在一名记者声称 Meta 旗下的 Mac 版 Muse 应用读取了其私人消息几天后——Meta 对这一说法提出异议——苹果宣布,将围绕 macOS 中一项名为“完整磁盘访问权限”的设置推出更多控制措施。苹果表示,这项功能最初是为了让备份正常运转而设计的,但人工智能代理如今增加了“与这一访问权限级别相关的风险”。
Days after a journalist claimed that Meta’s Muse app on Mac read their private messages — a claim that Meta disputed — Apple announced that it’s introducing additional controls around a setting called “Full Disk Access” on macOS. The feature was designed to allow backups to function properly, but AI agents have now increased “the risks associated with this level of access,” Apple said.
就在苹果发表声明前不久,《Inc.》专栏作家 Jason Aten 报道称,Muse 知道其私人消息的内容——尽管他声称并未向该人工智能代理授予相关权限。这篇报道引发了人们对桌面人工智能安全性与可信度的疑问:这类人工智能可以操控用户系统中的内容,并读取其文件和消息。
Apple’s statement comes shortly after Inc. columnist Jason Aten reported that Muse knew the content of his private messages — even though he claimed to have not given the AI agent permission. The report raised questions about the level of security and trust users have in desktop-based AI, which can control things on their systems and read their files and messages.
限制 Mac 版这项功能的决定,也发生在 Wired 一篇报道援引称 ChatGPT 的 Mac 应用存在漏洞、可能允许黑客访问敏感数据之后。
The decision to limit the Mac feature also comes after a Wired report cited that a flaw in ChatGPT’s Mac app could have allowed hackers to access sensitive data.
运行在桌面上的人工智能代理允许用户通过调整 macOS 设置,让相应的应用能够更广泛地访问其电脑中的文件、消息和其他个人内容。
AI agents that run on the desktop allow users to provide their respective apps with greater access to the files, messages, and other personal content on their computers by adjusting macOS settings.
在 Muse 中,用户可以选择是否为该人工智能代理启用“完整磁盘访问权限”。苹果解释道,这项设置会授予应用访问文件、邮件、消息乃至浏览历史的权限。
In Muse’s case, the AI optionally allows users to enable Full Disk Access. This setting, Apple explains, gives an app permission to access files, mail, messages, and even browsing history.
“一些开发者正在以可能让用户面临风险的方式使用‘完整磁盘访问权限’,从而在用户并不完全知情和理解的情况下,暴露其系统中的一切……”苹果在一篇面向开发者的新博客文章中说道。
“Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems…without users’ full knowledge and understanding,” Apple said in a new blog post aimed at developers.
该公司表示,今后将推出新的控制措施,旨在确保只有真正希望向应用授予如此高访问权限的用户,才能通过“非常明确的用户操作”完成授权。苹果公司写道:“解决这一问题至关重要。随着人工智能智能体日益强大且自主,与这种访问权限相关的问题将大幅增加。我们致力于确保用户在授予此类权限前清楚了解相关风险,从而能够就自己的数据和隐私作出明智决定。”
The company says that, going forward, it will introduce new controls aimed at ensuring that users who “genuinely wish to grant an app this extraordinary level of access” can do so only with “very explicit user action.”“Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy,” Apple wrote.
对于这项功能变更,苹果公司未回应 TechCrunch 的置评请求。
Apple did not respond to TechCrunch’s inquiry about the feature change.