HN in RSCserver-reason-react
top.mdnew.mdbest.mdask.mdshow.mdjobs.md
← Back to stories

Meta’s Muse is an adorable privacy and security dumpster fire

379 pointsby beardyw 1 day ago271 comments

Discussion

Loading discussion
  • whycome · 23 hours ago

    It’s interesting that the only ads I’ve seen for Muse don’t mention meta at all.

    • nervai · 22 hours ago

      if you go on meta.com there is not a single mention of Facebook or Instagram anywhere in sight, and those are their leading products and money makers... the company's brands are toxic and they know it.

  • coliveira · 23 hours ago

    And it's all by design, Meta and its founder have a long history of releasing products with security "flaws" that are immediately used by them to collect vast amounts of information about their victims.

  • jeanpah · 23 hours ago

    Again? This seems very intentional at this point

    • reactordev · 23 hours ago

      It’s 100% intentional, go look back at what they did with the Facebook app.

    • piva00 · 23 hours ago

      It's always very intentional, especially with Meta/Facebook. That's their whole modus operandi, a privacy nightmare which will feed their infinite money machine. Reading "Careless People" didn't make me surprised at all on how the company operates, it surprised me with the personal descriptions of how people like Mark Zuckerberg and Sherryl Sandberg actually are as humans. It scared me how most people at that level of wealth and power isn't too different from the accounts in the book, they're all seriously deranged people with a gigantic lever to impose their distorted realities upon the rest of humanity.

  • jagermo · 23 hours ago

    I get the appeal of agents, I do. This is the future stuff we always wanted. But I cannot get myself to give one of these things access to my bank account or allow it to do price comparsion and shopping without oversight. Or access to my email or chat history. I just do not trust any of them, not with my money or with access to my conversations.

    • reactordev · 23 hours ago

      I’m in the same boat. After witnessing context rot and inference collapse, I do not trust any LLM with mission critical work. Not Jev, not grok, not fable, not Opus.

      • ctkhn · 22 hours ago

        What extent does that happen for you? I have got very good results with self hosted qwen3.8 flash next at q4 and even with qwen3.635b on a laptop. I don't keep it running forever on every single repo, its ok to leave notes in agents.md and let it search that instead of the entire history staying in context.

        • reactordev · 22 hours ago

          I’m not talking coding agents. More so agent harnesses and using LLMs for decision making

        • cowboylowrez · 22 hours ago

          heh I got a completely stupid error from gemini about some apache configs, when I pointed it out, the llm apologised, said the line(s?) should look like this, then posted the same two lines uneditted haha

        • Aurornis · 22 hours ago

          The Qwen models, especially when quantized, can be really bad about just trying things and seeing what works. If you’re not watching all the tool calls you may not see it, but it’s kind of scary to watch them just bump into wrong decisions and backtrack. They also have a bad habit of accidentally building URLs that hit Alibaba infrastructure, likely because their training environment had them use those URLs. If you haven’t watched the outgoing network requests you might be very surprised at what your Qwen agents do sometimes.

          • julianlam · 19 hours ago

            > [Humans] can be really bad about just trying things and seeing what works. If you’re not watching all the tool calls you may not see it, but it’s kind of scary to watch them just bump into wrong decisions and backtrack.

    • ehe12 · 23 hours ago

      Personally to me this feels like another classic case of starting with the technology and figuring out where to sell it as opposed to the customer experience. It feels and seems too forced.

    • charliebwrites · 23 hours ago

      The missing piece for connecting an agent to your credit card or other financials is financial liability. If Meta/OpenAI/etc would guarantee they’d compensate you in full for anything that wasn’t supposed to happen —and had an established track record of doing so— it would make trusting agents to make financial choices easier

      • ehe12 · 23 hours ago

        “ If Meta/OpenAI/etc would guarantee they’d compensate you in full for anything that wasn’t supposed to happen —and had an established track record of doing so— it would make trusting agents to make financial choices easier” lol… talk about delusion.

      • beardyw · 21 hours ago

        First you would need to establish some sort of interaction. Probably with the same AI that spaffed your cash.

      • ls612 · 19 hours ago

        I think the solution is instead to require purchases to hit a hard harness restriction, so you must click yes for money to be spent.

      • proggy · 18 hours ago

        Assuming financial liability is an option, but because the risk profile of having an agent making purchases for a cardholder will never be zero, the companies making these guarantees will simply price the risk in to the cost of service. It’s the same basic mechanic at work with credit card reward points, the brands are all fighting each other for a share of customer debt so they slowly increase the rewards rates to one-up each other, and make up the cost on the back end by increasing merchant fees. It’s a dumb, unnecessary price war that ultimately increases the cost to the consumer and drives up the profits of the businesses providing risk/cost-burdened services.

    • the_snooze · 23 hours ago

      What AI boosters don't realize is that we're not in the optimistic days of the 1990s anymore. We've seen that the prevailing tech business model is to offer convenience as a lure to lock in dependent users and extract value from them. Unless these AI assistants are running on self-managed platforms independent of their developers, all I see is immense counterparty risk.

      • pelotron · 22 hours ago

        Absolutely. If you need any signal to know where Big Tech's head is at, just look at how quickly they became arms dealers.

        • watwut · 22 hours ago

          Big Tech's head is at "being evil is just being competent", "democracy is incompatible with freedom" (for me to do what I want). It is also at "humans are obsolete" point. And while Zuckenberg specifically does not have cool quotes, he was at the "who cares about genocide" and "let show weight loss ads to teenagers who we determined have low self-esteem" points in the past. Notes: actual quote is "If you're evil, you're at least competent. And if you're evil, you're not bad. And therefore, maybe you're actually kind of good because you're at least getting something done"

          • edot · 22 hours ago

            Quote was from Thiel FYI. https://youtu.be/B7yl7fEHeKM?t=840

            • ZnerflBerp · 21 hours ago

              Actual Demon Thiel

          • TheOtherHobbes · 21 hours ago

            Impressive how every single statement is absolutely wrong.

            • Avicebron · 20 hours ago

              You mean wrong because you don't believe this is how they are acting (likely because you are financially secure enough not to notice - part of the problem) or what they believe is dangerous and malevolent or because it's also nonsensical, despite being dangerous and worthy of reproach?

              • multiplegeorges · 19 hours ago

                No, more like: > If you're evil, you're at least competent. Incompetent evil exists. This statement is wrong, B does not follow A. > And if you're evil, you're not bad. They aren't mutually exclusive, so this is incorrect. > And therefore, maybe you're actually kind of good because you're at least getting something done This presupposes that "getting something done" is a positive end in itself, which is not a given. Each phrase is wrong. It's impressive, actually.

                • kkarakk · 6 hours ago

                  i think it was a bad analogy. he was talking about competent evil for eg ai enhanced weapons systems vs incompetent evil for eg middle easterners stoning people coz of religion. both are evil but you can rationalise competent evil coz you're getting something real done like preventing the upending of the moral world order.

                  • watwut · 3 hours ago

                    You're getting something real done like destroying moral world order, turning the western world into feudal techno fascist system. Which is his actual goal he stated multiple times. Considering weirdness of Thiel believes, his praise and support for actual atrocities, including actually in middle east, trying contrast him with violent religious fanatics is weird. They dont contrast, they have notable similarities.

          • antonvs · 20 hours ago

            Weird that Thiel seems to think the “Antichrist” is a bad thing, given that quote. I suppose he sees it as unwelcome competition.

      • Aurornis · 22 hours ago

        > What AI boosters don't realize is that we're not in the optimistic days of the 1990s anymore. Comments like this are in a different reality than most consumers. Most consumers don’t care about things like avoiding lock in to a platform. If the platform solves their problem then they don’t have any reason to leave it anyway. They’re not worried if their data is used to show them more targeted ads. Topics like this show a sharp divergence between what you read on Hacker News and how actual users operate. We already knew that people who don’t trust Facebook aren’t going to suddenly start using Muse. They were never going to consider it. For the people who do actually use Meta products, which is a customer base counted in the billions, many will not have any problem using these tools.

        • ctrl-alt-zen · 22 hours ago

          I see a lot of validity in your reply, but I think there is still nuance in how these priorities are expressed. How would you compare this issue to the Flock backlash, for example?

          • SpicyLemonZest · 21 hours ago

            I think most people draw a strong distinction between privacy violations that are done "to them" and privacy issues with things they've chosen to use, even if they're quite similar from a technological perspective. I'd bet a lot of anti-Flock people have location sharing enabled on their phone.

            • monocularvision · 20 hours ago

              And there is a very American anti-government aspect to it as well.

        • balder1991 · 22 hours ago

          This is only true as long as they don’t think about the future or do risk management.

        • klik99 · 21 hours ago

          I asked my wife to not share any info with Muse and she said “Well they know everything already”. Well I was able to convince her not to with some stories about hallucinations of agents getting things horribly wrong as agents in the past, because the privacy concerns just didn’t phase her. Shes even more aware than most people since I’m very privacy aware. 100% it’s very echo chambery to claim that it’s not 1990 anymore. It’s like a historian saying that history won’t repeat itself because we all know what happened last time

          • lrvick · 21 hours ago

            My wife and I do not even allow Meta Apple and Google products or proprietary software in our home (unless owned by guests) because they are all predatory and endless alternatives exist.

            • bookofjoe · 20 hours ago

              Do you allow guests to use their Meta Apple and Google products in your home?

              • lrvick · 19 hours ago

                Begrudgingly if for short periods of time, on a dedicated wifi network, but if they are visiting my home I encourage them to interact with me and others instead of doom scrolling. Try as I might some are so addicted and gone now that they just come over, doom scroll for a few hours, and leave. Maybe they feel like they get something out of just being in the same room as other people. It confuses me, but I will not force my views on guests.

            • trollbridge · 20 hours ago

              What software / hardware do you use? How do you get around binary firmware blobs?

              • lrvick · 20 hours ago

                I use Linux and maintain my own Linux distribution. All software I directly touch and rely on is Open Source and does not spy on me. I do not own or use a smartphone. I do however permit the use of proprietary software for purely entertainment use cases, such as video games, but never for a -tool- that I use to do my job or live my life. I even have a Talos workstation. Open hardware motherboard and open spec CPU both made in the US with fully open hardware. Also a Precursor which is similarly open. I support these efforts as much as I financially can, but I admit open firmware/hardware is not a gap I have fully closed day to day. Yet. Deep down in some hardware is firmware I do not control, such as on the inside of my AMD GPUs. But I wallet-vote for those over Nvidia who require proprietary code in user space where it requires rights within my operating system.

                • latexr · 19 hours ago

                  > I do however permit the use of proprietary software for purely entertainment use cases, such as video games How do you isolate those from affecting the rest of your machine? Do you use a different machine for entertainment? A different account? Something else? I’m not judging or trying to catch you in some kind of gotcha, I’m interested in your setup in case the idea is something I could use myself.

                  • lrvick · 14 hours ago

                    All machines that can do things like play games are untrusted to the point I never even lock them. They are treated as game console.

                • joquarky · 16 hours ago

                  I sometimes consider going scorched earth, but then I realize doing so will leave a conspicuous void which may also limit my options in the future.

                • trollbridge · 15 hours ago

                  Hmm. The areas where I ran into a brick wall on this were firmware for SSDs and hard drives. Doesn’t exist in open source form.

                  • lrvick · 14 hours ago

                    True but if it is immutable it still meets the FSF definition of an appliance regarded as a closed hardware problem vs a closed software problem. Software Freedom means no one has more control of the hardware in front of you than you do. If no one can change the SSD firmware, then it is part of the hardware. Now for firmware that can be changed, that is a different story and maybe the OpenSSD project gets us there. We will see.

        • shimman · 21 hours ago

          Most consumers absolutely care, why do you think the biggest bipartisan issue is a massive national backlash against tech companies and a clear majority of workers being against LLM tools in the workplace? These types of comments just show what a massive bubble you're in.

          • consensus1 · 21 hours ago

            That backlash is based on conspiracy theories about data centers using up all the water and the legitimate fear of AI taking their jobs, not anything to do with privacy.

            • shimman · 21 hours ago

              No the backlash is based on very real decline of material concerns, please try to speak in reality and talk to other humans outside of VC.

              • DaSHacka · 20 hours ago

                That's been happening for the past almost exactly 60 years, AI had nothing to do with the majority of it.

          • DaSHacka · 20 hours ago

            > a clear majority of workers being against LLM tools in the workplace? > These types of comments just show what a massive bubble you're in. The fact you think it's a "clear majority" and not a "sizable, but still loud minority" of workers shows that you're in a bubble. The vast, vast, majority of people are largely apathetic to AI as a technology at large, with general techbro-sentiment trending very negative (for all technology, across the board), especially towards SV/AI figureheads .

        • otikik · 21 hours ago

          Well they will start caring when their teen with image issues starts getting targetted beauty ads[1], or when they get pregnant, want to abort, and get directed to an anti-abortion center instead[2], and afterwards they get served "abortion reversal pills" ads[3]. Or when they are hit by any other privacy fuckup like that. [1] https://futurism.com/facebook-beauty-targeted-ads [2] https://www.bbc.com/news/health-61320202 [3] https://tech.yahoo.com/general/articles/facebook-made-money-...

        • datsci_est_2015 · 21 hours ago

          Imagine we were talking about soda (or pop, or coke, or soft drink, depending on your dialect). Personally, I find it absolute insanity to be regularly consuming so much dissolved sugar especially during our ongoing obesity and digestive health epidemic. But, “most consumers” don’t care about that. The beverage industry is insanely profitable, especially with recent forays into “energy drinks”. Do people who drink so much dissolved sugar live without consequences? Absolutely not. They have a significantly lower quality of life and die much sooner than people who do not drink dissolved sugar. I don’t see your comment as a valid dismissal. Just one more way that individual outcomes in our society are increasingly K-shaped.

          • runarberg · 20 hours ago

            Another way to say this is that your parent may be suffering from lack of imagination. Stuff like this can (and should) be regulated. Consumer protection is a thing most jurisdictions do. In fact there are millions of possible markets which consumers would absolutely fall victims to, but government regulators prohibit it because of the harm it causes consumers. Government regulators can (and should) apply the same logic to AI, but they don‘t. There is not really a good reason why they don‘t other then some ideological movement towards ever greater neo-liberalism, deregulation, and laissez faire capitalism.

          • datsci_est_2015 · 18 hours ago

            Expanding on this thought (too late for an edit), there's a nice simile to be had: - technologists : software that is bad for privacy - nutritionists : food and drink that gives you diabetes So, I'm no nutritionist, but I pay attention enough to pay attention when they say I shouldn't drink a liter of Coke every day. As technologists, we should carry the torch and speak loud-and-wide about the dangers of software that is bad for privacy.

        • dawnerd · 20 hours ago

          Most consumers do not want or need agents which also shows how much of a bubble tech people are living in.

        • tmpz22 · 20 hours ago

          How do you explain the brand segmentation Facebook is doing with Muse? They're keeping the Meta / Facebook brand very far away from the Muse product. Doesn't that imply Meta itself believes users care?

        • EA-3167 · 19 hours ago

          If we’re talking about the average consumer, they’re increasingly hostile towards ML in general and Facebook in particular. The majority want the tech regulated stat, so you might want to think twice before appealing to the masses.

      • ai-x · 21 hours ago

        Me and 4 Billion happy users don't care. HN must understand that they are not a representative sample of anything.

        • lrvick · 21 hours ago

          Most of the planet refused to wash their hands or use basic sanitation until about 150 years ago even though they had clear reproducible evidence doing so saved countless lives 50 years earlier. Most just considered doing the bare minimum to save lives as too much work. Also we used to advertise cigarettes and alcohol for consumption by babies in the 50s. It is reasonable to assume the majority of humans are intellectually lazy to the point of killing themselves and their families if told to with the right marketing. We should all make our own individual well researched choices and not ever buy into the worthless argument of "everyone does it".

          • ai-x · 20 hours ago

            False analogies won't make your case. There are plenty of happy, successful people who didn't die because they used a Meta product. In fact I'd even argue that all things equal, a Meta user is happier than a paranoid-meta-hater who worries every minute that someone is going to serve them an Ad that fits them "oh, the horror!!!. How am I ever going to recover from the trauma and financial ruin of seeing a targeted ad."

            • mrtesthah · 20 hours ago

              > successful people who didn't die Did you just move the goalposts to “it didn’t kill me”? We’re talking about society-wide effects here, including harm to children for which Facebook is paying 17 billion dollars. https://oag.dc.gov/release/attorney-general-schwalb-announce...

              • warkdarrior · 20 hours ago

                And those children are $17B richer today.

                • lrvick · 19 hours ago

                  The ones that did not commit suicide get a tiny tiny fraction of that, yes. Your comment implies no harm matters so long as people can sue for it later?

              • ai-x · 18 hours ago

                For a supposedly science-based cohort we aren't using any science aren't we? There is ZERO proven causality between social media usage (specifically Meta products) and long-term happiness of a person. All the social science are spurious correlations that can be attributed to anything (including higher education where hysteria about the modern world reins) As far as $17B settlement, it has nothing to do with causality. It's just some $$$ set aside for Meta to remove operational headaches. I could even say Meta-haters make more irrational life decisions compared to normal people who just browse Instagram and use WhatsApp without paranoia

                • Apocryphon · 18 hours ago

                  Did you just accuse others of not being science-based, while casually handwaving studies away?

            • lrvick · 20 hours ago

              > There are plenty of happy, successful people who didn't die because they used a Meta product. And plenty of teens that never became happy and successful people because they used a Meta product. These companies are predatory, and have nothing to offer us we cannot easily setup at home these days with privacy and sovereignty.

              • ai-x · 18 hours ago

                [citation needed] Note: Unless you spin an alternative universe there is no way you can prove causality of social media usage => happiness/depression.

                • lrvick · 14 hours ago

                  Meta would not have paid out if they saw the evidence and thought they had a chance in hell at winning. But it is the undeniable opinion of most mental healthcare professionals that giving teens an endless stream of content about unattainable body images or suicide content... results in more suicides. Meta -knew- this and then fired the team that told them about it and doubled down on pressing the gas. They knowingly and substantially increased the chances of teen suicides for money. And people want to give these monsters -MORE- data and power? I cannot comprehend anyone defending this company still.

        • jagermo · 20 hours ago

          Not at all, if you are happy, go for it. I might look into something like hermes, that seems to fit my bill more.

      • m463 · 21 hours ago

        I read "the tesla files", a book about a whistleblower leaking a ton of internal tesla files. They were discussing how tesla manages problems with full-self-driving. It was interesting how this realm of problems was viewed. If there was an accident while the car was driving itself due to some glitch, the police at the scene put all the blame on the driver. The book had a different viewpoint. obviously there was a tesla bug in full self driving, and they kept their mouth shut. meanwhile society/government doesn't even think of this and puts responsibility/blame on the user.

      • __MatrixMan__ · 21 hours ago

        AI seems to be an amplifier for other problems that we never fixed, more than an authentic source of problems on its own. In this case it's amplifying that we never really trusted the cloud to begin with. We have a lot of deferred problems to go back and solve before all these dreams can come true.

      • cyanydeez · 21 hours ago

        I think WallE is the perfect reference for the world AI/oligarchy are running towards. Not whether it exists, but that' dependency+environmental destitution.

      • mistercheese · 8 hours ago

        I agree with this, but I’m wondering where these self managed platforms are for the average person who doesn’t want to spend hours fixing OpenClaw upgrades. Surely there has to be an easy to use Muse/Dots/GrokBot self hosted solution for the privacy conscious?

    • awepofiwaop · 23 hours ago

      Don't worry, I'm sure eventually you'll simply be required to give one of these things access to your bank account and that decision will be taken out of your hands.

      • malfist · 23 hours ago

        When that happens, I'm sure banks will lock out secure local models for "security reasons" like an unlocked phone.

    • ctkhn · 23 hours ago

      I see the value of the tool but I would never use it from Meta. Would need to be self hosted with a very structured framework and guardrails so that even my local model couldn't accidentally wire 50k to a Nigerian prince or whatever the latest email scam is.

      • shostack · 22 hours ago

        I see everybody freaking out about unfettered payment access to one's bank accounts and I keep wondering why people don't jump to the obvious solution of simply only giving it a single purpose or limited fund credit card number from privacy.com or something. Am I missing something with the concern about ability to constrain the blast radius?

        • SpicyLemonZest · 21 hours ago

          I would call that kind of thing "a very structured framework and guardrails". You'd have to come up with entirely different solutions if you want the agent to receive payments or monitor your budget.

      • Octoth0rpe · 21 hours ago

        Man, I wonder how many facebook marketplace sales will be something like "In order to make sure you're a real person, before we can meet up so I can hand over this brand new macbook for $500 I need you to send me $10 electronically. It's really just to verify your commitment". With the right prompting, I'd be entirely unsurprised if Muse will just send over the $10, and of course the seller ghosts the buyer -_-

        • chasd00 · 21 hours ago

          I've sold a few things on marketplace and have got some strange requests from buyers that i think are AI. I was selling a piece of exercise equipment that has a screen attached to it (rowing machine) and got a request to take a picture with a tape measure to verify the screen dimensions. The product is only sold with one screen size and it was plainly visible in the listing pictures too.

          • ctkhn · 18 hours ago

            That could be either lazy buyer or someone who's had a seller tell them wrong dimensions or wrong model for the item. Someone I know from college told me a couple years about how they lied to a buyer about the cheap wayfair furniture was actually part of a sample sale from a big name brand. I usually ask the seller for any info thats make or break for me, but I also reverse google image search the listing photos to make it easier for myself though.

          • jamiek88 · 17 hours ago

            Classic GPTism that. It often asks me to take pictures of things with a tape measure across it. Been using it to help with a refurb of an old cottage as kind of a super google for old fittings etc.

      • onel · 2 hours ago

        And I see this few becoming more common. May I ask what agent you see? Most likely good for self-hosting?

    • KetoManx64 · 22 hours ago

      You don't have to, there is a world of things you can do with them without giving them access to your email or bank account. "Hermes, clone this android app to my computer, add this and this feature and fix this annoyance and then rebuild it and push it to my phone" "Hermes summarize this YouTube podcast and push the summary and transcript to my Obsidian vault" "Hermes check mg obsidian notes for when I last wrote a blog article about Neovim's integration with AI agents" *Hermes, you have an API token that allows read only access to the Zabbix monitoring system, check that and then use the Proxmox API token that only allows you to do limited actions to reboot the VM that is having issues" Etc, etc,

      • shostack · 22 hours ago

        YouTube transcripts are increasingly if not completely blocked now. It used to be great to grab content from long tops. I did not have time to watch but wanted to learn about. Now. The only way to do it is to manually copy and paste the transcript information or use computer use. But I cannot easily do it on my VPS it seems unless I'm missing a trick.

        • mrkn1 · 21 hours ago

          You can transcribe in seconds on CPU for free. Check out yapsnap repo, its free and open source

        • KetoManx64 · 21 hours ago

          I just have Hermes download the video using yt-dlp and transcribe it with a local whisper model using a local whisper server if the transcript is not available through the API, whisper base models works fairly well on CPU only servers nowadays.

    • f6v · 22 hours ago

      My wife has scheduled a visit with a physician and there was a younger person in there. They legit said “haha I don’t know what it is” and used ChatGPT for diagnosis. I have no doubt they would have no problem outsourcing everything to agents.

      • leptons · 21 hours ago

        That's some Idiocracy level bullshit.

      • edmundsauto · 21 hours ago

        Did they reach a good diagnosis by using tools to provide themselves additional information to process? Or did they make a fatally wrong diagnosis that was only discovered because the old doctor whipped out their medical encyclopedias? You left us hanging without the relevant part of the story!

    • thenatureboy · 22 hours ago

      Sad to see such paranoia, agents can genuinely be an agent of good and positive change. Last night I had ChatGPT go through an old email account and surface memories that I literally forgot. People who I have fond memories of. Yea I could have spent time querying gmail and digging but the agent did it in a way that really resonated. I don't care if Sama has my emails now. I do care about connecting with my past and enjoying the memories of a time long past. Paranoid scolds of HN want the average person to be deprived of value like this for some reason.

      • SpicyLemonZest · 21 hours ago

        I affirmatively want that exact scenario not to happen, yes. I'm opposed to the automation of nostalgia, I don't think it's good nor positive.

      • tempfile · 21 hours ago

        > I don't care if Sama has my emails now. I am perfectly prepared to believe you had a nice interaction with the robot. But this is an insane thing to say!

        • phoghed · 21 hours ago

          My email is gigabytes of garbage and a few useful bits of information that are useful and have personal relevance to me. You personally, dear reader, could probably read all my emails and I wouldn’t give a shit. I just checked my sent mails for the last few years, it’s like 90% sending absence excuses to my kid’s school. Google already has it all, so I guess I could just wait for them to get off their ass and make a useful equivalent to Grok Bot and friends.

          • onel · 2 hours ago

            I think that's fair and not a problem if you feel comfortable sharing that. But I think what op wants to say is that not sharing your email should be the default state, and only giving that when you want to get value in return like in this case with your agent

      • Apocryphon · 18 hours ago

        Independently of the actual state of the art, and the social implications and everything, my main takeaway from Her was always the initial setup of Samantha (huh, now that's some eerie nominative coincidence), wherein the AI curates his email inbox. That is the mundane chore that's always been my dream AI use case. https://www.youtube.com/watch?v=f9Hg1x-Ctlw

    • gadders · 21 hours ago

      Yeah, just waiting for the AI-enshittification when they give it to the growth hackers to drive VC returns at the expense of utility.

    • liendolucas · 21 hours ago

      Sorry, no. This is not the future I wanted. I do not run any agents nor ever will. I find all this is just the next-gen privacy violation, disguised obviously as: "Oh, WOW an agent in the computer is doing all this for me". Bullshit. It seems that never is enough with these ever thirsty companies, they keep pushing the limits and surprinsingly a lot of people do not care at all nor value the implications of having an arbitrary process running and doing pretty much whatever the agenda of their creators are.

      • ncr100 · 21 hours ago

        This outcome is always likely/ predictable. We are an opportunistic species. We don't have perfect knowledge nor thoughtfulness. We need to protect each other. We don't.

    • chasd00 · 21 hours ago

      I made an agent to derive and iterate on a stock trading strategy for me. What I did was give it a virtual bank account that models your typical brokerage account. So my agent reads the news, financials, markets, all the information it can gather to decide what stocks to buy/sell and manage its portfolio. Then what I do is just follow along with real money. I could see shopping being the same way, let the agent shop for you or identify good deals on things you want but then push them to you to make the actual purchase. Like you, I'm certainly not going to let an agent make a real purchase for me unattended and I doubt any merchant is going to have much sympathy for "my AI bought this by mistake".

    • lrvick · 21 hours ago

      I trust mine considerable, but only because I can run it mostly offline on hardware I own that lives in my garage. It baffles me that I am the only technical person I know that exclusively uses AI this way.

      • diskzero · 21 hours ago

        I am a technical person and while I appreciate the challenge of buying the hardware, setting up the software stack and managing the system, I can't figure out any use cases that would justify the work. This is the main issue I have with Muse, Dots, etc. There just must be something about my routines that don't align with what these companies are expecting their users to do. I do take advantage of the investor subsidized coding agents, but it will take years of my usage of their services to come close to initial start up cost of my own system. I am very curious as to what other people of using these agents for? Some of the use cases I hear; comparative shopping, travel planning, etc. don't appeal to me. Our people using them to manage family life issues like school schedules, meetings, etc? I feel like I am missing out, but I also am not seeing the greater appeal yet.

        • lrvick · 20 hours ago

          Once you have a local agent you can actually trust is not sharing your conversations anywhere, you just use it like a really smart search engine, and your need to use a web browser mostly goes away. Some of my recent use cases... Help me find cheap flights and a hotel and plan some interesting sights to see because I am speaking at x conference on x date. Download all my favorite music from x streaming service as FLAC files locally, then convert them to OGG and put them on my portable music player. Download all my youtube subscriptions locally to this folder and strip out any ads or sponsored content. Here are a list of all the books I own. Can you find me DRM-free epub copies and put them on this e-reader for me? Here is a picture of an object next to a measuring tape. Can you 3d print me a holder perfectly sized for it based on a openscad file i can easily tweak? I am really stressed right now. Can you help me talk through everything I have to do and help me rationally prioritize? Can you remind me and keep me on track and be my fake boss for today? Can you look through my email and keep track of any appointments or invites so I stop missing meetings?

          • diskzero · 19 hours ago

            Thanks for the useful tasks. If I actually had your setup, I might do those things. Like you, I am not going to ask Meta, et al. to do those things. I also am hesitant to invest in setting up a new system. However, I do have a M2 Mac Studio, so maybe I am closer to being able to run a local system than I thought.

            • lrvick · 14 hours ago

              The cool part when you have a local decent model is you can ask it to write automations for you that you can review, and see what works for you. Can keep stacking new requirements. I mostly use jcode in part because of the self-dev mode where it edits its own rust code and restarts itself into new binaries seamlessly to give itself new features.

          • ineptech · 19 hours ago

            I follow the same approach (finding LLMs useful but only running open models on my own hardware) but I've been limited by also not letting them into my email and being pretty restrictive about their internet access. Would you mind sharing what stack and agent harness you use, since your other comments make it clear you're highly restrictive about what kinds of tech you run at home and I assume you vetted it thoroughly, and it sounds like it's working well? I'm wondering specifically about things like what kind of tool or restrictions you use on web browsing to avoid being flagged as a bot and how you guardrail access to your email (to avoid, say, the LLM deciding that "help me organize" includes telling people you want to reschedule). I use Qwen 3.8 26b at home and find it very useful for some tasks but when I think of using it as a general assistant rather than coding assistant, I keep thinking of times it has gone wildly wrong (e.g. it once spent 20 minutes trying to get around Supabase authentication because it couldn't figure why a certain call wasn't working)

            • lrvick · 14 hours ago

              My go to right now is jcode, and doing a lot of one-shot experiments. Like I have a session being my MPD DJ as my local spotify right now. That said for persistent things like interfacing with homeassistant etc I am playing with zeroclaw. I run the same model as you for coding. For more sane automation tasks i recommend doing everything possible with MPCs so you can tell it to only use existing tools. ymmv By no means is my setup well oiled yet. Different vms and systems doing different things. As a QubesOS user jailing an agent for one job to one VM is easy, though I am working on an enclave native operating system that should make this easier for most people.

        • onel · 2 hours ago

          Just dropping in to say that this is no longer that big of a problem. There are hosted solutions only for agents from DO, Nous, etc But also more generic self-hosting solutions, where you can host a lot of stuff and also agents, like moose I think as people realize that self-hosting is a good option. Good services will appear more

    • mrob · 21 hours ago

      >This is the future stuff we always wanted. Speak for yourself. I hated the idea of agents ever since I first heard of it back in the 90s or 00s. For me, the most valuable feature of computers is predictability. I want tools, not agents. A computer should augment my own skills, not replace them.

      • jagermo · 20 hours ago

        I mean, fair. I want something like the TNG Enterprise computer, that works for me within the parameters I set. That, for me, is cool.

      • chrisjj · 19 hours ago

        Pretend you have insifficient skill to satisfy your desires, even after augmentation. You are now dead center of the "AI" agent's target market.

    • JKCalhoun · 20 hours ago

      Now add Meta to the mix and stir.

    • trollbridge · 20 hours ago

      Muse is basically OpenClaw, with all the pros and cons. Except I really don’t trust Meta to get any of this right.

    • latexr · 19 hours ago

      > This is the future stuff we always wanted. > (…) > I just do not trust any of them So… Actually not the future stuff we wanted? That’s what bothers me when people say “we have the Star Trek computer”¹. We clearly don’t, because if we did we could trust it with a high degree of certainty. Instead what we have is a computer we must distrust to a high degree. One of the two crucial variables is flipped. ¹ I’m not saying you are saying that, but several people have expressed that sentiment on HN.

    • hbn · 18 hours ago

      > allow it to do price comparsion and shopping without oversight You can get it to do the price comparison part without having it do purchases. I downloaded Muse, told it to find me some underwear to buy, asked some questions to narrow the options down, then once I came to a decision I went and purchased it myself.

    • mv4 · 17 hours ago

      It's evident that agents still can't be trusted to transact on your behalf. Too many things can go wrong.

    • bunderbunder · 16 hours ago

      I just can’t even fathom it. LLMs have no judgment, and it’s still so easy to “trick” them. If you forced me to decide between granting the ability to conduct financial transactions on my behalf to an LLM agent, or to my family member with Lewy body dementia, I’d have to have a serious think about which one is less risky.

    • theptip · 12 hours ago

      The right model for this usecase is a virtual card with a fixed budget, these exist. I’m sure someone is going to lose their Robinhood account or savings but with due care this is avoidable.

    • onel · 2 hours ago

      And I think that's fair. On one side is their abilities, or lack thereof, but on the other side, it's the privacy implication with something like Muse. I think for the former we can wait for bethel model, have better skills or give them small enough tasks. But for the latter, the only solution is honestly just hosting your own agent and all this having access to the data it creates, what it runs and what it reads.

  • otikik · 23 hours ago

    Oh Meta not giving a damn about privacy and security? Say it ain't so.

    • netless · 22 hours ago

      been mostly using WhatsApp, should i be worried?

      • ryukoposting · 22 hours ago

        > should i be worried? The question implies you already are. But yes, obviously.

  • nekusar · 23 hours ago

    "People just submitted it. I don't know why. They 'trust me'. Dumb fucks." -Mark Zuckerberg

    • jagged-chisel · 22 hours ago

      They didn’t though. No trust involved. Hormones and emotions. Today’s version of the platform targets just the right emotions to keep users “engaged.”

  • alistairSH · 22 hours ago

    Are all of these just flavors of "the agent has the same permissions as the user"? Not that I want to trust Meta with anything, but I'm guessing it asked for "root" access and the users granted it...?

    • dcss_gardener · 22 hours ago

      Yes, it is clearly designed to give you access to all of this intentionally. Its system prompt (which you can just read in the interface without asking) explicitly instructs it to act on behalf of the user, not meta. All of its memory files, skills, db schema, memory integration system etc are likewise visible because they went out of their way to add an interface for viewing them! I don't like or trust meta any more than I always did but I don't see how they could have done a "better" job with this. These kinds of agents are inherently pretty risky IMO but I don't see how this one is particularly more than any others. Playing around with it I really don't get the sense there's any hidden prompt contradicting what's visible. It's nearly gleeful at using the VM in ways that were not intended and likely against meta's interests. I feel like someone must have won a really interesting internal power struggle to get this thing out in this form.

      • jkingsman · 21 hours ago

        > I really don't get the sense there's any hidden prompt contradicting what's visible It will happily disclose its entire system prompt (which is interesting in its own right, and worth a read) or pop a reverse shell for you > I don't see how they could have done a "better" job with this I generally agree -- the openness is great. However, from experiences both inside and outside of Meta, good execution, a hacker ethic, and transparency ultimately has very little propping it up when money is on the line. In fact, it could be argued that Meta has a shareholder obligation to do profitable things such that even the best intentions can (and usually will) fall in the face of corporate hierarchy and sales numbers. I think they did a pretty bang up job with Muse (the lack of communication with first-time agent users around how powerfully and confidently they can make horrifying mistakes, and how careful you need to be with prompting, and how even that sometimes isn't enough, notwithstanding). I also think it will inevitably be used to squeeze profit, and given Meta's history, I think it's almost comical to not assume that will involve violations of the spirit of privacy. (and that's assuming that a proliferation of "it deleted all my files" "it messaged my ex" "it leaked private info" doesn't poison consumer sentiment before it even gets off the ground)

        • dcss_gardener · 20 hours ago

          I agree with all of that 100% as well. As it is now is probably not how it will stay for exactly those reasons.

    • oofbey · 21 hours ago

      Probably. But also the agents are finding flaws in the security model. Also Meta is actively encouraging users to grant them full permission, insisting with all their marketing might that it’s safe, which they know is a complete lie. Hard to blame the user when they’re being actively deceived like this. Other agent companies are more reserved and say things like “be careful” but Meta is the opposite.

      • alistairSH · 21 hours ago

        I definitely didn't intend to blame the victims here, beyond trusting Meta in the first place. As for security models, it's probably long since time to sandbox all data and apps. More like mobile devices. Allow users to toggle that all off so they can use their computers for development etc, but the default state should force apps/tools to explicitly ask for permission to any folder, other app, API, CLI, etc. And ask for that permission regularly (or rather, reset the permission after some period of time). Or something like that (I haven't given it a great amount of thought).

        • luka2233 · 18 hours ago

          there are patterns like task-scoped authorization solutions that could help here but the integration would be tricky since Muse is not open source

      • judge2020 · 17 hours ago

        I mean, it's not that the data isn't safe (they at least have modern user-level data protection similar to the other tech giants), nor will the agent generally do stuff you don't tell it to do. But I'm sure their stance was less "let's ask for granular per-category access whenever the user actually needs it" and more product-driven "we want the agent to have all the data and context it needs to become a successful product that gets people hooked, so let's ask for full disk access".

        • alistairSH · 3 hours ago

          Many/most major companies have had various leaks. Plus it’s one more place for the government to go looking for stuff. So it might be safe in the sense that Bob can’t see Sally’s data. But it’s not safe in the sense that Meta shouldn’t have the data at all and can’t be trusted not to use it.

  • ChrisArchitect · 22 hours ago

    Since this is mostly a collection of links to previously discussed articles: Related: Updates to Full Disk Access in macOS https://news.ycombinator.com/item?id=49937631 Meta’s Muse has a serious 0-day https://news.ycombinator.com/item?id=49802030 Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions https://news.ycombinator.com/item?id=49893709 Maybe don't let Muse run your Facebook Marketplace account https://news.ycombinator.com/item?id=49875006 What Meta got right with Muse https://news.ycombinator.com/item?id=49946526 Muse – Meta’s personal AI agent https://news.ycombinator.com/item?id=49615537

  • sdcfgy · 22 hours ago

    Isn't that Meta's entire product line?

  • DebtDeflation · 22 hours ago

    >When one tech YouTuber put Muse in charge of their Facebook Marketplace sales, it sold his stuff way below acceptable rates Why are we depending on LLM "reasoning" to negotiate a price rather than just having the user enter a lowest acceptable price deterministically?

    • f6v · 22 hours ago

      Because a lowest acceptable price probably depends on doing research and making a decision.

    • Sharlin · 22 hours ago

      That would require thinking, and thinking is the thing everybody seems to want to outsource to LLMs.

    • augment_me · 21 hours ago

      It involves cognitive effort to set a good lowest acceptable price. We don't want that, we want to reduce this effort that's what the tools are for

    • ncr100 · 21 hours ago

      Because we are human. (As a human, it's more physically taxing to think, and less taxing to relax. Conserving internal resources improves our survival odds. So when an opportunity presents itself to use less effort and still gain out of that, we tend to take it.) As human technologists, I believe we need to protect humanity more. In everything that we do, we need to think about the ways that our proclivities as a species can be compromised by our development of technology.

  • arshxyz · 22 hours ago

    > Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages Can someone explain how this is possible? If an app can do this without Full Disk Access or a popup of some kind that's a way bigger lapse on Apple's part than Meta's.

    • etatester · 21 hours ago

      Reading the linked articles suggests that this is not possible, but Apple did acknowledge that the full-disk access grants you access to other apps (until the most recent update) Typical "leopards ate my face" moment. You give AI (from Meta, nonetheless) full-disk access and then complain that—wow—it really meant FULL. In a perfect world where you got nothing to hide, where companies don't sell your data and there are no hackers, even I would love to just hand all my data to Muse and have it be my trusted assistant. People who think we live in such a world are already doing that, evidently.

      • lapcat · 21 hours ago

        > Apple did acknowledge that the full-disk access grants you access to other apps (until the most recent update) There was no recent update. Apple's announcement was about a future macOS update.

    • laweijfmvo · 21 hours ago

      I saw a theory, just a theory, that it may have accessed the message via its notification preview, which I think was similarly used to leak Signal messages recently?

    • lapcat · 21 hours ago

      > Can someone explain how this is possible? It's not.

  • fridder · 22 hours ago

    This shouldn't be a surprise to anyone. Why would you trust Meta with privacy and security?

  • labrador · 22 hours ago

    I can finally relax and let a random number generator make my decisions for me

    • ncr100 · 21 hours ago

      This person gets it. It really is about trading off personal energy and internal resources for gain. It's almost survival level logic.

  • chadd · 22 hours ago

    It's very simple. There is ZERO chance the worlds biggest advertising companies will refrain, long-term, from using your most intimate secrets, gathered through your many conversations with their AI personal assistants, to sell you things.

    • jagged-chisel · 22 hours ago

      Or to otherwise coerce you into whatever funnel that makes them money

      • NBJack · 21 hours ago

        "That sounds like a tough problem in your relationship right now. Would you like me to order another Crave cookie for you? There's a special right now on free delivery. What about renewing your subscription to aitherapynow.com?"

        • jagged-chisel · 21 hours ago

          More like “I have placed an order for which you have saved on delivery fees. Your aitherapynow.com subscription has been renewed and I will transfer you to the therapist momentarily. Just a note: your charges have resulted in using your free overdraft protection on your Chime® by Chase® from Goldman® with Fidelity® debit account - remember interest charges start in 29 days.”

    • airstrafer · 22 hours ago

      I agree with this but also think it is a first order consequence. This level of unfettered access to your personality, lifestyle, and secrets allows for an unprecedented kind of manipulation and control. You could see it as a new kind of wealth transfer: not only will They sell you things, They will subtly manipulate behaviors of the masses via trusted agents.

      • phoghed · 21 hours ago

        Brother the biggest ad companies already own the platforms most people use for their communications. For over half the world they are the browser, the OS, the TV, the messaging platform, the map, etc. I think to the vast majority of people having one of these companies run an agent platform is going to be business as usual.

        • airstrafer · 17 hours ago

          No disagreement here lol. E.g. Target knows you are pregnant before you do [1]. That being said I think AIs are a whole new level of invasiveness because people tend to trust them like a human. Here’s a prediction: the true AI moat will be owning the “AI friends” of the masses: a trusted coworker, therapist, personal music artist, or even just something to talk to. The moat comes from the fact that these “friends” will deeply understand the user and the users will want to “take them along” with their entire life (they’re useful!). So people will get “locked in” to their AI “team” which is only available via one of the major AI labs. And in turn, the AI labs parasitically will understand everything about the way you live and think at a level that traditional ad trackers could only dream of. Sama has alluded to this in interviews for a long time. He stated a year ago [2]: > The way that I think of it is that most people will want to have one AI service, and that needs to be useful to them across their whole life. And so you’ll use ChatGPT, but you’ll want it to be integrated with other services and so you need to have other apps inside of ChatGPT. We need to have an API business, because you will want to be able to sign in with OpenAI into some service that someone else has built, and you’ll want the kind of continuity of experience and you’ll want it to still know you and have your stuff and know what to share and what not to share. So we want to build this AI helper for people and that’s going to have to — there’s a few pieces that have to fit into that. [1] https://www.nytimes.com/2012/02/19/magazine/shopping-habits.... [2] https://stratechery.com/2025/an-interview-with-openai-ceo-sa...

        • joquarky · 16 hours ago

          They may have a lot of data on people, but they seem to have trouble using it effectively. Why do they send me ads that seem like I am assigned to random demographics if they know everything about me?

    • winrid · 21 hours ago

      "I've gone ahead and placed an order based on your Google doc Daily Diary "Bad Dragon" entry."

    • piyuv · 21 hours ago

      “to sell you things” -> to manipulate you Let’s not forget Facebook caused a genocide

    • ncr100 · 21 hours ago

      In your locality, do you know if there are any upcoming votes/ laws or politicians who are realistically working to preserve your privacy, in these regards? In mine, I don't. That seems like an oversight/ opportunity.

    • rurp · 15 hours ago

      Agreed, it's surprising to me how often I see people on HN and other tech communities who don't assume every big tech AI product will get aggressively enshittified over time. It's a surprise to me because these same communities universally agree that the last era of big tech products has been ruined by greed and abuse. Products like Facebook and Google search were magical in their early days, but over the past couple decades they have been relentlessly and deliberately degraded into useless slop. The people who made all of those unfortunate decisions are the exact same people building and funding AI! What do you think they are going to do with more powerful Skinner boxes? Help the masses live their best, most empowered lives?!

    • davvie · 8 hours ago

      Yep, at this point nothing they say makes me believe otherwise

    • onel · 2 hours ago

      Yeah I also believe that would be the case. The temptation is way too big. Mark also said that their monetization might be related to selling stuff: them getting a cut when you buy something through your agent. Which kind of poisons a bit the recommendation you might get from it. Muse might be biased towards products or services where it gets a cut.

  • matltc · 22 hours ago

    Couldn't pay me to use this junk. Trying to think of a number that I would consider it, and honestly $1k/month wouldn't convince me unless - I have root on device - device is on its own vlan, fully segmented - !(SIM || 5G antenna) - no google/apple id authenticated on device - terminate agreement at any time without cost I'm probably forgetting/not aware of ten things I should consider.

    • DaSHacka · 20 hours ago

      Ironically it already satisfies all of those conditions because it runs in a VM on Meta's servers as root, where it'll happily let you install whatever you want inside the VM, including a custom remote access tool to let you logon as the root user inside it.

  • Razengan · 21 hours ago

    Does anyone remotely interested in AI use Muse out of explicit choice? Facebook is like Microsoft at this point: The thing your grandparents use. Even if they make something technically superior for a while, like what the Zune was to the iPad, tHey'll never really be cool. and they'll certainly never be trusted.

    • shepherdjerred · 20 hours ago

      Muse is a decent model at a VERY low price The Muse app is very polished and it seems to actually be popular with younger people. I have tried it out but I’m still struggling with use cases, same problem I had with OpenClaw

      • tmpz22 · 20 hours ago

        Surely that price is being subsidized at launch though, and will ratchet up faster then even the Streaming services currently are?

  • measurablefunc · 21 hours ago

    Every social media & AI company is also a surveillance company. Targeted advertising doesn't work w/o mountains of behavioral data aggregated across all of Meta's & Google's software "products".

  • piazz · 21 hours ago

    I’m pretty frustrated with Muse and the last thing I want to be doing with my free time is defending Meta, but this is such clickbait. Point by point: > “OMG you can jailbreak it and get it to spill its VM” This is the whole point; any content on the VM is yours. It runs in an isolated sandboxed VM separate from stored credentials etc; this is effectively your own computer. You don’t have to trick it. > It collects dossiers on your contacts These are more text files that live on your private VM, alongside memory.md, etc. Do you want your secretary to forget every person you contact every day? > It accessed Messages without full disk access This whole story never made sense or was substantiated. Full disk access is an OS level security boundary; the user had to switch this on. > It sold some guys stuff for too cheap and gave out his address OK this one I basically believe, haha. Because this is the problem with Muse: the LLM is just too dumb to perform complex tasks effectively in many cases.

    • ralphington · 20 hours ago

      You just did the tech equivalent of "not to sound racist, but..."

    • moscoe · 20 hours ago

      Absolutely agree. So much feigned outrage in these articles (and HN comments) about the LLM models doing x. Yesterday everyone was all worked up about OpenAI generating an image with a signature on it. Caveat emptor. Don’t be an idiot. Grow up. Make informed decisions regarding your use of these products and take responsibility for those decisions.

      • JohnMakin · 20 hours ago

        > Caveat emptor. Don’t be an idiot. Grow up. Make informed decisions regarding your use of these products and take responsibility for those decisions. Feigned outrage, indeed. I don't think it's unreasonable to point out that Meta has been consistently predatory, reckless, and creepy with user data before, and that this is a very aggressive expansion of that. The old facebook booster retort of "if you don't like it, don't use it, take responsibility" or whatever is nonsense. You're in their system whether you use their product or not. Even if you somehow avoid their pervasive web-wide tracking, a single contact you know installing this thing and gobbling up all your correspondence with them can compromise your privacy choices, and that's well beyond your control, unless you seriously suggest I audit every single one of my contact's devices and browbeat them into using the privacy choices I prefer. Get real.

        • bigyabai · 19 hours ago

          > "if you don't like it, don't use it, take responsibility" or whatever is nonsense. Why? I don't use Meta products, and my life isn't substantially impacted or controlled by them. Explain to me why I need to lobby my OS developers to reign-in Meta, from my perspective. Why is my hands-off approach insufficient for teaching adults to make intelligent decisions? Facebook is unquestionably awful, but that's a regulatory issue. 90% of the people chiming-in with Facebook outrage aren't using Meta products; they are literally feigning surprise and outrage as someone that clearly knows better. Oftentimes, they oppose any regulation that would force Meta to reconcile their damages because it would also jeopardize other abusive monopolies like the App Store that they love to defend. So where does the buck actually stop? Does it ever? HN has done this for years. Years and years and years. "Meta is horrible! Stop them!" -> "New Meta product has ~10-100 million MAU" -> "We need private enterprises to limit Meta!" -> Stagnant status-quo where exploitation is rewarded. Things got this bad because of the pugilist, tribal attitudes that dominated tech discussions and steered people away from common-sense regulatory measures.

      • stephen_cagle · 20 hours ago

        My assumption is you clearly don't have vulnerable or elderly people in your life? I'm not as concerned about my ability to navigate these waters as I am about the people I care about.

      • slashdave · 18 hours ago

        > Make informed decisions regarding your use of these products They are mass marketed. The creators should do the upmost to ensure this and not pin blame on users.

      • givinguflac · 16 hours ago

        In this context, normal people will believe the marketing and trust meta, and caveat emptor is a cop-out at best. I can sell you a basket of bread, and it’s privacy-preserving bread, but it will also punch you in the face if you don’t read every bit of the agreement. No one reads the agreement, and that’s what Meta runs on, plus skirting the law in every way they can possibly get away with.

        • bigyabai · 16 hours ago

          In this context, Apple provided a feature that gives applications Full Disk Access. The journalist enabled it, and then had their face eaten by leopards after ignoring the warning. Take Meta out of the equation here; any agent with FDA can do the exact same thing. Claude, Codex, DeepSeek, any of them. This is why Apple's response is a fix to their own software. The fix is a mea-culpa, Apple would not have to patch their OS if it was behaving exactly the way they wanted it to. Apple and the journalist made the biggest mistakes here. Meta is a godawful company that should be regulated into the dirt until Zuck is left with nothing. Guess what? They're not to blame in this scenario, and your rabid attacks on lapcat (who is a reputable and generally impartial macOS developer) is unnecessarily hostile towards a perfectly normal observation. This brand of comment is so misleading, low-effort and harmful to good-faith discussion that I'm tempted to flag this whole thread for being founded on a misunderstanding. Your response has contributed to the derailing of this conversation by tribalist "Apple vs Meta" pundits who are drowning out a well-known and respected expert that has technically-salient architectural details to share. HN cannot foster intellectual gratification under these conditions.

    • cmiles74 · 19 hours ago

      I gotta' disagree on this one. Meta made claims that it was taking privacy seriously and it turns out, not so much. I do think they should be getting some pressure on that score.

      • jonplackett · 19 hours ago

        Anyone who believes meta are taking privacy seriously cannot have more than a handful of brain cells.

        • bdangubic · 19 hours ago

          handful is too many in this case

      • IshKebab · 19 hours ago

        > it turns out, not so much Why though? The comment you're replying to is explaining how the accusations of poor privacy are nonsense and you've just replied "I disagree because they have poor privacy". I mean I'm not going to hand over any data to Facebook if I can help it but it doesn't seem like there are any specific issues here.

      • piazz · 19 hours ago

        Okay, but what is the evidence to back up this assertion? My point is, at this time, there is none. There is no “it turns out”. Give them some time to screw up at least.

        • GeekyBear · 19 hours ago

          > Meta’s New Muse AI Agent Read My Private Messages. I Never Asked It To https://www.inc.com/jason-aten/metas-new-muse-ai-agent-read-...

          • lapcat · 19 hours ago

            Literally nobody has reproduced this. The Messages database is protected by macOS TCC. If Aten were correct, there would exist a macOS zero day vulnerability. The vastly more likely explanation is that Aten mindlessly gave Full Disk Access to Muse. And that appears to be Apple's assumption, based on Apple's newly published developer note.

            • cmiles74 · 19 hours ago

              Reading it over, it does seem like giving the app full disk access would be enough for it to read our messages. I mean, they are stored on disk somewhere.

              • lapcat · 18 hours ago

                Yes?

              • GeekyBear · 18 hours ago

                Exactly. Meta's claim that Muse would not read your messages without explicit permission was meaningless.

                • judge2020 · 17 hours ago

                  > Meta's claim that Muse would not read your messages without explicit permission was meaningless. But it was true and you still haven't refuted that Aten mindless clicked through and allowed Muse full disk access and/or the messages connector setting in the Muse app.

              • cloudfudge · 6 hours ago

                The real question is why you'd give an app full disk access if you didn't want it reading your files.

            • GeekyBear · 19 hours ago

              Apple's statement on the matter sure sounds like Meta has once again been caught with their hand in the cookie jar. > Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.

              • lapcat · 19 hours ago

                > Apple's statement on the matter sure sounds like Meta has once again been caught with their hand in the cookie jar. > > Some developers are using Full Disk Access in ways that could put users at risk In other words, Muse did have Full Disk Access. Jason Aten did grant Full Disk Access to Muse, despite his claims otherwise. If Aten did not grant Full Disk Access to Muse, then why would Apple even be talking about Full Disk Access? The point is that Aten apparently granted Full Disk Access absent-mindedly, so absent-mindedly that he won't even admit that he did it. This is why Apple is making changes to Full Disk Access to make it more obvious what's happening.

                • GeekyBear · 18 hours ago

                  > In other words, Muse did have Full Disk Access. Jason Aten did grant Full Disk Access to Muse, despite his claims otherwise. Perhaps you should do some reading on the matter? > Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges. One is full-disk access, a macOS system-level permission. The other is to enable a Messages connector setting in Muse. “The Messages integration in the Muse Mac app is opt in,” Singleton said. “Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.” Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame. https://arstechnica.com/security/2026/10/apple-changes-full-... Meta has a long history of not respecting boundaries once something is technically possible.

                  • lapcat · 18 hours ago

                    > Perhaps you should do some reading on the matter? Perhaps you should: https://lapcatsoftware.com/articles/2026/10/2.html > Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame. Indeed, and it looks like Aten absent-mindedly did all of this! > Meta has a long history of not respecting boundaries once something is technically possible. It's not technically possible for Muse to read the Messages db without Full Disk Access. Aten denies having given FDA to Muse. Thus, Aten is simply wrong, misremembering or something. And if he misremembers about FDA, he likely also misremembers about granting app-level permissions to Muse. Again, literally nobody has reproduced Aten's experience. Show me one other person. In fairness, Aten behaved just like many other users would, mindlessly granting permissions that an app requests. That's certainly a problem. Unfortunately, Aten stubbornly refuses to admit this, instead confusing the problem by suggesting technical impossibilities. Aten doesn't want to take any responsibility for his own actions.

                    • GeekyBear · 18 hours ago

                      > Indeed, and it looks like Aten absent-mindedly did all of this! Since Aten has clearly said he did not grant Muse the permission to read his messages (inside Muse), I'm not accepting your version of the events.

                      • lapcat · 18 hours ago

                        So you prefer to accept the version of events where Aten somehow stumbled upon a macOS security vulnerability that allows apps without Full Disk Access to read the Messages database, a vulnerability that nobody else has reproduced and that Apple itself apparently doesn't recognize? Just because one writer said so?

                        • cloudfudge · 17 hours ago

                          If what the writer said was strictly true, Apple would be having a little security freakout about how Muse managed to bypass this OS control. My assumption is that the writer did not understand everything he was granting it permission to do, so he legitimately believes that he didn't grant it those permissions. But he did.

                          • GeekyBear · 17 hours ago

                            Apple's statement is that the permission is being abused to do things that users do not think are possible. In this case, Meta explicitly promises that Muse will not read your messages even after you grant it disk permissions.

                            • lapcat · 15 hours ago

                              > In this case, Meta explicitly promises that Muse will not read your messages even after you grant it disk permissions. There's no reason to doubt this claim. The only person in the world who has claimed that Muse disrespects its own internal setting is the same person who claimed that he didn't grant Full Disk Access to Muse. Ironically, Aten's own screenshot appears to show that he toggled the internal setting from "Off" to "Read only". In my own testing, it's "Off" by default, and the only way to change the internal setting is to enable Full Disk Access first. Thus, the likeliest scenario is that Aten unthinkingly granted Full Disk Access to Muse, granted the Messages app permission, then had a change of heart, disabled Full Disk Access, and then forgot what he had done. Later, when he noticed that Muse had some of his messages, he went back and checked, and saw the FDA was disabled, forgetting that he had toggled it on and off.

                    • givinguflac · 16 hours ago

                      Lmfao you tell someone to read and then post your own opinionated blog post? I would reiterate that you need to read, perhaps outside your own bubble.