Hacker Dudes// alternate deck. same feed.
FEED ~1/h SIGNAL
100%
SPOOLED 0/30 CYCLE 61319.852.53.27
Meta’s Muse is an adorable privacy and security dumpster firetechdirt.com
353pts/236 comments/8h/─
by beardyw / hn> / « feed
▲▼ whycome13:30 hn>

It’s interesting that the only ads I’ve seen for Muse don’t mention meta at all.

▲▼ nervai14:05 hn>

if you go on meta.com there is not a single mention of Facebook or Instagram anywhere in sight, and those are their leading products and money makers...

the company's brands are toxic and they know it.

▲▼ coliveira13:32 hn>

And it's all by design, Meta and its founder have a long history of releasing products with security "flaws" that are immediately used by them to collect vast amounts of information about their victims.

▲▼ jeanpah13:36 hn>

Again? This seems very intentional at this point

▲▼ reactordev13:40 hn>

It’s 100% intentional, go look back at what they did with the Facebook app.

▲▼ piva0013:52 hn>

It's always very intentional, especially with Meta/Facebook.

That's their whole modus operandi, a privacy nightmare which will feed their infinite money machine.

Reading "Careless People" didn't make me surprised at all on how the company operates, it surprised me with the personal descriptions of how people like Mark Zuckerberg and Sherryl Sandberg actually are as humans. It scared me how most people at that level of wealth and power isn't too different from the accounts in the book, they're all seriously deranged people with a gigantic lever to impose their distorted realities upon the rest of humanity.

▲▼ jagermo13:37 hn>

I get the appeal of agents, I do. This is the future stuff we always wanted. But I cannot get myself to give one of these things access to my bank account or allow it to do price comparsion and shopping without oversight. Or access to my email or chat history.

I just do not trust any of them, not with my money or with access to my conversations.

▲▼ reactordev13:39 hn>

I’m in the same boat. After witnessing context rot and inference collapse, I do not trust any LLM with mission critical work. Not Jev, not grok, not fable, not Opus.

▲▼ ctkhn14:13 hn>

What extent does that happen for you? I have got very good results with self hosted qwen3.8 flash next at q4 and even with qwen3.635b on a laptop. I don't keep it running forever on every single repo, its ok to leave notes in agents.md and let it search that instead of the entire history staying in context.

─ 4 more ─
▲▼ ehe1213:40 hn>

Personally to me this feels like another classic case of starting with the technology and figuring out where to sell it as opposed to the customer experience.

It feels and seems too forced.

▲▼ charliebwrites13:47 hn>

The missing piece for connecting an agent to your credit card or other financials is financial liability.

If Meta/OpenAI/etc would guarantee they’d compensate you in full for anything that wasn’t supposed to happen —and had an established track record of doing so— it would make trusting agents to make financial choices easier

▲▼ ehe1213:49 hn>

“ If Meta/OpenAI/etc would guarantee they’d compensate you in full for anything that wasn’t supposed to happen —and had an established track record of doing so— it would make trusting agents to make financial choices easier”

lol… talk about delusion.

▲▼ beardyw15:02 hn>

First you would need to establish some sort of interaction. Probably with the same AI that spaffed your cash.

▲▼ ls61217:06 hn>

I think the solution is instead to require purchases to hit a hard harness restriction, so you must click yes for money to be spent.

▲▼ proggy18:39 hn>

Assuming financial liability is an option, but because the risk profile of having an agent making purchases for a cardholder will never be zero, the companies making these guarantees will simply price the risk in to the cost of service. It’s the same basic mechanic at work with credit card reward points, the brands are all fighting each other for a share of customer debt so they slowly increase the rewards rates to one-up each other, and make up the cost on the back end by increasing merchant fees. It’s a dumb, unnecessary price war that ultimately increases the cost to the consumer and drives up the profits of the businesses providing risk/cost-burdened services.

▲▼ the_snooze13:50 hn>

What AI boosters don't realize is that we're not in the optimistic days of the 1990s anymore. We've seen that the prevailing tech business model is to offer convenience as a lure to lock in dependent users and extract value from them.

Unless these AI assistants are running on self-managed platforms independent of their developers, all I see is immense counterparty risk.

▲▼ pelotron14:06 hn>

Absolutely. If you need any signal to know where Big Tech's head is at, just look at how quickly they became arms dealers.

─ 7 more ─
▲▼ Aurornis14:52 hn>
>What AI boosters don't realize is that we're not in the optimistic days of the 1990s anymore.

Comments like this are in a different reality than most consumers. Most consumers don’t care about things like avoiding lock in to a platform. If the platform solves their problem then they don’t have any reason to leave it anyway. They’re not worried if their data is used to show them more targeted ads.

Topics like this show a sharp divergence between what you read on Hacker News and how actual users operate. We already knew that people who don’t trust Facebook aren’t going to suddenly start using Muse. They were never going to consider it. For the people who do actually use Meta products, which is a customer base counted in the billions, many will not have any problem using these tools.

─ 23 more ─
▲▼ ai-x15:19 hn>

Me and 4 Billion happy users don't care.

HN must understand that they are not a representative sample of anything.

─ 10 more ─
▲▼ m46315:40 hn>

I read "the tesla files", a book about a whistleblower leaking a ton of internal tesla files.

They were discussing how tesla manages problems with full-self-driving.

It was interesting how this realm of problems was viewed.

If there was an accident while the car was driving itself due to some glitch, the police at the scene put all the blame on the driver.

The book had a different viewpoint. obviously there was a tesla bug in full self driving, and they kept their mouth shut.

meanwhile society/government doesn't even think of this and puts responsibility/blame on the user.

▲▼ __MatrixMan__15:41 hn>

AI seems to be an amplifier for other problems that we never fixed, more than an authentic source of problems on its own. In this case it's amplifying that we never really trusted the cloud to begin with.

We have a lot of deferred problems to go back and solve before all these dreams can come true.

▲▼ cyanydeez15:53 hn>

I think WallE is the perfect reference for the world AI/oligarchy are running towards. Not whether it exists, but that' dependency+environmental destitution.

▲▼ awepofiwaop13:58 hn>

Don't worry, I'm sure eventually you'll simply be required to give one of these things access to your bank account and that decision will be taken out of your hands.

▲▼ malfist14:00 hn>

When that happens, I'm sure banks will lock out secure local models for "security reasons" like an unlocked phone.

▲▼ ctkhn14:00 hn>

I see the value of the tool but I would never use it from Meta. Would need to be self hosted with a very structured framework and guardrails so that even my local model couldn't accidentally wire 50k to a Nigerian prince or whatever the latest email scam is.

▲▼ shostack14:55 hn>

I see everybody freaking out about unfettered payment access to one's bank accounts and I keep wondering why people don't jump to the obvious solution of simply only giving it a single purpose or limited fund credit card number from privacy.com or something.

Am I missing something with the concern about ability to constrain the blast radius?

─ 1 more ─
▲▼ Octoth0rpe15:34 hn>

Man, I wonder how many facebook marketplace sales will be something like "In order to make sure you're a real person, before we can meet up so I can hand over this brand new macbook for $500 I need you to send me $10 electronically. It's really just to verify your commitment". With the right prompting, I'd be entirely unsurprised if Muse will just send over the $10, and of course the seller ghosts the buyer -_-

─ 3 more ─
▲▼ KetoManx6414:08 hn>

You don't have to, there is a world of things you can do with them without giving them access to your email or bank account.

"Hermes, clone this android app to my computer, add this and this feature and fix this annoyance and then rebuild it and push it to my phone"

"Hermes summarize this YouTube podcast and push the summary and transcript to my Obsidian vault"

"Hermes check mg obsidian notes for when I last wrote a blog article about Neovim's integration with AI agents"

*Hermes, you have an API token that allows read only access to the Zabbix monitoring system, check that and then use the Proxmox API token that only allows you to do limited actions to reboot the VM that is having issues"

Etc, etc,

▲▼ shostack14:57 hn>

YouTube transcripts are increasingly if not completely blocked now. It used to be great to grab content from long tops. I did not have time to watch but wanted to learn about. Now. The only way to do it is to manually copy and paste the transcript information or use computer use. But I cannot easily do it on my VPS it seems unless I'm missing a trick.

─ 2 more ─
▲▼ f6v14:47 hn>

My wife has scheduled a visit with a physician and there was a younger person in there. They legit said “haha I don’t know what it is” and used ChatGPT for diagnosis.

I have no doubt they would have no problem outsourcing everything to agents.

▲▼ leptons15:17 hn>

That's some Idiocracy level bullshit.

▲▼ edmundsauto15:43 hn>

Did they reach a good diagnosis by using tools to provide themselves additional information to process?

Or did they make a fatally wrong diagnosis that was only discovered because the old doctor whipped out their medical encyclopedias? You left us hanging without the relevant part of the story!

▲▼ thenatureboy15:02 hn>

Sad to see such paranoia, agents can genuinely be an agent of good and positive change.

Last night I had ChatGPT go through an old email account and surface memories that I literally forgot. People who I have fond memories of. Yea I could have spent time querying gmail and digging but the agent did it in a way that really resonated. I don't care if Sama has my emails now. I do care about connecting with my past and enjoying the memories of a time long past.

Paranoid scolds of HN want the average person to be deprived of value like this for some reason.

▲▼ SpicyLemonZest15:13 hn>

I affirmatively want that exact scenario not to happen, yes. I'm opposed to the automation of nostalgia, I don't think it's good nor positive.

▲▼ tempfile15:15 hn>
>I don't care if Sama has my emails now.

I am perfectly prepared to believe you had a nice interaction with the robot. But this is an insane thing to say!

─ 1 more ─
▲▼ Apocryphon18:38 hn>

Independently of the actual state of the art, and the social implications and everything, my main takeaway from Her was always the initial setup of Samantha (huh, now that's some eerie nominative coincidence), wherein the AI curates his email inbox. That is the mundane chore that's always been my dream AI use case.

https://www.youtube.com/watch?v=f9Hg1x-Ctlw

▲▼ gadders15:15 hn>

Yeah, just waiting for the AI-enshittification when they give it to the growth hackers to drive VC returns at the expense of utility.

▲▼ liendolucas15:21 hn>

Sorry, no. This is not the future I wanted. I do not run any agents nor ever will.

I find all this is just the next-gen privacy violation, disguised obviously as: "Oh, WOW an agent in the computer is doing all this for me". Bullshit.

It seems that never is enough with these ever thirsty companies, they keep pushing the limits and surprinsingly a lot of people do not care at all nor value the implications of having an arbitrary process running and doing pretty much whatever the agenda of their creators are.

▲▼ ncr10015:47 hn>

This outcome is always likely/ predictable.

We are an opportunistic species. We don't have perfect knowledge nor thoughtfulness.

We need to protect each other.

We don't.

▲▼ chasd0015:34 hn>

I made an agent to derive and iterate on a stock trading strategy for me. What I did was give it a virtual bank account that models your typical brokerage account. So my agent reads the news, financials, markets, all the information it can gather to decide what stocks to buy/sell and manage its portfolio. Then what I do is just follow along with real money.

I could see shopping being the same way, let the agent shop for you or identify good deals on things you want but then push them to you to make the actual purchase. Like you, I'm certainly not going to let an agent make a real purchase for me unattended and I doubt any merchant is going to have much sympathy for "my AI bought this by mistake".

▲▼ lrvick15:37 hn>

I trust mine considerable, but only because I can run it mostly offline on hardware I own that lives in my garage. It baffles me that I am the only technical person I know that exclusively uses AI this way.

▲▼ diskzero15:46 hn>

I am a technical person and while I appreciate the challenge of buying the hardware, setting up the software stack and managing the system, I can't figure out any use cases that would justify the work. This is the main issue I have with Muse, Dots, etc. There just must be something about my routines that don't align with what these companies are expecting their users to do. I do take advantage of the investor subsidized coding agents, but it will take years of my usage of their services to come close to initial start up cost of my own system.

I am very curious as to what other people of using these agents for? Some of the use cases I hear; comparative shopping, travel planning, etc. don't appeal to me. Our people using them to manage family life issues like school schedules, meetings, etc? I feel like I am missing out, but I also am not seeing the greater appeal yet.

─ 3 more ─
▲▼ mrob15:53 hn>
>This is the future stuff we always wanted.

Speak for yourself. I hated the idea of agents ever since I first heard of it back in the 90s or 00s. For me, the most valuable feature of computers is predictability. I want tools, not agents. A computer should augment my own skills, not replace them.

▲▼ jagermo16:49 hn>

I mean, fair. I want something like the TNG Enterprise computer, that works for me within the parameters I set. That, for me, is cool.

▲▼ chrisjj17:22 hn>

Pretend you have insifficient skill to satisfy your desires, even after augmentation.

You are now dead center of the "AI" agent's target market.

▲▼ JKCalhoun16:17 hn>

Now add Meta to the mix and stir.

▲▼ trollbridge16:52 hn>

Muse is basically OpenClaw, with all the pros and cons. Except I really don’t trust Meta to get any of this right.

▲▼ latexr17:18 hn>
>This is the future stuff we always wanted.
>(…)
>I just do not trust any of them

So… Actually not the future stuff we wanted? That’s what bothers me when people say “we have the Star Trek computer”¹. We clearly don’t, because if we did we could trust it with a high degree of certainty. Instead what we have is a computer we must distrust to a high degree. One of the two crucial variables is flipped.

¹ I’m not saying you are saying that, but several people have expressed that sentiment on HN.

▲▼ hbn18:33 hn>
>allow it to do price comparsion and shopping without oversight

You can get it to do the price comparison part without having it do purchases.

I downloaded Muse, told it to find me some underwear to buy, asked some questions to narrow the options down, then once I came to a decision I went and purchased it myself.

▲▼ mv419:16 hn>

It's evident that agents still can't be trusted to transact on your behalf. Too many things can go wrong.

▲▼ bunderbunder20:09 hn>

I just can’t even fathom it. LLMs have no judgment, and it’s still so easy to “trick” them. If you forced me to decide between granting the ability to conduct financial transactions on my behalf to an LLM agent, or to my family member with Lewy body dementia, I’d have to have a serious think about which one is less risky.

▲▼ otikik13:45 hn>

Oh Meta not giving a damn about privacy and security? Say it ain't so.

▲▼ netless14:13 hn>

been mostly using WhatsApp, should i be worried?

▲▼ ryukoposting14:53 hn>
>should i be worried?

The question implies you already are. But yes, obviously.

▲▼ nekusar13:48 hn>

"People just submitted it. I don't know why. They 'trust me'. Dumb fucks."

-Mark Zuckerberg

▲▼ jagged-chisel14:13 hn>

They didn’t though. No trust involved. Hormones and emotions.

Today’s version of the platform targets just the right emotions to keep users “engaged.”

▲▼ alistairSH14:05 hn>

Are all of these just flavors of "the agent has the same permissions as the user"? Not that I want to trust Meta with anything, but I'm guessing it asked for "root" access and the users granted it...?

▲▼ dcss_gardener14:40 hn>

Yes, it is clearly designed to give you access to all of this intentionally. Its system prompt (which you can just read in the interface without asking) explicitly instructs it to act on behalf of the user, not meta. All of its memory files, skills, db schema, memory integration system etc are likewise visible because they went out of their way to add an interface for viewing them!

I don't like or trust meta any more than I always did but I don't see how they could have done a "better" job with this. These kinds of agents are inherently pretty risky IMO but I don't see how this one is particularly more than any others.

Playing around with it I really don't get the sense there's any hidden prompt contradicting what's visible. It's nearly gleeful at using the VM in ways that were not intended and likely against meta's interests. I feel like someone must have won a really interesting internal power struggle to get this thing out in this form.

▲▼ jkingsman15:37 hn>
>I really don't get the sense there's any hidden prompt contradicting what's visible

It will happily disclose its entire system prompt (which is interesting in its own right, and worth a read) or pop a reverse shell for you

>I don't see how they could have done a "better" job with this

I generally agree -- the openness is great. However, from experiences both inside and outside of Meta, good execution, a hacker ethic, and transparency ultimately has very little propping it up when money is on the line. In fact, it could be argued that Meta has a shareholder obligation to do profitable things such that even the best intentions can (and usually will) fall in the face of corporate hierarchy and sales numbers.

I think they did a pretty bang up job with Muse (the lack of communication with first-time agent users around how powerfully and confidently they can make horrifying mistakes, and how careful you need to be with prompting, and how even that sometimes isn't enough, notwithstanding).

I also think it will inevitably be used to squeeze profit, and given Meta's history, I think it's almost comical to not assume that will involve violations of the spirit of privacy. (and that's assuming that a proliferation of "it deleted all my files" "it messaged my ex" "it leaked private info" doesn't poison consumer sentiment before it even gets off the ground)

─ 1 more ─
▲▼ oofbey15:21 hn>

Probably. But also the agents are finding flaws in the security model.

Also Meta is actively encouraging users to grant them full permission, insisting with all their marketing might that it’s safe, which they know is a complete lie. Hard to blame the user when they’re being actively deceived like this. Other agent companies are more reserved and say things like “be careful” but Meta is the opposite.

▲▼ alistairSH15:38 hn>

I definitely didn't intend to blame the victims here, beyond trusting Meta in the first place.

As for security models, it's probably long since time to sandbox all data and apps. More like mobile devices. Allow users to toggle that all off so they can use their computers for development etc, but the default state should force apps/tools to explicitly ask for permission to any folder, other app, API, CLI, etc. And ask for that permission regularly (or rather, reset the permission after some period of time). Or something like that (I haven't given it a great amount of thought).

─ 1 more ─
▲▼ judge202019:28 hn>

I mean, it's not that the data isn't safe (they at least have modern user-level data protection similar to the other tech giants), nor will the agent generally do stuff you don't tell it to do. But I'm sure their stance was less "let's ask for granular per-category access whenever the user actually needs it" and more product-driven "we want the agent to have all the data and context it needs to become a successful product that gets people hooked, so let's ask for full disk access".

▲▼ ChrisArchitect14:12 hn>

Since this is mostly a collection of links to previously discussed articles:

Related:

Updates to Full Disk Access in macOS

https://news.ycombinator.com/item?id=49937631

Meta’s Muse has a serious 0-day

https://news.ycombinator.com/item?id=49802030

Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions

https://news.ycombinator.com/item?id=49893709

Maybe don't let Muse run your Facebook Marketplace account

https://news.ycombinator.com/item?id=49875006

What Meta got right with Muse

https://news.ycombinator.com/item?id=49946526

Muse – Meta’s personal AI agent

https://news.ycombinator.com/item?id=49615537

▲▼ sdcfgy14:18 hn>

Isn't that Meta's entire product line?

▲▼ DebtDeflation14:30 hn>
>When one tech YouTuber put Muse in charge of their Facebook Marketplace sales, it sold his stuff way below acceptable rates

Why are we depending on LLM "reasoning" to negotiate a price rather than just having the user enter a lowest acceptable price deterministically?

▲▼ f6v14:51 hn>

Because a lowest acceptable price probably depends on doing research and making a decision.

▲▼ Sharlin14:54 hn>

That would require thinking, and thinking is the thing everybody seems to want to outsource to LLMs.

▲▼ augment_me15:22 hn>

It involves cognitive effort to set a good lowest acceptable price. We don't want that, we want to reduce this effort that's what the tools are for

▲▼ ncr10015:55 hn>

Because we are human.

(As a human, it's more physically taxing to think, and less taxing to relax. Conserving internal resources improves our survival odds. So when an opportunity presents itself to use less effort and still gain out of that, we tend to take it.)

As human technologists, I believe we need to protect humanity more.

In everything that we do, we need to think about the ways that our proclivities as a species can be compromised by our development of technology.

▲▼ arshxyz14:32 hn>
>Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages

Can someone explain how this is possible? If an app can do this without Full Disk Access or a popup of some kind that's a way bigger lapse on Apple's part than Meta's.

▲▼ etatester15:11 hn>

Reading the linked articles suggests that this is not possible, but Apple did acknowledge that the full-disk access grants you access to other apps (until the most recent update)

Typical "leopards ate my face" moment. You give AI (from Meta, nonetheless) full-disk access and then complain that—wow—it really meant FULL.

In a perfect world where you got nothing to hide, where companies don't sell your data and there are no hackers, even I would love to just hand all my data to Muse and have it be my trusted assistant. People who think we live in such a world are already doing that, evidently.

▲▼ lapcat15:53 hn>
>Apple did acknowledge that the full-disk access grants you access to other apps (until the most recent update)

There was no recent update. Apple's announcement was about a future macOS update.

▲▼ laweijfmvo15:26 hn>

I saw a theory, just a theory, that it may have accessed the message via its notification preview, which I think was similarly used to leak Signal messages recently?

▲▼ lapcat15:52 hn>
>Can someone explain how this is possible?

It's not.

▲▼ fridder14:34 hn>

This shouldn't be a surprise to anyone. Why would you trust Meta with privacy and security?

▲▼ labrador14:38 hn>

I can finally relax and let a random number generator make my decisions for me

▲▼ ncr10015:57 hn>

This person gets it.

It really is about trading off personal energy and internal resources for gain. It's almost survival level logic.

▲▼ chadd14:40 hn>

It's very simple. There is ZERO chance the worlds biggest advertising companies will refrain, long-term, from using your most intimate secrets, gathered through your many conversations with their AI personal assistants, to sell you things.

▲▼ jagged-chisel14:44 hn>

Or to otherwise coerce you into whatever funnel that makes them money

▲▼ NBJack15:04 hn>

"That sounds like a tough problem in your relationship right now. Would you like me to order another Crave cookie for you? There's a special right now on free delivery. What about renewing your subscription to aitherapynow.com?"

─ 1 more ─
▲▼ airstrafer14:59 hn>

I agree with this but also think it is a first order consequence.

This level of unfettered access to your personality, lifestyle, and secrets allows for an unprecedented kind of manipulation and control. You could see it as a new kind of wealth transfer: not only will They sell you things, They will subtly manipulate behaviors of the masses via trusted agents.

▲▼ phoghed15:33 hn>

Brother the biggest ad companies already own the platforms most people use for their communications. For over half the world they are the browser, the OS, the TV, the messaging platform, the map, etc.

I think to the vast majority of people having one of these companies run an agent platform is going to be business as usual.

─ 1 more ─
▲▼ winrid15:16 hn>

"I've gone ahead and placed an order based on your Google doc Daily Diary "Bad Dragon" entry."

▲▼ piyuv15:47 hn>

“to sell you things” -> to manipulate you

Let’s not forget Facebook caused a genocide

▲▼ ncr10015:49 hn>

In your locality, do you know if there are any upcoming votes/ laws or politicians who are realistically working to preserve your privacy, in these regards?

In mine, I don't.

That seems like an oversight/ opportunity.

▲▼ matltc14:57 hn>

Couldn't pay me to use this junk.

Trying to think of a number that I would consider it, and honestly $1k/month wouldn't convince me unless

- I have root on device

- device is on its own vlan, fully segmented

- !(SIM || 5G antenna)

- no google/apple id authenticated on device

- terminate agreement at any time without cost

I'm probably forgetting/not aware of ten things I should consider.

▲▼ DaSHacka16:31 hn>

Ironically it already satisfies all of those conditions because it runs in a VM on Meta's servers as root, where it'll happily let you install whatever you want inside the VM, including a custom remote access tool to let you logon as the root user inside it.

▲▼ Razengan15:04 hn>

Does anyone remotely interested in AI use Muse out of explicit choice?

Facebook is like Microsoft at this point: The thing your grandparents use.

Even if they make something technically superior for a while, like what the Zune was to the iPad, tHey'll never really be cool.

and they'll certainly never be trusted.

▲▼ shepherdjerred16:13 hn>

Muse is a decent model at a VERY low price

The Muse app is very polished and it seems to actually be popular with younger people.

I have tried it out but I’m still struggling with use cases, same problem I had with OpenClaw

▲▼ tmpz2216:26 hn>

Surely that price is being subsidized at launch though, and will ratchet up faster then even the Streaming services currently are?

▲▼ measurablefunc15:18 hn>

Every social media & AI company is also a surveillance company. Targeted advertising doesn't work w/o mountains of behavioral data aggregated across all of Meta's & Google's software "products".

▲▼ piazz15:25 hn>

I’m pretty frustrated with Muse and the last thing I want to be doing with my free time is defending Meta, but this is such clickbait.

Point by point:

>“OMG you can jailbreak it and get it to spill its VM”

This is the whole point; any content on the VM is yours. It runs in an isolated sandboxed VM separate from stored credentials etc; this is effectively your own computer. You don’t have to trick it.

>It collects dossiers on your contacts

These are more text files that live on your private VM, alongside memory.md, etc. Do you want your secretary to forget every person you contact every day?

>It accessed Messages without full disk access

This whole story never made sense or was substantiated. Full disk access is an OS level security boundary; the user had to switch this on.

>It sold some guys stuff for too cheap and gave out his address

OK this one I basically believe, haha. Because this is the problem with Muse: the LLM is just too dumb to perform complex tasks effectively in many cases.

▲▼ ralphington16:29 hn>

You just did the tech equivalent of "not to sound racist, but..."

▲▼ moscoe16:43 hn>

Absolutely agree. So much feigned outrage in these articles (and HN comments) about the LLM models doing x.

Yesterday everyone was all worked up about OpenAI generating an image with a signature on it.

Caveat emptor. Don’t be an idiot. Grow up. Make informed decisions regarding your use of these products and take responsibility for those decisions.

▲▼ JohnMakin16:53 hn>
>Caveat emptor. Don’t be an idiot. Grow up. Make informed decisions regarding your use of these products and take responsibility for those decisions.

Feigned outrage, indeed. I don't think it's unreasonable to point out that Meta has been consistently predatory, reckless, and creepy with user data before, and that this is a very aggressive expansion of that.

The old facebook booster retort of "if you don't like it, don't use it, take responsibility" or whatever is nonsense. You're in their system whether you use their product or not. Even if you somehow avoid their pervasive web-wide tracking, a single contact you know installing this thing and gobbling up all your correspondence with them can compromise your privacy choices, and that's well beyond your control, unless you seriously suggest I audit every single one of my contact's devices and browbeat them into using the privacy choices I prefer.

Get real.

─ 1 more ─
▲▼ stephen_cagle16:53 hn>

My assumption is you clearly don't have vulnerable or elderly people in your life? I'm not as concerned about my ability to navigate these waters as I am about the people I care about.

▲▼ slashdave18:57 hn>
>Make informed decisions regarding your use of these products

They are mass marketed. The creators should do the upmost to ensure this and not pin blame on users.

▲▼ givinguflac20:03 hn>

In this context, normal people will believe the marketing and trust meta, and caveat emptor is a cop-out at best. I can sell you a basket of bread, and it’s privacy-preserving bread, but it will also punch you in the face if you don’t read every bit of the agreement. No one reads the agreement, and that’s what Meta runs on, plus skirting the law in every way they can possibly get away with.

▲▼ cmiles7417:02 hn>

I gotta' disagree on this one. Meta made claims that it was taking privacy seriously and it turns out, not so much. I do think they should be getting some pressure on that score.

▲▼ IshKebab17:21 hn>
>it turns out, not so much

Why though? The comment you're replying to is explaining how the accusations of poor privacy are nonsense and you've just replied "I disagree because they have poor privacy".

I mean I'm not going to hand over any data to Facebook if I can help it but it doesn't seem like there are any specific issues here.

▲▼ piazz17:21 hn>

Okay, but what is the evidence to back up this assertion? My point is, at this time, there is none. There is no “it turns out”. Give them some time to screw up at least.

─ 17 more ─
▲▼ moffkalast18:09 hn>

Ah yes, Meta and privacy. Two things that go together like a jet engine and a library.

▲▼ hitekker17:25 hn>

It's the market for attention. Many of techdirt's writers are heavy Bluesky users so most of their articles cater towards other Bluesky users. Venting might be the most common longform on either website.

▲▼ JMiao17:58 hn>

i started using bluesky recently and the venting seemed about normal by internet standards

─ 1 more ─
▲▼ GeekyBear17:30 hn>
>It accessed Messages without full disk access
>This whole story never made sense or was substantiated

This story makes perfect sense, and Meta has a long history of not respecting user privacy controls.

>tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits

https://arstechnica.com/security/2026/10/apple-changes-full-...

▲▼ bigyabai17:36 hn>

Which privacy control did they fail to respect, in this instance? Everything on the journalist's machine was working as-intended.

▲▼ kccqzy17:44 hn>

The reason that story didn’t make sense to me was that the tech columnist never showed the Apple system settings on whether full disk access was enabled or not. If you trusted the tech columnist that full disk access was not enabled, then Meta’s Muse AI seemed to have discovered a zero-day vulnerability in Apple software, specifically a TCC bypass.

First I doubt Muse is that good of an AI. Second, even if that’s the case, why wouldn’t someone report it to Apple to get thousands of dollars in bug bounty rewards?

─ 13 more ─
▲▼ lapcat17:50 hn>
>Meta has a long history of not respecting user privacy controls.

Meta's respect is irrelevant, because macOS TCC prevents any and every app, including malware, from accessing your Messages database without Full Disk Access.

>he never granted Muse permissions to read his messages

That's what he said, but I would suggest that one person's memory is a lot more fallible than a longstanding operating system security feature.

─ 1 more ─
▲▼ zardo19:27 hn>

Aren't permissions on notifications less restricted then full disk access?

▲▼ butlike17:31 hn>
>I’m pretty frustrated with Muse and the last thing I want to be doing with my free time is defending Meta

Then don't.

▲▼ iAMkenough18:28 hn>

Nice! Starting my own crypto miner using Meta infra then.

▲▼ al_borland18:29 hn>

In. Jonna Stern’s interview with Zuckerberg he talked about the security, and how they delayed it to make sure they got it right. He then went on to say there was more to do and they weren’t totally isolated yet (I can’t remember his exact wording).

I felt like he was undermining his original point. They delayed to make it better, but didn’t delay long enough to do the actual right thing he mentioned they could potentially do in the future.

When it’s pulling in data from all over the phone or computer, it’s not just the user’s data. Some of my personal data (detailed contact info, emails, etc) can be pulled in and used by Muse if someone I know installs it, without my knowledge or consent. That needs to be taken seriously, and Meta has a history of abusing this concept (uploading fully address books to find friends)

▲▼ greenavocado19:15 hn>
>the LLM is just too dumb to perform complex tasks effectively in many cases.

Muse Spark 1.3 is way better than anything else out there outside of the US labs except Deepseek Flash which comes close.

▲▼ Havoc15:43 hn>

The model is decent and cheap under contributor version but no way I’m letting meta AI anywhere near anything that matters in my life.

>Zuck: They "trust me"
>Zuck: Dumb fucks.
▲▼ uejfiweun15:49 hn>

I get this, but to be honest he said this when he was in college, I don't put much weight on it. You're telling me that you never said anything stupid in college?

▲▼ williamdclt16:06 hn>

I sure have, and through my life experience I have learned many lessons that made me change my mind about this stupid stuff I said.

What lessons could zuck have learned, when he's been incredibly successful since these college days? The guy has become one of the richest and most powerful people on the planet _because_ of disregarding trust, and continues to operate the same way, I guess it's not impossible he fundamentally changed but I don't see a reason to think he did

▲▼ shepherdjerred16:10 hn>

It might show his true character which is something that generally doesn’t too much change with time

Or it might just have been a dumb thing a young person said

▲▼ setnone16:23 hn>

well the premise didn't change, they still trust him, so what would mature zuck say?

▲▼ dam_jackalopes16:54 hn>

The issue is less when he made the statement and more that nothing he or the organizations he manages do or say makes one think that he still doesn't believe the thrust of the statement is still true.

▲▼ hannofcart15:45 hn>

I understand that a typical HN user is very different from the average person.

However, surely by now even the lay people who have seen the testimonies before Congress, the lawsuits and the excesses by Meta execs over and over again ought to be atleast somewhat wary of handing them more personal data?

I think the average person has very similar self preservation instincts as the rest of us. So it can't be that. Which leaves the fact that there are lot of people who don't know about the above mentioned scandals galore that Meta has been involved in?

▲▼ logancbrown15:48 hn>

This "holier than thou" attitude in this comment is precisely the reason why HN users have largely misunderstood tech trends and desires by the general public.

▲▼ kevinwang15:49 hn>

I think a lot of normal people do perceive Meta as a shady and bad brand -- why do you assume otherwise?

▲▼ shepherdjerred16:13 hn>

A lot of people don’t care about their data being shared

▲▼ compiler-guy15:54 hn>

Just remember that Meta (née Facebook) changed the entire Facebook feature set and feed style in search of greater engagement and clickbait so that you would do what was best for it rather than satisfy your preferences. And if you liked it more the old way, tough luck. Your feed is now a stream of rage-bait, half-dressed women, and engagement slop instead of a way to keep in touch with acquaintances.

No way I would allow them to develop the agent that runs my life. Even if it works well now, the rug pull is absolutely inevitable.

I was never all that into facebook, but it was nice to get an update on an old high-school friends once every month or two. Now its completely unviewable. Muse may be fun now, but it is one whim-of-Zuck from being unusable, or worse.

▲▼ chrisjj15:57 hn>
>Muse consistently creates detailed profiles of all your friends, family, colleagues, “collaborators,” and people you “follow.” Obviously much of that information is necessary for the agent to get to “know” you, but this being Meta, people are understandably uncomfortable with this sort of massive ramp up of data collection

People who give their data to Meta are uncomfortable with Meta collecting that data.

Hmm.

▲▼ cdrnsf16:24 hn>

Everything Meta makes is a privacy and security dumpster fire.

▲▼ ygjb16:34 hn>

I continue to believe that Meta is the company that is building products I want from a company I have absolutely zero desire to do business with. I put Google in the same category - I used to be a google fanboy, but that subsided over the years as Google grew and killed products I used and liked. Now I only use their products because of inertia and network effect.

I don't trust any of the hyperscalers to place me as a user first, I expect them to guide me into a stall, strap on a feedbag, and start the value extraction process while they build the meatrix[1] around me.

I want tools like Muse, and Meta Glasses, Google Gemini and a horizontally integrated AI agent, but I want it on my terms, where I am in control and accountable, and without a layer of data collection and harvesting on top of it.

Fortunately I am skilled enough to assemble most of what I want, but I fear a world where people who lack the skills and resources I have available have no choice but to onboard and give up control in order to remain competitive, employed, and connected in the world to come :(

[1] https://www.youtube.com/watch?v=rEkc70ztOrc

▲▼ honestduane16:35 hn>

But isn't Muse just a fork of OpenClaw?

▲▼ warkdarrior17:05 hn>

Yes, just like Dropbox is a fork of FTP+SVN.

▲▼ jjcm16:41 hn>

I don't think anyone is arguing it isn't one. The fact that all of these agents have provisions for keeping .env vars and credit cards out of their chain of thought and responses is evidence enough of that - they know full well the info they're handing can easily be leaked. Notably though PII is absent from that, since without that information the agent just isn't valuable.

What most people are arguing is whether or not it's worth it. These things are essentially executive assistants, which historically have also been massive vectors for security leaks. EAs know the most about you, your behaviors, and your motivations. Still an EA is almost always worth it if you can afford one. Given now the cost is free, Muse is something I've both used and recommended. It's worth the risk for me.

at the cost of all your data and probably your eternal soul

▲▼ dasil00317:07 hn>

I agree with your assessment, however I think tech executives are out of touch and lack self-awareness if they think people really want or need this. The whole reason an EA is worth it is because you are making outsized money and your time is worth too much to handle any mundane details that normal people deal with. Along with that there's the whole social signaling of having an EA because it signifies ones wealth and importance.

A free digital EA confers none of that—and it will annoy everyone you know. The only use case I see having legs is dealing with large bureaucracies like canceling subscriptions or medical billing issues, but there I think the common man will lose as the rise of this automation will see a distributed adversarial response from bureaucracies who will happily put up whatever barriers are needed to prevent Muse and other digital EAs from impacting their bottom line.

There's a 50/50 chance I'm just getting old here, but I really think we're going through an epochal shift where new consumer tech won't have the same reception as the smart phone and increasingly addictive bite-sized algorithmic media did over the last couple decades. I think going forward there will be more palpable questioning from younger generations about why do we even want some of these tech products? At some point convenience reaches diminishing returns and we have to think deeper about what we're trying to get out of life.

▲▼ chasing16:48 hn>

Have we learned nothing?

The MOMENT they can, Meta will take all data they have about you and sell it to anyone who wants it, including to people who wish to do you harm.

Honestly, this is where actual government regulations with teeth would make me significantly more comfortable. But self-regulated? Absolutely not.

▲▼ geophile16:49 hn>

A tangent, but todays’s NYT Daily podcast, about one journalist’s experience with Muse, was pretty irresponsible in not covering these problems.

▲▼ autoexec16:50 hn>

Facebook has never been shy about what they are and how little they care about you. They've demonstrated it over and over and over. At this point if you use their products you're asking for what you get. They should still be sued into the ground for lying to people about the privacy of Muse (and everything else), but why the hell is anyone still using their products at all? How has this company got so many people acting like battered spouses? Facebook is never going to stop hurting you. It's time to leave Facebook for good.

▲▼ ls61217:13 hn>

The concept of Muse is I think where things are going but there's no way I'm letting Zuck of all people run an AI agent for me. Either I'd use Hermes with some ZDR provider on openrouter (the compromise choice during the hardware crisis) or a self-hosted model.

▲▼ hamandcheese17:25 hn>

In its current form, Meta's muse is actually the most pro-user agent among Muse, Instinct, and Grok bot. Instinct and Grok bot are both prompted to hide details from you, not reveal how they work, etc. which is user-hostile.

Muse on the other hand is very much Your Agent and does not (yet) have silly limitations that work against your interests.

I hate Meta as much as the next guy, but Muse is well designed.

▲▼ HarHarVeryFunny17:40 hn>
>Meanwhile, Wired found that Muse consistently creates detailed profiles of all your friends, family, colleagues, “collaborators,” and people you “follow.” Obviously much of that information is necessary for the agent to get to “know” you, but this being Meta, people are understandably uncomfortable with this sort of massive ramp up of data collection

This is pretty funny! What ramp up? Building detailed profiles of you and your friends/etc is Meta's core business. They even build profiles for people who are not signed up for FaceBook, waiting/hoping for the day you join.

▲▼ CSSer17:41 hn>

Yes, and we’ve told people this for two whole decades now only for them to shrug.

▲▼ douglee65018:08 hn>

The very clear evidence for security is obvious to anyone who has done a meaningful, deployed body of work.

Whatever the reason, Claude (Code in terminal; my experience domain), despite explicit direction:

- "never leak any secrets" - "never display any passwords" - "everything to the right of the first '=' sign on any given line is a value; never echo or process it bare"

… etc.

--- 5 chats later ---

Notew hile working I accidentally echoed your Apple Keychain decrypted passwords. Oof sorry hehe"

▲▼ moffkalast18:14 hn>

I have a feeling LLM security breaches are slowly transitioning from exploiting obscure zero days to simply walking through the front door with the still live access token they've been pretrained on, lmao.

▲▼ moron4hire18:20 hn>

Why are these AI projects so bad at security? Why do they keep running "just trust me, bro" at their service auth layer? GitHub had an issue not long ago where the agents could be used to expose private repos to unauthorized users. Access control is not all that hard, you just have to, you know, actually DO it!

▲▼ joemi19:51 hn>

To be fair, "just trust me, bro" has _always_ been Meta/Facebook's policy. Sure, they have a big long nicely-written policies if you look for them, but they continually break them, get caught, say "sorry, my bad" and then the way they broke the policy gets worked into the new policy as something that's allowed. This has happened so many times since Facebook started.

▲▼ mv419:10 hn>

Ex-Meta employee here, used to work on AI infra and privacy.

I felt every agentic product was focusing on personal accounts. So I started building a platform for small teams and households (where you can have a personal workspace and a shared workspace). I am now testing it with friends and family, so if anyone wants an invite - join the list.

https://getcinnamon.ai/

How it's different:

1) personal (private) and group context (e.g. household) 2) multiple guardrails 3) different architecture (not spinning up a VM for every user) while still protecting personal data 4) not run by Meta

▲▼ mv419:32 hn>

I forgot about the downvotes! OK I will need to do a proper Show HN at some point.

▲▼ malshe19:56 hn>

This one is from a tweet that posted a screenshot of the transcript between their Muse agent and a plumber:

Call transcript with Guerra's Plumbing, Englewood, CO at September 17, 2026, 1:32 PM

Recipient: This is Robert.

Muse: Hi, this is Brett calling on Ankit Gordhandas’s behalf. I'll be transcribing this call for notes. I'm looking for a quote to install three customer-supplied bidet sprayers. Can you help with that?

Recipient: Can you soak my dick?

Muse: I'm just calling about the installation quote. Is there someone there who can help with plumbing pricing?