piazz
a day ago
I’m pretty frustrated with Muse and the last thing I want to be doing with my free time is defending Meta, but this is such clickbait.
Point by point:
> “OMG you can jailbreak it and get it to spill its VM”
This is the whole point; any content on the VM is yours. It runs in an isolated sandboxed VM separate from stored credentials etc; this is effectively your own computer. You don’t have to trick it.
> It collects dossiers on your contacts
These are more text files that live on your private VM, alongside memory.md, etc. Do you want your secretary to forget every person you contact every day?
> It accessed Messages without full disk access
This whole story never made sense or was substantiated. Full disk access is an OS level security boundary; the user had to switch this on.
> It sold some guys stuff for too cheap and gave out his address
OK this one I basically believe, haha. Because this is the problem with Muse: the LLM is just too dumb to perform complex tasks effectively in many cases.
cmiles74
a day ago
I gotta' disagree on this one. Meta made claims that it was taking privacy seriously and it turns out, not so much. I do think they should be getting some pressure on that score.
piazz
a day ago
Okay, but what is the evidence to back up this assertion? My point is, at this time, there is none. There is no “it turns out”. Give them some time to screw up at least.
GeekyBear
a day ago
> Meta’s New Muse AI Agent Read My Private Messages. I Never Asked It To
https://www.inc.com/jason-aten/metas-new-muse-ai-agent-read-...
lapcat
a day ago
Literally nobody has reproduced this.
The Messages database is protected by macOS TCC. If Aten were correct, there would exist a macOS zero day vulnerability.
The vastly more likely explanation is that Aten mindlessly gave Full Disk Access to Muse. And that appears to be Apple's assumption, based on Apple's newly published developer note.
GeekyBear
a day ago
Apple's statement on the matter sure sounds like Meta has once again been caught with their hand in the cookie jar.
> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.
lapcat
a day ago
> Apple's statement on the matter sure sounds like Meta has once again been caught with their hand in the cookie jar.
> > Some developers are using Full Disk Access in ways that could put users at risk
In other words, Muse did have Full Disk Access. Jason Aten did grant Full Disk Access to Muse, despite his claims otherwise.
If Aten did not grant Full Disk Access to Muse, then why would Apple even be talking about Full Disk Access?
The point is that Aten apparently granted Full Disk Access absent-mindedly, so absent-mindedly that he won't even admit that he did it. This is why Apple is making changes to Full Disk Access to make it more obvious what's happening.
GeekyBear
a day ago
> In other words, Muse did have Full Disk Access. Jason Aten did grant Full Disk Access to Muse, despite his claims otherwise.
Perhaps you should do some reading on the matter?
> Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges. One is full-disk access, a macOS system-level permission. The other is to enable a Messages connector setting in Muse.
“The Messages integration in the Muse Mac app is opt in,” Singleton said. “Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.”
Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame.
https://arstechnica.com/security/2026/10/apple-changes-full-...
Meta has a long history of not respecting boundaries once something is technically possible.
ipsum2
a day ago
Meta CTO is Bosworth, not David Singleton. If an article can't get a basic fact like that right, I have low hopes for the rest of it to be accurate.
lapcat
a day ago
> Perhaps you should do some reading on the matter?
Perhaps you should: https://lapcatsoftware.com/articles/2026/10/2.html
> Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame.
Indeed, and it looks like Aten absent-mindedly did all of this!
> Meta has a long history of not respecting boundaries once something is technically possible.
It's not technically possible for Muse to read the Messages db without Full Disk Access. Aten denies having given FDA to Muse. Thus, Aten is simply wrong, misremembering or something. And if he misremembers about FDA, he likely also misremembers about granting app-level permissions to Muse.
Again, literally nobody has reproduced Aten's experience. Show me one other person.
In fairness, Aten behaved just like many other users would, mindlessly granting permissions that an app requests. That's certainly a problem. Unfortunately, Aten stubbornly refuses to admit this, instead confusing the problem by suggesting technical impossibilities. Aten doesn't want to take any responsibility for his own actions.
GeekyBear
a day ago
> Indeed, and it looks like Aten absent-mindedly did all of this!
Since Aten has clearly said he did not grant Muse the permission to read his messages (inside Muse), I'm not accepting your version of the events.
lapcat
a day ago
So you prefer to accept the version of events where Aten somehow stumbled upon a macOS security vulnerability that allows apps without Full Disk Access to read the Messages database, a vulnerability that nobody else has reproduced and that Apple itself apparently doesn't recognize? Just because one writer said so?
cloudfudge
a day ago
If what the writer said was strictly true, Apple would be having a little security freakout about how Muse managed to bypass this OS control. My assumption is that the writer did not understand everything he was granting it permission to do, so he legitimately believes that he didn't grant it those permissions. But he did.
GeekyBear
a day ago
Apple's statement is that the permission is being abused to do things that users do not think are possible.
In this case, Meta explicitly promises that Muse will not read your messages even after you grant it disk permissions.
lapcat
a day ago
> In this case, Meta explicitly promises that Muse will not read your messages even after you grant it disk permissions.
There's no reason to doubt this claim. The only person in the world who has claimed that Muse disrespects its own internal setting is the same person who claimed that he didn't grant Full Disk Access to Muse.
Ironically, Aten's own screenshot appears to show that he toggled the internal setting from "Off" to "Read only". In my own testing, it's "Off" by default, and the only way to change the internal setting is to enable Full Disk Access first.
Thus, the likeliest scenario is that Aten unthinkingly granted Full Disk Access to Muse, granted the Messages app permission, then had a change of heart, disabled Full Disk Access, and then forgot what he had done. Later, when he noticed that Muse had some of his messages, he went back and checked, and saw the FDA was disabled, forgetting that he had toggled it on and off.
givinguflac
a day ago
Lmfao you tell someone to read and then post your own opinionated blog post? I would reiterate that you need to read, perhaps outside your own bubble.
lapcat
a day ago
My blog post included links to and quotes from Jason Aten's posts, which shows that I had done reading on the matter, contrary to GeekyBear's unfounded insinuation.
Moreover, my "opinionated" blog post also included a screen recording of the Muse first run experience, so everyone can see for themselves what it's like. And if you don't trust my screen recording, then you can perform the exact same experiment yourself. Nothing I did was unique.
b112
a day ago
So you're saying he mindlessly, and without thinking about it granted two OS level permissions to Muse? I don't understand how this refutes anything the parent poster said.
cmiles74
a day ago
Reading it over, it does seem like giving the app full disk access would be enough for it to read our messages. I mean, they are stored on disk somewhere.
GeekyBear
a day ago
Exactly.
Meta's claim that Muse would not read your messages without explicit permission was meaningless.
judge2020
a day ago
> Meta's claim that Muse would not read your messages without explicit permission was meaningless.
But it was true and you still haven't refuted that Aten mindless clicked through and allowed Muse full disk access and/or the messages connector setting in the Muse app.
cloudfudge
20 hours ago
The real question is why you'd give an app full disk access if you didn't want it reading your files.
lapcat
a day ago
Yes?
givinguflac
a day ago
“Mindlessly” gave full disk access. This is why Apple is restricting FDA further- people are stupid. TCC exists, great, but you’re spending so many comments harping on TCC that you e lost the plot here.
runarberg
a day ago
Do we really need evidence here? We know Meta is a bad actor, we have plenty of evidence of Meta/Facebook engaging in criminal or otherwise human-hostile behavior (including facilitating a genocide).
When an actor has shown it self to be this malicious, we should be allowed to assume all the worst thing about it. And we should at the very least resist and complaint whenever it shows it self able to cause even more harm to humanity.
mapremap
a day ago
It's definitely faster to just assume that there is evidence to reinforce our existing biases than it is to do the same after succeeding or failing to locate that evidence, so considering that all three methods lead to the same result, the one with the lowest time cost is optimal.
piazz
a day ago
This is terrible logic.
Trump is stripping the White House for copper and selling it!! Well, actually he’s not, but since we know he’s corrupt, isn’t it safe to just assume he might also be doing this other bad thing?
If your decision is to avoid Muse due to Meta’s poor track record, that’s absolutely your prerogative (and a reasonable one!). But specific claims must be evaluated based on their evidence. This article fails that. There’s no story here.
runarberg
a day ago
The logic here is that Meta (a company known to be malicious) is putting out a product which is potentially dangerous. There are some anecdotal evidence of said dangers, and it is perfectly rational to believe given the history and dangers involved. Best case regulators step in and ban this product before we know the validity of these anecdotes. Worst case, regulators do nothing, the public starts using the product, and these anecdotes turn out to be valid.
Off course there is space between the worst and the best case. But given Meta’s history it is safest (and the most rational) to assume the worst.
moffkalast
a day ago
Ah yes, Meta and privacy. Two things that go together like a jet engine and a library.
redindian75
a day ago
have u heard of Whatsapp?
IshKebab
a day ago
> it turns out, not so much
Why though? The comment you're replying to is explaining how the accusations of poor privacy are nonsense and you've just replied "I disagree because they have poor privacy".
I mean I'm not going to hand over any data to Facebook if I can help it but it doesn't seem like there are any specific issues here.
jonplackett
a day ago
Anyone who believes meta are taking privacy seriously cannot have more than a handful of brain cells.
bdangubic
a day ago
handful is too many in this case
GeekyBear
a day ago
> It accessed Messages without full disk access
>This whole story never made sense or was substantiated
This story makes perfect sense, and Meta has a long history of not respecting user privacy controls.
> tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits
https://arstechnica.com/security/2026/10/apple-changes-full-...
kccqzy
a day ago
The reason that story didn’t make sense to me was that the tech columnist never showed the Apple system settings on whether full disk access was enabled or not. If you trusted the tech columnist that full disk access was not enabled, then Meta’s Muse AI seemed to have discovered a zero-day vulnerability in Apple software, specifically a TCC bypass.
First I doubt Muse is that good of an AI. Second, even if that’s the case, why wouldn’t someone report it to Apple to get thousands of dollars in bug bounty rewards?
GeekyBear
a day ago
Apple's statement makes their position on the matter clear.
> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.
kccqzy
a day ago
That Apple statement assumes that the user has granted full disk access but the user said he did not. So I conclude that Apple thinks the user is either lying or had forgotten he had enabled full disk access.
I’ll be charitable and say the user isn’t lying. Okay he has made a mistake in the initial granting of permissions. Then why didn’t he correct or retract the article?
GeekyBear
a day ago
Because Muse has a setting in the app that you are supposedly required to turn on before it can read your message?
One that the journalist in question did not turn on.
lapcat
a day ago
The app-level setting is irrelevant if the app does not have Full Disk Access.
Muse cannot bypass built-in macOS protections. TCC does not work on "the honor system", any more than UNIX permissions. It doesn't matter how nefarious Meta happens to be. Operating system security is designed to be resistant to malware.
GeekyBear
a day ago
> The app-level setting is irrelevant if the app does not have Full Disk Access.
I'm just going to have to ignore you on this issue.
> Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges.
bigyabai
a day ago
One one of those privileges actually stops them from accessing the filesystem. Any agent, Meta or otherwise, can access iMessages without the connector in that configuration.
lapcat
a day ago
> I'm just going to have to ignore you on this issue.
Sure, what do I know? After all, I'm only [checks notes] a 20 year veteran of Mac software development with multiple Apple-issued CVEs to my credit. ¯\_(ツ)_/¯
> > Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges.
Yes. Those two:
1. Full Disk Access
2. The Messages Setting in Muse
As I said, without the first, the second alone won't allow Muse to read your Messages db. Do you not understand why Singleton said that Muse needs both?
GeekyBear
a day ago
The entire story here is that Meta claimed that Muse would not access your messages without you granting it the second permission, even after your granted it the first.
Hence Apple's statement that the first permission was being abused to destroy any promises of user privacy.
lapcat
a day ago
> even after your granted it the first.
The problem here is that Aten claimed he did not grant the first, and moreover, you have been defending that claim of Aten's in these comments.
As soon as you admit that Aten did indeed grant the one permission, it's not much of a stretch to conclude that he also granted the second permission. It would be very odd, I think, to distrust Aten in the one case yet stubbornly take him at his word in the second.
Again, if even one other person in the entire world could reproduce Aten's alleged experience...
GeekyBear
a day ago
The story has always been:
Meta promised that they would not read a user's messages without an additional permission the user must enable inside of Muse, even after they granted Muse full disk access.
A journalist reported that Muse read his messages despite the fact that he did not grant permission for it to do so inside Muse. He never claimed he did not grant full disk access.
Apple announced that the full disk access permission was being abused.
lapcat
a day ago
> He never claimed he did not grant full disk access.
False. In fact he has claimed this multiple times:
"Full disk access off. Muse synced 187k lines form my messages chat db." https://www.threads.com/@jasonaten/post/DdezsMJFhBr
"I still haven’t gotten an answer as to how it was reading my messages with Full Disk Access turned off, but I’d be happy to dig into it with anyone from Meta that wants to help." https://www.inc.com/jason-aten/meta-keeps-apologizing-for-mu...
This is why he's not a reliable narrator.
And another false claim he made, "Also, that full disk access doesn’t say anything about your message database", which anyone can easily refute by opening System Settings and reading the text.
cma
a day ago
That's the setting to let it read your messages if you don't want to give it full disk access. If you give it full disk access wouldn't that supersede it unless you don't store your messages on the disk?
TeMPOraL
a day ago
> I’ll be charitable and say the user isn’t lying. Okay he has made a mistake in the initial granting of permissions. Then why didn’t he correct or retract the article?
There is no answer to that consistent with the premise you assumed out of charity :).
zardo
a day ago
Aren't permissions on notifications less restricted then full disk access?
lapcat
a day ago
> Meta has a long history of not respecting user privacy controls.
Meta's respect is irrelevant, because macOS TCC prevents any and every app, including malware, from accessing your Messages database without Full Disk Access.
> he never granted Muse permissions to read his messages
That's what he said, but I would suggest that one person's memory is a lot more fallible than a longstanding operating system security feature.
givinguflac
a day ago
Seriously, stop trying to grandstand this thread and being Meta’s lap cat. It’s gross.
How on earth, after literally decades of abusive behavior by meta, are you standing the straw man that maybe and based on your assumption the user is lying??
lapcat
a day ago
Please read and respect the HN guidelines: https://news.ycombinator.com/newsguidelines.html
I said that Aten is misremembering. That's not the same as lying. We all misremember things.
I don't care about or trust Meta. In my blog post about the Muse first run experience, I said, "For testing I used a fresh VM, not signed in to my Apple Account, because of course I don’t trust Meta with any of my data!" https://lapcatsoftware.com/articles/2026/10/2.html
What I do care about is truth and accuracy. My mistrust of Meta is not going to make me distort the truth. Muse cannot bypass macOS TCC, that's a simple truth.
I'm a macOS software developer. That's the reason for my interest in this story, the technical aspects of it.
bigyabai
a day ago
Which privacy control did they fail to respect, in this instance? Everything on the journalist's machine was working as-intended.
al_borland
a day ago
In. Jonna Stern’s interview with Zuckerberg he talked about the security, and how they delayed it to make sure they got it right. He then went on to say there was more to do and they weren’t totally isolated yet (I can’t remember his exact wording).
I felt like he was undermining his original point. They delayed to make it better, but didn’t delay long enough to do the actual right thing he mentioned they could potentially do in the future.
When it’s pulling in data from all over the phone or computer, it’s not just the user’s data. Some of my personal data (detailed contact info, emails, etc) can be pulled in and used by Muse if someone I know installs it, without my knowledge or consent. That needs to be taken seriously, and Meta has a history of abusing this concept (uploading fully address books to find friends)
hitekker
a day ago
It's the market for attention. Many of techdirt's writers are heavy Bluesky users so most of their articles cater towards other Bluesky users. Venting might be the most common longform on either website.
yalogin
a day ago
Using an encrypted VM is standard but the encryption is the core issue. Just plain encryption will allow them to proclaim it’s all secure/private. But that is where I don’t trust Meta. Are they using a different key for every user? They are not claiming that meta cannot and will not see the data. Can they say that the user data is not exfiltrated for their own training and analysis? Are they claiming that their developers cannot see user data? What happens when a government request comes? What happens when a bug happens and their admins and devs need to debug? What about a rogue dev/admin?
I don’t trust meta will do any of this
butlike
a day ago
> I’m pretty frustrated with Muse and the last thing I want to be doing with my free time is defending Meta
Then don't.
greenavocado
a day ago
> the LLM is just too dumb to perform complex tasks effectively in many cases.
Muse Spark 1.3 is way better than anything else out there outside of the US labs except Deepseek Flash which comes close.
iAMkenough
a day ago
Nice! Starting my own crypto miner using Meta infra then.
moscoe
a day ago
Absolutely agree. So much feigned outrage in these articles (and HN comments) about the LLM models doing x.
Yesterday everyone was all worked up about OpenAI generating an image with a signature on it.
Caveat emptor. Don’t be an idiot. Grow up. Make informed decisions regarding your use of these products and take responsibility for those decisions.
slashdave
a day ago
> Make informed decisions regarding your use of these products
They are mass marketed. The creators should do the upmost to ensure this and not pin blame on users.
givinguflac
a day ago
In this context, normal people will believe the marketing and trust meta, and caveat emptor is a cop-out at best. I can sell you a basket of bread, and it’s privacy-preserving bread, but it will also punch you in the face if you don’t read every bit of the agreement. No one reads the agreement, and that’s what Meta runs on, plus skirting the law in every way they can possibly get away with.
bigyabai
a day ago
In this context, Apple provided a feature that gives applications Full Disk Access. The journalist enabled it, and then had their face eaten by leopards after ignoring the warning.
Take Meta out of the equation here; any agent with FDA can do the exact same thing. Claude, Codex, DeepSeek, any of them. This is why Apple's response is a fix to their own software. The fix is a mea-culpa, Apple would not have to patch their OS if it was behaving exactly the way they wanted it to. Apple and the journalist made the biggest mistakes here.
Meta is a godawful company that should be regulated into the dirt until Zuck is left with nothing. Guess what? They're not to blame in this scenario, and your rabid attacks on lapcat (who is a reputable and generally impartial macOS developer) is unnecessarily hostile towards a perfectly normal observation. This brand of comment is so misleading, low-effort and harmful to good-faith discussion that I'm tempted to flag this whole thread for being founded on a misunderstanding. Your response has contributed to the derailing of this conversation by tribalist "Apple vs Meta" pundits who are drowning out a well-known and respected expert that has technically-salient architectural details to share. HN cannot foster intellectual gratification under these conditions.
JohnMakin
a day ago
> Caveat emptor. Don’t be an idiot. Grow up. Make informed decisions regarding your use of these products and take responsibility for those decisions.
Feigned outrage, indeed. I don't think it's unreasonable to point out that Meta has been consistently predatory, reckless, and creepy with user data before, and that this is a very aggressive expansion of that.
The old facebook booster retort of "if you don't like it, don't use it, take responsibility" or whatever is nonsense. You're in their system whether you use their product or not. Even if you somehow avoid their pervasive web-wide tracking, a single contact you know installing this thing and gobbling up all your correspondence with them can compromise your privacy choices, and that's well beyond your control, unless you seriously suggest I audit every single one of my contact's devices and browbeat them into using the privacy choices I prefer.
Get real.
bigyabai
a day ago
> "if you don't like it, don't use it, take responsibility" or whatever is nonsense.
Why? I don't use Meta products, and my life isn't substantially impacted or controlled by them. Explain to me why I need to lobby my OS developers to reign-in Meta, from my perspective. Why is my hands-off approach insufficient for teaching adults to make intelligent decisions?
Facebook is unquestionably awful, but that's a regulatory issue. 90% of the people chiming-in with Facebook outrage aren't using Meta products; they are literally feigning surprise and outrage as someone that clearly knows better. Oftentimes, they oppose any regulation that would force Meta to reconcile their damages because it would also jeopardize other abusive monopolies like the App Store that they love to defend. So where does the buck actually stop? Does it ever?
HN has done this for years. Years and years and years. "Meta is horrible! Stop them!" -> "New Meta product has ~10-100 million MAU" -> "We need private enterprises to limit Meta!" -> Stagnant status-quo where exploitation is rewarded. Things got this bad because of the pugilist, tribal attitudes that dominated tech discussions and steered people away from common-sense regulatory measures.
stephen_cagle
a day ago
My assumption is you clearly don't have vulnerable or elderly people in your life? I'm not as concerned about my ability to navigate these waters as I am about the people I care about.
ralphington
a day ago
You just did the tech equivalent of "not to sound racist, but..."