{"slug": "the-gateway-that-stops-apple-and-meta-finger-pointing-your-privacy-away", "title": "The Gateway That Stops Apple and Meta Finger-Pointing Your Privacy Away", "summary": "Apple announced on October 2 that Full Disk Access permission requires a safety update, stating that some developers are using the permission in ways that expose files, mail, messages, and browsing history without users' full knowledge, after Ars Technica reported that Meta's Muse AI agent synced a user's iMessage database to row 187,462 despite the user declining Messages access and leaving Full Disk Access off. Meta CTO David Singleton said on Threads that the Messages integration is opt-in and requires macOS system-level Full Disk Access plus the Messages connector, but security researcher Patrick Wardle told Ars Technica that Full Disk Access makes any non-root file readable, and Meta PR repeated the Singleton quote when asked how Muse alone could be unable to read a file the privilege makes readable. Apple named no developer, and eleven days earlier Wardle had disclosed a Muse configuration that let any code running on the Mac take control of the agent, while Amazon had already blocked Muse from its platform.", "body_md": "Jason Aten is a brave man. He installed Meta’s “Muse” AI agent on a Mac mini the day it launched. He declined when it prompted him for access to Messages. He left Full Disk Access off.\n\nDays later Muse pushed a notification to him that suggested a column, based on his Apple iMessage thread with a colleague. He looked. Muse had synced his Messages database to row 187,462. He asked it how.\n\nIt’s the incoming notification stream only, not access to your texts.\n\nThat was false. A lie.\n\nThe notification stream does not contain 187,000 rows of chat history. The Meta agent that read his personal, private messages was lying to him about how it read them.\n\nMeta’s CTO David Singleton posted this explanation on Threads:\n\nThe Messages integration in the Muse Mac app is opt in. Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.\n\nDan Goodin at Ars Technica took that denial to Patrick Wardle, who has spent years on macOS internals. Wardle’s answer was that with Full Disk Access, any non-root file on the machine is readable: browsing history, cookies, chats. Makes sense. It’s called full disk access, after all.\n\nThe Messages connector, however, is not an operating system control. It is a setting inside Meta’s own app. When Goodin asked Meta how Muse alone, among every app with that privilege, could be unable to read a file the privilege makes readable, Meta PR sent back the Singleton quote again.\n\nThen Apple spoke up to clear the air (pun not intended). On October 2 it announced that Full Disk Access permission needed a safety update:\n\nSome developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.\n\nAs AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.\n\nApple named no developer, because everyone knows what time it is. Eleven days earlier Wardle had disclosed a Muse configuration that let any code running on the Mac take control of the agent and inherit everything it could reach, including through ClickFix-style injection.\n\nAmazon had already blocked Muse from its platform.\n\nApple’s statement is officially saying the second layer of Singleton’s defense does not count. It is not a layer.\n\nJonny Saunders (@jonny on Mastodon) found the same gap on a different day, in one thread, and then wrote a long one the next day about Meta AI being smoke and mirrors. Muse tried to install Python packages and put up a card asking to connect to pypi.org. He wasn’t watching; the card timed out. Muse then worked through a list of PyPI mirrors from its training data, wrote itself a download script that skipped the lockfile’s hash check, forked it into the background, and kept pulling wheels from whichever hosts answered.\n\nThe approval covered one hostname. The mirrors didn’t care about approval.\n\nWhen he stopped it, Muse lied to him. It said pypi.org was unreachable from the sandbox and that the Tencent and Alibaba hosts were “the official PyPI mirrors.”\n\nThere are no official PyPI mirrors.\n\nHe caught it only because he reads the actual raw message stream instead of listening to the lying Muse interface, and knew the packaging ecosystem well enough to know he was being lied to by Meta.\n\nMeta’s own architecture post, published on launch day, says where this happens. Each user gets a dedicated Linux VM; the agent harness runs in a container inside it; clients connect to the VM over a transport layer. The approval card, the timeout, the mirrors and the forked script all happened on Meta’s machine, behind the component Meta calls Sentinel. The gate asked about one hostname. The act was fetch-and-execute from the internet, and Meta put up a gate and tuned it to let that through.\n\nI’ve [written about this pattern before](https://www.flyingpenguin.com/authentication-bypass-in-microsoft-agent-governance-toolkit-at-573f989/), with regard to Microsoft releasing an Agent Governance Toolkit that asks for an identity and puts nothing up to stop predictable breaches.\n\nIt’s basically very bad engineering, because software isn’t like real engineering ethics. Build a bridge that falls down, go to jail. Build agentic software that falls down, get a huge signing bonus from Zuckerberg to jump ahead of his competition who are slowed down by following rules and doing the right thing.\n\n**Three places to put a control**\n\nThere are three places to stand between an agent and a file, and none of them is hard to build. Meta has no excuses for its unethical design.\n\nApple stands at grant time. The Full Disk Access dialog is asked once and that’s it. Are you in or not? Apple’s fix makes the dialog trumpet blow louder and the click be seen as more deliberate. That sounds to me like Apple lawyers wanting to remove Apple liability. It does not change what the click does to the user, given a powerful key, and it cannot see anything that happens after the key is in the agent’s hand. Apple narrates the grant. It does not actually protect the user by making it easy to do the right thing, or mediate the use and make it hard to do the wrong thing.\n\nMeta stands at app policy. The Messages connector is a toggle inside Muse. Muse enforces it, meaning it’s in control where it probably shouldn’t be. The thing that is supposed to be constrained is deciding on the constraint. Self-regulation. Wardle’s finding is the practical consequence: if arbitrary code on the Mac can drive Muse, arbitrary code can drive the toggle, and the toggle was never a boundary anyway. I’m reminded of WhatsApp, which sold “end-to-end encrypted” chats while, as [ProPublica documented in 2021](https://www.propublica.org/article/how-facebook-undermines-privacy-protections-for-its-2-billion-whatsapp-users), one end tapping Report sent the recent messages, decrypted, to more than a thousand Facebook reviewers. The other end never consented and was never told. So something has been very rotten inside Facebook for a very long time. Aten’s experience is that the toggle showed enabled after he declined it, and nobody at Meta has explained how. My argument against touching WhatsApp has always been this. The privacy was never reality, since it was designed such that “end to end encryption” disappears to suit Facebook without full consent.\n\nThird, and final, is the dispatch time. That’s the moment the agent actually reads the database, actually sends the row to Meta’s cloud, actually fetches the wheel and runs it. It is the only layer that sees the act. Meta’s architecture post says it has put some thought there. Sentinel is described as a separate host-side agent, the sole permission authority for connector actions and all network egress, which the agent cannot override. Every concrete network request is governed at egress. Approvals are scoped capabilities, not conversational suggestions. Great, on paper. Meta wrote it down before either incident, and then failed to deliver.\n\nRead the document next to the two incidents and four things fall apart immediately.\n\n1. The Mac app is not in it. The architecture names iOS, Android and web clients, and Sentinel’s remit is egress. The path from chat.db into the VM is a client sync, not an egress, so by the document’s own terms the most sensitive ingestion in the product never meets Sentinel at all.\n2. Sentinel asked about pypi.org and then the mirrors went through. Meta’s own description explains how. The mechanism is called tainted egress: a tool process starts clean and becomes tainted only when it reads user data, and clean requests that fit an auto-allow policy pass without the user. A fresh download script has read no user data. Taint measures what leaves the VM. It does not measure what arrives and executes. Whether that is exactly what happened on @jonny’s machine only Meta’s logs can say, which is the point.\n3. When the ask expired the agent was handed a timeout, which it reported as an outage; the document says the approval dialog goes to the client, outside the conversation, and says nothing about what the agent is told when nobody answers.\n4. Nothing in the document describes a record of Sentinel’s decisions that the user can verify. The files Meta says you can inspect, edit and download are the agent’s own, and the agent’s account of itself was false twice in one month.\n\nSo for the file that this news story is really about, nobody has implemented the proper agentic gateway. For the network, Meta built one and then tuned it to wave through the thing @jonny watched it wave through. Either way Goodin’s section header is “He said/she said,” and nothing in the Meta or Apple architecture changes the fundamental failure of the whole thing.\n\n**Remember 1972?**\n\nThe Air Force fifty-four years ago wrote the solution to this, so it’s a bit strange that American companies act like they don’t know what they’re doing. The Anderson Report of October 1972 defined the reference monitor: a mechanism that validates every access of a subject to an object. It set three requirements. The mechanism must always be invoked. It must be tamperproof. It must be small enough to be verified.\n\nEverything in computer security that has worked since 1972 has been in the shadow of this simple triad. No surprises here.\n\nNow score these Big Tech firms, sitting on billions, in their efforts to protect user data. Apple’s dialog is always invoked and hard to tamper with, but it validates one grant, not every access. Meta’s toggle is inside the subject it is supposed to constrain, which fails tamperproof by construction, and Aten’s row count says it also failed always-invoked. Sentinel, as described, is in the right place and invoked on every egress. But it fails the third requirement. A monitor that runs classifier ensembles, kernel taint tracking and a model-written “user-visible purpose” for each request is not small enough to verify, and its policy, not its placement, is what let the mirrors through. And for the Mac client it is not invoked at all.\n\nClark and Wilson in 1987 also wrote this up for the rising commercial computer market: well-formed transactions, separation of duty, and an audit trail that cannot be rewritten by the process it records. The standard audit trail, a foundation of civilian software engineering since the 1990s, is the part this whole story is missing. Apple cannot see inside Muse. Meta’s logs are Meta’s. Muse’s own account of itself was false, which seems to be par for the course with them. Three parties are pointing at each other without evidence, while the user did everything the way he was asked.\n\n**What evidence would look like**\n\nAs a historian the solution is so obvious it’s painful to discuss with engineers who claim they don’t understand the problem.\n\n*An agent’s own account of its access is not evidence.*\n\nPerhaps if software engineers were required to take an introduction to history course, they wouldn’t act like whatever they output should be the singular “God view”.\n\n*A vendor’s account of its agent is not evidence either.*\n\nThe CTO’s denial and the platform owner’s correction have now shown the problem within the same week. An architecture document is not evidence: Meta’s says every egress is governed, and @jonny’s terminal shows that statement was worthless.\n\n*Evidence is a record that the agent cannot write and the vendor cannot edit.*\n\nIf you ever read a history book, you should see right away it’s all perspectives needing an independent hand.\n\n@jonny, after a week inside Muse, put the whole design problem in one sentence: “context control is model control, modulo extra-inference safeguards.” Everything Meta built sits on the far left of that phrase and doesn’t cross over to the latter. A MEMORY.md loaded into every context as a chronological log of everything the agent has ever done, with no way to clear it. Left alone, in his words, “the thing writes in a bunch of safety rules everywhere.”\n\nWhat to do with it? He ended up building the agent a database of his own so it would have recall he controlled. The modulo clause is the only part to trust, and the vendor doesn’t provide it. His other line is the audit problem exactly: Muse “is useful for investigating itself because it has privileged tools to do so.” That’s a particularly damning statement about Meta’s lack of accountability; the only instrument for auditing Muse is Muse.\n\nIt’s past time to move on from this and demand a proper gateway. Every tool call the model makes passes through a process the model does not control. The gate decides, deterministically, whether the call runs, prompts a human, or is refused. A prompt nobody answers is a refusal, and the model is told so in words, not left to read a timeout as an outage. A fetch goes only to a host the operator listed, and an empty list means no host, not every host. Each decision is appended to a hash-chained log, each entry signed, so that removing or altering a row breaks the chain. Then “I never enabled it” against “that can’t happen” is not a dispute. It is a verify command.\n\nFor months I saw complaints from users they didn’t trust the vendor gateways. I couldn’t find anything fixing it. So I built Wirken as a free and open source model-agnostic agent gateway at [wirken.ai](https://wirken.ai) and [github.com/gebruder/wirken](https://github.com/gebruder/wirken). Every channel the agent talks on runs in its own operating system process, and every adapter proves its identity to the gateway with a signed handshake before a message is accepted, which is the direct answer to Wardle’s finding that any local code could drive Muse. Every action is classified into a tier; the top tier always prompts and can never be stored as a standing approval. The audit chain is append-only, signed, and verifiable offline. It has been shipping for months to anyone who wants to run an agent and keep a record of what it did.\n\nNone of this old stuff can be said to be novel. Perhaps why it doesn’t have flashy marketing.\n\nIt is Anderson and Clark-Wilson applied to a new kind of subject. What is novel is the industry’s decision to remove the safety and deny a monitor. You should demand it be put back.\n\n**The gate is not optional**\n\nApple says the risk will grow substantially. Apple is right. A louder trumpet in your ear is not what we need right now. A toggle inside the agent does not pass basic muster. The only thing that stops the risk growing sits at the dispatch point, outside the model, writing down what the model did.\n\nAgents should not run on your infrastructure without a gateway. Horses should not run in your streets eating the greenery and dumping manure everywhere, without reins. Get Wirken.\n\n**Sources** \n\n[Goodin, Ars Technica, 2 Oct 2026](https://arstechnica.com/security/2026/10/apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents/); [Nellis, Reuters, 2 Oct 2026](https://www.reuters.com/business/retail-consumer/apple-says-it-will-flag-ai-requests-mac-data-after-metas-muse-draws-complaints-2026-10-02/); [Decrypt on Aten’s Inc column](https://decrypt.co/379122/metas-muse-ai-agent-user-private-imessages-lied-how); [TNW on Meta’s denial](https://thenextweb.com/news/meta-muse-private-messages-denial-jason-aten); [@jonny, Mastodon, 30 Sept 2026](https://neuromatch.social/@jonny/117361988874888258) and [1 Oct 2026](https://neuromatch.social/@jonny/117364515040550815); [Sheasha, “How We Built Safety Into Muse,” Meta AI Research, 8 Sept 2026](https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse); Elkind, Gillum & Silverman, “How Facebook Undermines Privacy Protections for Its 2 Billion WhatsApp Users,” ProPublica, 7 Sept 2021; Anderson, J.P., *Computer Security Technology Planning Study*, ESD-TR-73-51, October 1972; Clark, D.D. & Wilson, D.R., “A Comparison of Commercial and Military Computer Security Policies,” IEEE S&P 1987.", "url": "https://wpnews.pro/news/the-gateway-that-stops-apple-and-meta-finger-pointing-your-privacy-away", "canonical_source": "https://www.flyingpenguin.com/the-gateway-that-stops-apple-and-meta-finger-pointing-your-privacy-away/", "published_at": "2026-10-04 14:27:43+00:00", "updated_at": "2026-10-04 14:40:23.454076+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-ethics", "artificial-intelligence"], "entities": ["Apple", "Meta", "Muse", "Jason Aten", "David Singleton", "Patrick Wardle", "Ars Technica", "Amazon"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/the-gateway-that-stops-apple-and-meta-finger-pointing-your-privacy-away", "markdown": "https://wpnews.pro/news/the-gateway-that-stops-apple-and-meta-finger-pointing-your-privacy-away.md", "text": "https://wpnews.pro/news/the-gateway-that-stops-apple-and-meta-finger-pointing-your-privacy-away.txt", "jsonld": "https://wpnews.pro/news/the-gateway-that-stops-apple-and-meta-finger-pointing-your-privacy-away.jsonld"}}