apple (after correcting the "every -> very" error in the summary) makes it clear that this is *not* what is being proposed, so if that was the original poster's intent, then it was incorrect.

The way I interpreted the original sentence — "They're going to make it like sudo where when you give permission to a program to write protected files once it has it forever after" — is that they're going to make it like the sudoers file, where you edit it to grant permission to a program to do something, and it permanently has the right to do that... which is exactly what happens when you grant full disk permission, just with a dialog box instead of editing a file.

That said, I'm not sure if that's how the original statement was intended to be interpreted. It was a bit confusing. :-)

Comment Re:Groundwork for censorship (Score 1) 103

Some would argue that censoring spam is bad due to free speech, once again, fuck your free speech as I don't want to associate with spammers. Security of body, should we put up with speech preaching violence?

Nope. And this is why I object to the phrase "censorship is bad". *Unreasonable* censorship is bad. But not all restraint on speech is bad.

Comment Re:Groundwork for censorship (Score 1) 103

Censorship is a problem when you are not free to express an idea.

The form of the idea can be limited without it being censorship: for example, you can't protest with a bullhorn in the middle of the night.

No, you're confusing the definition of censorship with what restraints on free speech are constitutional. You're defining the term based on legality in a specific jurisdiction. If you applied the same standard with a different jurisdiction — say what can legally be spoken in Iran — you would get a very different definition. This is why you cannot define censorship based on a specific legal standard. It must be defined in the abstract.

The general definition is that censorship is the suppression of expression by an authority. That expression could be a constitutionally protected idea, or it could be an advertisement for Taco Bell. It's still expression, and blocking it is still censorship.

Free speech doesn't mean everyone has to listen to you, it means the people who want to listen to you are able to. Youtube demonetizing a video is not censorship. Removing videos because they don't like the ideas in the videos is the worst kind of censorship, because they are trying to control you.

And again, you're using the U.S. definition of free speech to define censorship. These things are not synonymous. Nobody is talking about whether someone should have to listen to you. The fact that someone shut you up is still censorship. It may be *constitutionally allowable* censorship. It may even be *entirely* *reasonable* censorship. But it is still censorship.

Not all censorship is bad. Restraints on speech based on time, place, and manner restrictions can be entirely reasonable. They are still, at least in a purely abstract way, a form of censorship. Restraints on speech where your speech costs someone else money can also be entirely reasonable (e.g. spam, robodialers, etc.). But those decisions still represent censorship in the abstract. We simply choose to say that those types of restraints on speech are reasonable and necessary for a functioning society.

It's all about balancing rights — your right to swing your fist ends when it meets my nose, and all that. Censorship is generally justifiable when exercising your right to speech has the effect of violating someone else's rights. For example, if you call for violence and that violence happens, you can get thrown in jail, and your rights to free speech can be massively curtailed. This is, however, still censorship in a purely abstract sense.

Submission + - Pneumonic plague outbreak hits Siberia as lab worker, 28, dies (hotair.com)

schwit1 writes: A suspected plague outbreak has erupted in Russia — killing a young lab worker, forcing nearly 200 people into isolation and triggering accusations that Vladimir Putin’s regime is trying to keep the infection’s possible spread under wraps.

The alarm was raised in Siberia after a worker at an anti-plague laboratory died of the disease, which killed tens of millions in the medieval Black Death, according to a report from The Moscow Times.

Anna Popova, who heads Russia’s public-health watchdog, then rushed 2,600 miles from Moscow to the Irkutsk region as authorities quarantined a hospital and placed scores of people who had come into contact with the victim under medical observation.

"FSB units accompanying ambulances transporting people who had been in contact with [lab tech] Shipilova for medical examination," as per local news. This is significant. FSB is Russia's domestic security / counterintelligence service, tasked w/implementing the national security of Russia." (Its predecessor was the KGB). This suggests quarantine was not voluntary.

It also means Russian authorities are treating the lab accident and plague outbreak as a national security issue, involving a lot more than routine public health.

https://x.com/AnnieJacobsen/st...

Comment Re:I'll take $10K (Score 1) 124

FUD means fear, uncertainty, doubt. When Microsoft told people that Linux may have a license problem and that the viral GPL is cancer, that was FUD. They wanted people to hesitate to switch to Linux, not because they knew it would be a problem, but because they didn't want to risk the possibility of it being or becoming a problem for them.

Currently people are spreading rumors how bad data centers were, who never have seen one from close. In particular Youtubers seem to be happy to explain people they were evil, using arguments that would imply that a lot of people living near an existing one already suffered the bad consequences.

There are surely details that can and should be discussed. How near is the next apartment? How is the electricity supply? But there are other things that will probably not be relevant, like the spread fear about depleting water supplies. Most modern DCs rely mainly on closed loop cooling. The next thing is the idea that they would poison the water supply. One evidence video shows brown tap water. What do the people think data centers would do?! The reason for the tap water was the construction site (I think they actually broke some rules), because the data center wasn't even finished at that time. Criticizing the construction company is completely valid, but the things get taken out of context to tell "data centers bad".

The main problem I have with that is, that most people telling that clearly use it as proxy argument for other (possibly more valid) concerns. When they say "I fear that AI may replace my job", that's honest and something one can discuss. On the other hand, they risk that the outcome of the discussion may not be to their favor. So they take the proxy argument to say "AI hurts the environment" trying to stop AI by attacking another topic than they actually care about. That's not only dishonest, but also prevents people from discussing the actual problem. If AI replaces a lot of jobs, this may be an economic problem and should be addressed. Even that singular case of that person can be discussed to find good solutions (or to find out, that their job may be still required), but that doesn't work when they talk about electricity, water, and possible environmental damange.

Not long ago I've seen another FUD argument. Someone posted an aerial picture of some site with forest around it. Everything nice and green. Then they posted a picture of the same site with the data center built and the trees all brown. The environmental damage must be huge, no? What poison did the data center release to kill all the trees? The explanation was simple: The first picture was taken in summer, the second in winter and the color of the trees was unrelated to the DC.

Comment Re:Correct. And oh, no. (Score 1) 51

Yeah, "very". They're going to make it like sudo where when you give permission to a program to write protected files once it has it forever after.

No, wait, that isn't how it works, is it?

That's how it already works. But you can request the permission from the user with a pop-up. Presumably a "very explicit action" means going into the Settings app and turning it on by hand.

But that's going to do exactly nothing. The app will tell them that they have to do this, and the users, having no idea how dangerous it is to give an AI unrestricted access to their device, will do it anyway, and we'll be right back to where we are now. And the next step will be "See, we can't allow full disk access." And then macOS will cease to be usable.

The only reasonable choice is to flag Meta's software as malware for extending their full disk access to agents. Force them to implement a proper sandbox. Apple already gives them all the tools they need to do it right.

  • The main host app asks for full disk access, but functions without it, triggering an open file dialog to work around missing access when necessary. Most users will end up granting full disk access out of frustration, but that's okay because the agents themselves don't have that access. If possible, make it start out with a read-only full-disk entitlement, because otherwise, using it will be much harder.
  • Each agent runs in a separate agent runner process with a stricter sandbox.
  • The agent sandbox has an entitlement that grants read-only access to the entire disk (or, if the main host app's sandbox doesn't allow that, to every resource that the main host app has access to), and bans the use of the socket() system call.
  • AI agents can request read-write access to specific files or directories by asking the host app. The agent is encouraged to ask for access to an entire directory at once if it needs to write to multiple files in that directory.
  • The host app can pass in a security-scoped bookmark/URL to grant permission, but asks the user first unless the URL is part of an explicit list of allowlisted URLs that the user provided before beginning the task. Doing this expands the sandbox to allow writing to that file or to files in that directory. The SSB can be created programmatically or, if the main app also doesn't have access, through showing an Open File dialog.
  • One tool provides network access to specific hosts with no POST, all GET parameters filtered, and a low limit on URL length to mitigate exfiltration risk. This tool has an entitlement that allow socket access inside an environment where opening sockets is otherwise banned, and thus can be run directly by AI agents.
  • One tool provides broader network access with full upload capabilities. This tool lives outside the sandbox so that the AI agents cannot run it themselves — only ask the main host app to run it for them. Then:
    • The main host app requires the user to give permission to access a single hostname for either a single request (allow once) or a single task (always allow for this task).
    • If the user clicks the "Always allow sending data to example.com" button, the user is asked "Trust example.com for similar request parameters only" or "Trust fully".
    • If the user choose to trust similar request parameters only, then any additional GET parameters must be explicitly allowed each time.
  • The main host app passes each AI agent runner a new open socket connected to the AI service's server.
  • The AI service's server is configured to provide minimal or no network access from the server side.

This is how you protect privacy in an agentic environment.

Comment Re:I'll take $10K (Score 1) 124

EU has pretty strict regulations. In particular US people make fun of it and talk about how companies can compete less, but in the end it means that the citizens can assume that nobody is dumping radioactive waste in their local lake and that the USB charger they bought won't burn their house down because a missing extra capacitor would make the production 5 cent more expensive.

Comment Re:Correct. And oh, no. (Score 1) 51

I hereby retract everything I just said. The entire post was based on a misunderstanding caused by Slashdot's editors adding a single extra letter.

  • Original: "very explicit user action."
  • Slashdot: "every explicit user action."

What a difference an 'e' makes. I was imagining every single file access causing a UAC dialog.

Yikes.

Well, no, I don't retract the last paragraph. They should still kick Meta's garbage agent off the platform until Meta can get security right.

Comment Re:Correct. And oh, no. (Score 3, Funny) 51

This looks like the final cell-phonification of the Mac. I'm bummed.

How do you figure that? From the Apple post: "Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. "

The word was *every*. *Every* explicit user action.

Oh, bloody hell. I just got rage-baited by incompetent Slashdot editors.

Good night. I'm done for the day.

Comment Re:Correct. And oh, no. (Score 1) 51

This looks like the final cell-phonification of the Mac. I'm bummed.

If this happens, this thirty-year Mac user will be leaving the platform. Full stop. So will just about everyone else within months to single-digit years.

This approach didn't work with Gatekeeper in Mac OS 7. It didn't work for Windows XP. It won't work for modern Mac OS, either. Here's why: CONSTANT PROMPTING MAKES SECURITY WORSE.

Prompting users over and over again to allow or deny actions makes security WORSE. Period. It means that users are constantly being nagged, and constantly having to decide whether an action is harmful or not. This rapidly (over the course of just minutes) turns into query burnout, and the user just clicks "Allow" for everything. And not only does it fail to meet its objective, but it also causes them to the same for every other dialog, including all of the other things Apple put in place to improve privacy and security. And now people are granting every app whatever access it asks for automatically without question, and every advantage that Apple has security-wise and privacy-wise evaporates instantaneously.

Continuous prompting NEVER makes security better. It ONLY makes security worse.

AND this would have a hopelessly deleterious effect on EVERYTHING that high-end users do, from running commands in Terminal (which would become completely unusable) to third-party backups, etc.

And that latter one would also be a major antitrust problem for Apple, which is to say that if they do this, they WILL get sued, and they WILL lose, because it is so clearly open-and-shut that this is not the correct solution for the problem, but that Apple stands to greatly benefit while their competitors are irreparably harmed.

What's described here would completely break the platform at a level that makes it a toy, no more useful than iOS, and completely unreasonable to use for any serious professional work, whether as a software engineer or a graphic designer. And it is pathetically absurd that they think this is a good idea. It makes me assume that none of the Apple security engineers I know are still around, because all of them would have flat out called you a moron for even suggesting something like this. They actually understood security at a more-than-superficial level. Someone proposing this "solution" clearly does not.

You can't fix sh**ty apps by making the platform objectively worse or making things that people legitimately need to do as painful as possible. The only way to fix sh**ty apps is by banning them from the App Store and flagging direct downloads as malware repeatedly until such time as they get their security model right. There are correct ways to sandbox things like agentic frameworks. This is about as far from the right way as you can get, as it does nothing to improve the security of the agentic setup, while catastrophically breaking overall platform usability and turning users into mindless "Allow" clickers.

Find another way. Kick Meta's horrific agentic tool off the platform until they can get security right.

Comment Re:Groundwork for censorship (Score 1) 103

Moderation is censorship by definition.

False.

Censorship means suppression of speech or expression by a governing authority. It can be prior restraint (blocking publication) or censorship after the fact (take-downs, bans, etc.).

In the strictest sense, you could maybe argue that soft moderation in the Slashdot style where people who want to see what has been moderated down doesn't qualify as censorship because there's a way around it, but the net impact is still that most of the potential audience doesn't see it, so that argument is on somewhat shaky ground.

At best, you can argue that moderation is not prior restraint censorship, but while prior restraint makes censorship way more likely to be a first amendment issue if the government is involved, it's not a requirement for something being censorship.

Comment Re:LOL wut? (Score 2) 51

AI agents have different level of access. You can of course give it automatic access and let it delete all your files if it needs more disk space, but you can also have it ask you for every action, for not whitelisted actions, or restrict which files it can access. Different software implements different controls, but most have a "YOLO" mode and a more sane mode that doesn't allow it to delete your hard drive without asking.

Slashdot Top Deals

"Well, it don't make the sun shine, but at least it don't deepen the shit." -- Straiter Empy, in _Riddley_Walker_ by Russell Hoban

Working...