↑
logo

Updates to Full Disk Access in macOS

Posted by notfirstpost |2 hours ago |49 comments

moecables 2 hours ago[1 more]

IMHO, it's good to add more specific controls for this. After reading this, I went and checked my list of app with full disk access:

- Ghostty (fine, it's my terminal)

- Alfred (fine, I use it for searching everywhere)

Then I have a few turned off:

- Spotify (why does it need full disk access) ??

- Gemini (nope, don't need it to know everything about my computer)

mrkpdl 2 hours ago[1 more]

I would like the ability to see which specific folders I have granted access to on an app by app basis. And edit. It’s not clear to me how you revoke an app’s individual folder access after you have granted it.

post_break 2 hours ago[4 more]

One update away to revoking Full Disk Access in the future. This commercial has come full circle: https://www.youtube.com/watch?v=VuqZ8AqmLPY

etatester an hour ago[3 more]

What we need is true application isolation even in the command line. Treat Terminal as privileged access, not something any app can just command. Sandbox non-app store apps as well.

Kim_Bruning 2 hours ago[9 more]

Am I getting old? "full disk access" used to be something that's supposed to be normal; if you're the owner of the machine.

VCFundedGenYer an hour ago

If it worked as intended, they wouldn't be in this predicament.

That feature was so stupidly nonfunctional before. Some apps got stopped by it, others didn't. Often you'd be able to install an app from homebrew and it had full ride access to the disk, while App Store apps had to request consent for any folder whatsoever. It was completely random.

jameskraus 2 hours ago[2 more]

Oh no, even more permission prompts on macOS. It's already almost unusable due to the existing ones.

pkulak an hour ago[1 more]

I feel like this isn't going to be a simple permission popup. Probably along the lines of getting an "unapproved" binary to run, where you have to stop what you're doing and wade through settings, trying to find the right toggle 6 nodes deep in the tree.

tekacs an hour ago

Apple, as always, seem extremely determined to make sure that they protect things on your computer from being accessed by you.

Apple Intelligence is a great example of this. Everything can funnel up to Siri, but neither you nor any other app on your computer can see what is fed to it by all of the APIs that would provide it data. So anyone who adds support for it is enabling Apple to do their usual slow broken thing with Siri and not enabling any other way you might want to use software or AI with that data.

tapvt an hour ago

I dislike restrictions out of instinct, but to be fair, I've had permissions request popups on my Mac that were the first sign of software, which I had actually written, maybe had some bugs allowing it to work outside of its intended bailiwick.

rwz 2 hours ago[2 more]

When I give something a "Full Disk Access" permission, I expect it to have full access to what's on my disk, including "files, mail, messages, and even (gasp) browsing history"! Who are those mysterious people who expect their browsing history to be magically excluded from something called Full fucking Disk Access?

techscruggs 2 hours ago[1 more]

Everyday, we get one step closer to the year of the Linux desktop.

big_toast 2 hours ago[2 more]

"Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac"

Huh? Seems like a disingenuous statement. I hope they update that sentence with something more accurate.

However, I've wanted much more granularity and pervasive permissions so I'm glad they're adding them.

lapcat 2 hours ago[2 more]

My understanding is that Meta Muse simply opens the System Settings Full Disk Access pane, and the user has to enable it themselves using System Settings, which says, "Allow the applications below to access data like Mail, Messages, Safari..." and which requires an administrator password to change.

Thus, I'm not sure what more Apple can do here, but I'm definitely afraid of what they're going to do.

russellbeattie an hour ago

Maybe it's just my pet peeve, but it's less about my documents and mail and more about programs, tools and AI harnesses deciding they can fill hidden dotfile folders at root with whatever they want (which they do indiscriminately). I don't just hate that there's tons of untracked caches and temp file data that isn't easily discoverable, but more specifically, I don't want all that crap in my root directory.

Who decided that hidden folders are a good thing anyways? .agent, .agents, .aws, .bun, .cache, .cargo, .claude, .codex , .config, .docker, .gemini, etc. I just end up having to show hidden folders all the time, which defeats the point.

It's gotten truly ridiculous. I want the OS to strictly enforce my root directory. There should be a few global preference files in there for like .zsh, and everything else organized in proper, unhidden folders.

jonathanstrange 2 hours ago

If there is one thing I absolutely despise with all of my heart, then it's mega corporations patronizing their paying customers.

ls-a an hour ago

Comment deleted