upvote
> Am I getting old?

I think so.

I don't know where this "ownership" debate came from. My ownership of my machine depends on strict, broad + fine grained control over what third-party devs (who are not me) get to do with my machine. Our interests are incompatible and hostile, in an era where most "native apps" ship analytics and marketing SDKs, or are videcoded. If macOS didn't offer these controls I would run every apps in a browser where it's sandboxed. This isn't the 90s.

This change is a reaction to a viral story from a tech reporter who shipped all his texts to Meta without meaning to, which tells you there's a consent and transparency issue for nontechnical users. I don't think anyone in the industry has figured out a proper solution. Unless you never interact with nontechnical people, it impacts your privacy indirectly no matter what you do. Though as technical user I hope we can get more fine-grained control and auditing.

reply
This isn't 1980 anymore. The internet is super hostile and everyone wants to extract data. You're still free to allow every app on your computer full access, I won't. I am very glad that none of the hundreds of apps installed across my phone and Mac can access my photos and cameras without permission.
reply
My concern is that eventually Apple will require all apps (including non-App Store) to be specially approved by Apple in order to get full-disk-access, even if the end-user wants to allow it; like how there are no third-party iPhone/iPad backup apps.
reply
I’m 50 and I think it’s crazy we ever thought it was acceptable to give every app you run full access to all the files on your computer by default.
reply
macOS has been revoking access to stuff like this over the past decade. Things like unfettered access to modifying the OS went away with Gatekeeper and System Integrity Protection. "root" access is no longer true root on any Mac, and the user is treated like a prisoner. The UAC-esque prompts that come up in macOS would make Vista-era MS so jealous.
reply
root access is also no longer true root access on a lot of linux distros that are immutable, and container-esque like interfaces such as namespaces + cgroups also limit roots power.
reply
TFA:

> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding.

If you think an app from (say) Facebook can be trusted with unrestricted access to your whole machine, you're at least a bit naive.

reply
Only on systems without proper user management, or if the owner is logged in as the administrator.
reply
being a nerd here, sudo - yes, but indeed I thought the entire UNIX design of everything is files and there are permissions, groups, etc, should be sufficient.

But I think the "new world" is, we are over stimulated (eg. agents ask us 'permissions' for a long command) so we might give a sudo not fully aware of it where a big bold UX message box after a 'pseudo' sudo would better catch our eyes.

So it seems this is about adding additional layers over already existing ones in a way?

reply
The UNIX model assumed each human had one user. It did not provide a flexible way to sub-divide that scope for each program running as that user.

It has been extended, but not in a way that non-technical users can really use.

reply
Do you run every process as root?
reply
The software running isn't the owner though.
reply
deleted
reply
And despite hyperbole about Apple locking down macOS, ending the era of personal computing, it's hidden behind a toggle in settings. https://www.xkcd.com/1200/ applies, and in the era of downloading random programs off the Internet and cryptocurrency, random programs should have to jump through an extra hoop before getting access to everything. Imo Apple went a bit overboard with granularity, but it's not 1990 and the Windows 98 (lack of) security model doesn't work, and neither does Unix permissions either.
reply
I'm sure it'll be a permission the user can toggle. So they won't be taking away the ability for apps to see all the files but they'll be adding an extra layer of security so users can choose what an app can see. They're being light on details at the moment though.
reply
But this is what it is currently. At the moment, not only is it a toggle, but unlike almost all other permissions, you can't just request the permission.

You have to send the user to the system settings pane for it and have them manually toggle it on there.

It's hard to imagine how it could be more explicit than it is currently. I imagine they have something draconian planned.

reply