Apple and a Hacker’s Future

#summary

Apple and a Hacker’s Future

Ben Thompson runs a dedicated Mac mini with a persistent Claude Code thread that records ideas and tracks projects. When its monitoring tool restarted, the agent warned of unexpected changes and stopped executing commands. Thompson says he used that same agent to investigate, build a watcher and wipe the machine, despite its advice to stop using it. He argues that macOS protects files by asking each app for approval in a GUI the unattended agent cannot inspect, forcing him to log in remotely to click through prompts. He wants permission granted at the supervising-agent level, not afresh to each program it writes.

That request collides with the privacy risk Apple describes: Full Disk Access can expose files, messages and other people’s correspondence. Apple’s October 2 developer note promises additional explicit-consent controls but does not say what they will be. Thompson connects his frustration to a broader preference for a personal agent that builds its own interfaces and controls home devices rather than relying on Apple’s app integrations. His hacked host makes that independence an operational responsibility as well as an attraction.

The chronology needs care. The Ars Technica report quoted as saying the patch arrived “last week” was published August 14: Apple’s advisory dates the screen-sharing fix to August 6, and the Dutch NCSC recorded active exploitation on August 12. The October 5 essay reports Thompson’s experience, not a newly discovered October vulnerability. The NCSC verifies exposed machines with miners, not the exact entry path on Thompson’s machine; his logs and later reliability are not public. Apple’s settings also distinguish background security files from automatic macOS version updates. This is an instructive incident, not a measured claim that agents outperform endpoint security.

Read at stratechery.com · 15 min