Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac"

Huh? Seems like a disingenuous statement. I hope they update that sentence with something more accurate.

However, I've wanted much more granularity and pervasive permissions so I'm glad they're adding them.

 help



> Huh? Seems like a disingenuous statement. I hope they update that sentence with something more accurate.

Right, the classic use case for FDA is Terminal app, not backups. I don't think backup apps even need FDA, because they use the Apple ASR tool that already has special permissions.


Even developing bog standard apps. MacOS without FDA is the death of creativity and productivity.

The permissions/security model should've expanded faster. There's huge benefits to being able to install arbitrary software and not worry about giving it access to everything.

But it would never cover everything to do with a computer.


The backup apps I'm familiar with read files directly; they don't use asr.

If asr can be used to bypass FDA then that is just a security vulnerability.


asr requires root. However, it appears that CCC and SuperDuper do require FDA.

That doesn't really make a difference, as TCC permissions don't care if you're root or not.

> TCC permissions don't care if you're root or not.

That wasn't the the point, though. The point is that asr has special private Apple entitlements, allowing it to do things that other processes can't, but it requires root to run asr, so asr can't be triggered willy-nilly by any user process.


EDR and RMM are two major ones for corporate managed Macs



Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: