Apple and a hacker's future

278 points · 236 comments on HN · read original →

Points and comments are a snapshot, not live.

A hacked Mac Mini shows tensions between agent autonomy and macOS security controls.

The author's always-on Mac Mini running Claude and Codex was hacked through a macOS screen sharing vulnerability (CVE-2026-65400, severity 7.1). Claude's agent detected the compromise-a root-planted crypto miner-and helped remove it. The incident highlights friction with macOS TCC permission prompts, which silently block headless agents and forced reliance on screen sharing. Apple's new Full Disk Access restrictions aim to protect users from AI agents but may limit legitimate automation. The author argues Apple prioritizes platform control over user-defined computing, contrasting with a vision of agent-driven home automation.

What commenters are saying

Two camps form: some support Apple's move, arguing Full Disk Access warnings protect against Meta Muse's data leaks and prompt injection risks, while others see it as platform control limiting pro-user automation. A key point notes that disabling SIP is the only workaround for TCC prompts, but scare warnings deter that. Another cites Muse reading iMessages without permission as evidence the restrictions are needed. Skeptics warn granular access may become impossible for legitimate tools like Terminal.