macOS 完全磁盘访问权限更新
Updates to Full Disk Access in macOS

原始链接: https://developer.apple.com/news/?id=p6zjojqw

苹果警告称,一些应用会滥用“完全磁盘访问权限”,未经授权访问敏感文件、电子邮件、消息、浏览记录以及第三方通信内容。为应对日益严峻的隐私风险,尤其是随着人工智能代理的能力和自主性不断提升,苹果计划要求用户明确采取行动后,才会向应用授予此类广泛权限。这样做的目的是确保用户了解相关风险,并对自己的数据和隐私作出知情决定。

苹果表示,将为 macOS 的“完全磁盘访问权限”添加更严格的控制,因为某些应用可以在用户几乎不了解其用途的情况下,访问文件、邮件、信息以及浏览历史。目前公开的细节仍然有限,但目标似乎是让此类高权限访问变得更加困难,并需要用户更加明确地授权。 The Hacker News 上的讨论呈现明显分歧。支持者认为,现代软件——尤其是 AI 智能体——都应被视为潜在威胁,因此,细粒度权限、一次性授权、审计以及清晰的撤销机制都很有价值。他们建议增加按文件夹划分的控制,限制终端和命令行工具,并改善应用级权限隔离,可能借鉴 OpenBSD、SELinux、容器或虚拟机的思路。 批评者则认为,这项改动带有家长式色彩,会打扰用户,并可能给合法开发、备份和终端使用带来麻烦。他们还抱怨 macOS 会弹出过多权限请求,并担心苹果最终会限制用户控制权或阻止用户侧载软件。总体而言,这场争论反映了隐私与安全同个人计算机应有的便利和自由之间的矛盾。
相关文章

原文

We give developers powerful APIs to build incredible capabilities into their apps for Apple products, backed by a set of controls designed to protect users’ private data. Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac. Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.

Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.

联系我们 contact @ memedata.com