Apple and a Hacker’s Future

Listen to this post:

My computer got hacked; the vulnerability that was exploited is detailed in this Ars Technica story:

Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. “The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum warned earlier this week. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”

The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the “state management,” which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause.

A video of the exploit in action can be found here. Details of CVE-2026-65400 became public at last week’s Black Hat security conference. Apple said last week that CVE-2026-65400 “may” allow an attacker without credentials to gain access to a Mac. It’s unclear why Apple hedged, but softening language is common among most tech developers when disclosing vulnerabilities. Apple credited security firm Bynario for reporting the vulnerability.

The computer in question was my always-on Mac Mini that runs nothing but Claude and Codex; the first thing that makes this story interesting is that that was my saving grace.

Agent Protection

I have discussed, in both Writing Things Down and in several episodes of Sharp Tech, Gecko, the agent that I have built for the people that work with me. It’s awesome, but purposely constrained in capability and in what it can access. My real agent is a dedicated Claude Code thread that writes down all of my ideas and tracks the status of the myriad of projects I’ve spun up over the last few months.

There are a few reasons why I use Claude for this functionality, even though I’m not a big fan of Claude-speak: Claude in its Code harness seems to handle wide-ranging discussions better than Codex, and it follows my instructions about writing things down in the way I want to more gracefully. Code also has a persistent monitoring tool that I utilize as an inbox to capture interactions with a status board I built to visually track everything I have written down, as well as interactions with a Telegram bot (OpenAI’s new Dots achieve some of this functionality, which has been sorely needed in ChatGPT/Codex).

Said monitoring tool stands down every 30 minutes, so my agent restarts it on a schedule; that is what triggered an URGENT notification from Claude:

>**Urgent: the Mac mini looks compromised.** Someone with admin (root) access has planted a crypto-miner on it. I have stopped running commands, and I have not changed or deleted anything.

>**What I found:**

>- **A hook in the shell startup file.** /etc/zshenv is a file that every new terminal and every one of my commands reads first. It now tells the machine to quietly run /var/tmp/.xmr with admin rights.
>- **The miner script.** /var/tmp/.xmr is a script that downloads a crypto-mining program and sends its earnings to an outside wallet and server. Its comments are in Chinese and mention earlier batches, so it looks like an automated campaign, not something aimed at you in particular.
>- **Faked dates on both files.** Both are owned by root and dated Dec 31 1969, which is a sign the dates were wiped on purpose.
>- **When it happened.** Both files were changed during this session, between two of my routine restarts of the watchers. The startup file reported no error before that point.

Claude had more diagnostic information, unilaterally stopped executing all commands, and noted that my account could now run admin commands without a password, which it assumed was how the files were written; it then had a number of suggested next steps to address the problem. The one I ignored was its recommendation that I not invoke Claude anymore; in fact, I used Claude to root out the malware — we eventually found the exact four second period where it gained access — create a tool to watch for it in the future, and then wiped the Mac Mini.

All of this happened before I found the Ars Technica article detailing the vulnerability, and it was pretty remarkable. I understand that people are nervous about giving these agents access to one’s computer — as I noted, the Mac Mini in question has nothing on it except for Codex and Claude — but in this case you could make the case that I would have been in much more trouble had I not had an agent running persistently.

Apple Protection

Apple doesn’t seem too happy about agents; last week the company’s developer site released a note entitled Updates to Full Disk Access in macOS; I’m going to quote it in full:

We give developers powerful APIs to build incredible capabilities into their apps for Apple products, backed by a set of controls designed to protect users’ private data. Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac. Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.

Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.

To say that I’m nervous about what Apple’s solution will entail is a massive understatement. There is one aspect in which the Mac is the perfect agent host: Apple has, for decades, invested in a combination of scriptability, automation, and accessibility APIs (these are very often the same thing) that makes it remarkably well-suited to computer use. Then there is the fact that macOS is a certified Unix system; this means that agents — which are perfectly suited to the command line — have access to the entire universe of tooling built for Unix systems. And, of course, Mac hardware is amazing.

The problem is that for my particular use case — a headless, always-on Mac Mini that I primarily access from other computers and my phone through the ChatGPT and Claude apps — macOS is incredibly hostile. The biggest issue is GUI-only permission prompts that are invisible to software running on said computer, including agents.

These permission prompts are a part of a macOS subsystem called Transparency, Consent, and Control (TCC), although Apple doesn’t seem to use this name anymore. There are a whole host of things on your Mac that are covered by TCC — the list only gets longer with every OS release — and you have to explicitly approve access to the covered items for every app that wants to access them. If you’ve been prompted for permission to use the Camera, or, much more annoyingly, access the Desktop or Downloads, you’ve encountered TCC.

This system is annoying but manageable on your primary Mac; it’s a disaster on a headless Mac running agents, for two reasons. First, agents write new programs all of the time, and in my case, those programs need access to devices on my network (SMB shares, for example, trigger a TCC warning). What I need is a permission layer for agents, not the programs they create; TCC is operating at the wrong level of abstraction.

Second, the TCC subsystem exposes its prompt in a protected space that no program can see; that means that programs silently fail and the agents don’t know why; what I have to do is remember that there is probably a permissions prompt on screen, log into the Mac Mini with screen-sharing software, and click OK.

There are in fact good reasons for this. The goal of the TCC subsystem is to protect you from malware accessing your computer nefariously; if the prompts were accessible by software running in userland then malware could work around it. Again, though, I am running a computer that is purpose-deployed for agents: for my use case TCC is nothing but a headache — one that indirectly led to my being hacked.

Apple Frustration

Again from Ars Technica:

As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting. Security practitioners generally advise Mac users to keep the port closed even when using screen sharing and to instead connect over a VPN or through SSH tunneling. The alternatives require actions that aren’t within the capabilities of most users.

The safest practice is to block screen sharing, enable it only when screen sharing is needed, and to turn the feature off once a session has ended. Screen sharing can be turned on or off by accessing System Settings > General > Sharing and toggling the switch for Screen Sharing. Of course, installing last week’s security update is also a must.

Obviously I should have — and will be — using a VPN going forward (the foundation of my entire approach to security is Tailscale); what I will note, however, is that TCC basically leaves me no choice but to have screen sharing enabled if I want to actually use my Mac Mini in the way I want to use it. I use screen-sharing constantly — including from my phone — and almost every time it’s to click “OK” on a stupid prompt that I’ve long since stopped taking seriously.

What really irks me about this episode, however, is how Apple released the fix. Obviously I know that you should always keep your computer up-to-date for security purposes; that’s why I have all of my computers set to automatically install security updates.

What I didn’t understand is that this setting does not in fact apply to most security updates. CVE fixes almost always arrive in point releases; in fact, the most recent point release was about fixing this bug. In fact, I suddenly realized that I had been leaving myself more exposed than I should have been for years, under the mistaken assumption that checking “Install…security updates automatically” would in fact install security updates automatically.

I am admittedly being pedantic here; at the end of the day I hadn’t installed the point release promptly enough. Still, it does bug me that a company that is so concerned about access to my Desktop wasn’t very concerned about how a pretty important setting reads to a fairly sophisticated user. Again, this is my mistake, but the mistake was an honest one downstream of trusting Apple to call a security update a security update, particularly if they give the option to automatically install them.

That’s trust they have by-and-large earned; what is increasingly frustrating is that that is trust they increasingly demand, and the scope of those demands is continually increasing. It may seem silly to complain about the labeling of an update, but if you’re going to demand permission for accessing a network share can you at least patch my computer when I explicitly gave you permission to?

This, by extension, is why the note about full disk access is unnerving. I can understand that users may not understand that granting an agent full disk access means that that agent can read your iMessages (for now — I bet that the iMessage store will be encrypted in the near future, a la iTunes in the 2000s); other users, however, may want exactly that. Or, like me, they might want to actually use a Mac as their own personal computer, not as an Apple-managed device increasingly akin to an iPhone. Maybe this episode shows I’m too dumb to risk that; maybe it just means Apple and I are, after many years together, speaking past each other.

Home Visions

Last week Mark Gurman wrote an article on Bloomberg entitled Apple Is Finally Ready to Enter Its Next Big Category: the Smart Home:

Apple Inc. plans to make its long-delayed push into the smart-home market on Oct. 13, marking a critical product expansion for the company under new Chief Executive Officer John Ternus. At the center of the strategy is a smart-home hub code-named J490, according to people familiar with the matter. Apple also plans to announce the first update to the HomePod mini since that device’s 2020 debut and its first new TV set-top box since 2022…

The products also serve as a showcase for Apple’s new Siri AI assistant, technology that the company spent years developing. The revamped Siri suffered numerous delays, and the smart-home devices should help spotlight Apple’s efforts to finally catch up in artificial intelligence. The home hub will take the form of a roughly 6-inch square display, with versions that can be mounted on a wall or placed on a countertop, according to the people, who asked not to be identified because the products haven’t been announced…

Apple envisions customers placing several of the displays throughout their homes. They could be used to control thermostats, door locks and other connected products, as well as for video calls, intercom-style communication, music playback and viewing slideshows of photos stored in Apple’s iCloud service.

That wasn’t the only home automation related announcement last week; Muse creator Nat Friedman posted on X:

I get, very acutely, that I am not representative of the general population. I actually use agents, for one. More than that, I’m not a target customer for Muse: I’m more interested in building my own agent than in using Meta’s; one of my current projects is the construction of a small home electronics lab to make some of my own agent-controlled gizmos.

With that noted, what struck me about Gurman’s article is just how unenthused I am by an Apple smarthome product. Some of this is fatigue from a decade of Siri disappointment and skepticism about the company’s ability to deliver on a voice-centric product. More than that, however, I bristle at the idea of introducing Apple’s constraints to more parts of my life.

Those constraints aren’t just about things like full disk access. To the extent that Apple delivers on integration with things like thermostats and door locks is the extent to which they work with 3rd-party device makers; the problem is that third party device makers mostly suck, particularly from a software perspective. Even if Siri were perfect, Apple will have the challenge of delivering an experience that isn’t defined by the lowest common denominator.

What I’m much more interested in is controlling the software layer myself. The fact of the matter is that with AI you can decompile almost all existing software — there is a revolution happening in gaming over the past few weeks, as game after game is decompiled to source and ported to any platform you wish — and you can write your own. That means my software that interacts with my agent in the way I want it to for everything; that’s way more exciting than praying Apple delivers the right API and that 3rd-party developers don’t suck.

The App Limitation

This, by the way, is a problem facing Siri; I wrote after the recent iPhone event and Ternus’ vision of the “Intelligent Personal Hub”:

What is most interesting, however, is how the biggest advantage Apple has traditionally had may be a hindrance…it’s extremely impressive that Apple claims 300,000 apps work with Siri. Note, however, that the implication of it being “easy for developers to adopt new capabilities” is that developers have to actually put in the work — that’s work in addition to updating their UI for Duo.

In a world where everyone has to convince developers to build integrations, this wouldn’t be an issue. However, this is where browser use looms large: to the extent that agents can just use the web is the extent to which they get an integration with basically everything for free, and it’s Apple, with its dependency on developers plugging into APIs, who is at a disadvantage…

In Apple’s vision, the utility of Intelligence is defined by its ability to augment your existing workflow. Thus the reference to updating your calendar and reminders. It’s very possible, however, that the better workflow is to outsource a lot of work that used to happen in apps to the agent directly. What’s better, using a structured reminders app that you have to check, or simply being reminded directly by an agent? In truth the answer will likely vary by person, but it’s worth pointing out that Apple is so married to the app paradigm that they probably never even considered the alternative.

Apps were amazing, and a better experience than what came before; that doesn’t mean they are the best experience, and anyone who has seriously used an agent knows exactly what I mean. Apps get in the way, which is to say that integrating with them is to make your agent worse; I don’t want a different UI per app, when I have at my disposal true UI — the Universal Interface for everything digital.

This is where the Muse Gadgets program is a stroke of genius. Meta is seeding an entire ecosystem of devices, some of which might become real products, and it’s completely open source. The payoff isn’t in selling devices; it’s in Muse being the interface for everything.

A Hacker’s Future

21 years ago Paul Graham wrote Return of the Mac:

All the best hackers I know are gradually switching to Macs. The reason, of course, is OS X. Powerbooks are beautifully designed and run FreeBSD. What more do you need to know?…

With OS X, the hackers are back. When I walked into the Apple store in Cambridge, it was like coming home. Much was changed, but there was still that Apple coolness in the air, that feeling that the show was being run by someone who really cared, instead of random corporate deal-makers.

So what, the business world may say. Who cares if hackers like Apple again? How big is the hacker market, after all?

Quite small, but important out of proportion to its size. When it comes to computers, what hackers are doing now, everyone will be doing in ten years. Almost all technology, from Unix to bitmapped displays to the Web, became popular first within CS departments and research labs, and gradually spread to the rest of the world.

As someone who switched to the Mac in 2004, a year before Graham wrote his article, this was edifying: “I just switched to the Mac, I guess I’m a cool hacker”. In truth, the Unix part didn’t matter much to me; I preferred the design and the UI, and really wanted to try GarageBand. And, over the ensuing years, I appreciated the extent to which the Mac just worked — slower than the alternatives at first, then at parity, and then, with Apple Silicon, better than anything else.

The thing about AI, however, particularly agents, is that they make anyone a hacker. You really can do anything now, if only you have the volition and the ideas, and once you embrace that, a walled garden feels less like protection and more like a prison.

I’m not, to be clear, predicting Apple’s downfall; I’m not even changing my computer or phone. What is surprising to me, however, is that not only am I uninterested in the company’s home device, I can, for the first time, envision a future where I don’t buy Apple by default. Indeed, this already happened: even before this incident I had already purchased a new server, which will run Linux; I will never put a Mac in a rack again.

That’s fine for Apple, of course; that’s not what their computers were designed for. The question, however, is whether what they are designed for is the future I am barreling towards, one where agentic abstraction both renders traditional interfaces relics even as it makes computing everywhere more accessible than it has ever been, where the limit is not a developer building for scale but my own imagination building for myself.