Apple and a Hacker’s Future – Stratechery by Ben Thompson

My laptop bought hacked; the vulnerability that was exploited is detailed in this Ars Technica story:
Dutch officers have warned {that a} high-severity macOS vulnerability that enables attackers to execute malicious code is beneath energetic exploitation. “The NCSC has obtained a notification indicating that energetic abuse of this vulnerability has been noticed on a number of methods on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum warned earlier this week. “In all these instances, root had been accessed on the affected system and a Monero crypto miner had been positioned.”
The vulnerability, tracked as CVE-2026-65400, obtained a patch from Apple final week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity score of seven.1 out of 10, stems from a bug within the macOS display sharing functionality, which permits a distant get together to view the display and management the keyboard and mouse whereas a machine is turned on. A flaw within the “state administration,” which retains observe of previous occasions, person interactions, variables, and different system states, is the underlying trigger.
A video of the exploit in motion may be discovered here. Details of CVE-2026-65400 became public eventually week’s Black Hat safety convention. Apple stated final week that CVE-2026-65400 “might” enable an attacker with out credentials to achieve entry to a Mac. It’s unclear why Apple hedged, however softening language is widespread amongst most tech builders when disclosing vulnerabilities. Apple credited safety agency Bynario for reporting the vulnerability.
The laptop in query was my always-on Mac Mini that runs nothing however Claude and Codex; the very first thing that makes this story attention-grabbing is that that was my saving grace.
Agent Protection
I’ve mentioned, in each Writing Things Down and in a number of episodes of Sharp Tech, Gecko, the agent that I’ve constructed for the folks that work with me. It’s superior, however purposely constrained in functionality and in what it might probably entry. My actual agent is a devoted Claude Code thread that writes down all of my concepts and tracks the standing of the myriad of initiatives I’ve spun up over the previous few months.
There are just a few the reason why I exploit Claude for this performance, regardless that I’m not a giant fan of Claude-speak: Claude in its Code harness appears to deal with wide-ranging discussions higher than Codex, and it follows my directions about writing issues down in the way in which I need to extra gracefully. Code additionally has a persistent monitoring tool that I make the most of as an inbox to seize interactions with a standing board I constructed to visually observe every little thing I’ve written down, in addition to interactions with a Telegram bot (OpenAI’s new Dots achieve some of this functionality, which has been sorely wanted in ChatGPT/Codex).
Said monitoring device stands down each half-hour, so my agent restarts it on a schedule; that’s what triggered an URGENT notification from Claude:
Claude had extra diagnostic data, unilaterally stopped executing all instructions, and famous that my account may now run admin instructions with out a password, which it assumed was how the information had been written; it then had a variety of instructed subsequent steps to handle the issue. The one I ignored was its advice that I not invoke Claude anymore; in reality, I used Claude to root out the malware — we ultimately discovered the precise 4 second interval the place it gained entry — create a device to look at for it sooner or later, after which wiped the Mac Mini.
All of this occurred earlier than I discovered the Ars Technica article detailing the vulnerability, and it was fairly outstanding. I perceive that persons are nervous about giving these brokers entry to at least one’s laptop — as I famous, the Mac Mini in query has nothing on it aside from Codex and Claude — however on this case you can make the case that I might have been in way more bother had I not had an agent working persistently.
Apple Protection
Apple doesn’t appear too pleased about brokers; final week the corporate’s developer website launched a word entitled Updates to Full Disk Access in macOS; I’m going to cite it in full:
We give builders highly effective APIs to construct unbelievable capabilities into their apps for Apple merchandise, backed by a set of controls designed to guard customers’ personal information. Full Disk Access largely sidesteps these controls in an effort to enable backup apps to perform correctly on the Mac. Some builders are utilizing Full Disk Access in ways in which may put customers in danger, exposing every little thing on their methods—together with information, mail, messages, and even shopping historical past—with out customers’ full information and understanding. For communication apps, this will additionally compromise the privateness of the individuals customers are speaking with.
Going ahead, we are going to introduce extra controls to make sure that customers who genuinely want to grant an app this extraordinary degree of entry can solely achieve this with very express person motion. Addressing that is vital. As AI brokers change into more and more succesful and autonomous, the dangers related to this degree of entry will develop considerably. We are dedicated to making sure customers clearly perceive these dangers earlier than granting such entry, to allow them to make knowledgeable selections about their very own information and privateness.
To say that I’m nervous about what Apple’s resolution will entail is an enormous understatement. There is one side by which the Mac is the right agent host: Apple has, for many years, invested in a mixture of scriptability, automation, and accessibility APIs (these are fairly often the identical factor) that makes it remarkably well-suited to laptop use. Then there may be the truth that macOS is a licensed Unix system; which means that brokers — that are completely suited to the command line — have entry to the complete universe of tooling constructed for Unix methods. And, after all, Mac {hardware} is wonderful.
The downside is that for my specific use case — a headless, always-on Mac Mini that I primarily entry from different computer systems and my telephone via the ChatGPT and Claude apps — macOS is extremely hostile. The largest difficulty is GUI-only permission prompts which might be invisible to software program working on stated laptop, together with brokers.
These permission prompts are part of a macOS subsystem referred to as Transparency, Consent, and Control (TCC), though Apple doesn’t appear to make use of this identify anymore. There are a complete host of issues in your Mac which might be coated by TCC — the checklist solely will get longer with each OS launch — and you must explicitly approve entry to the coated gadgets for each app that wishes to entry them. If you’ve been prompted for permission to make use of the Camera, or, way more annoyingly, entry the Desktop or Downloads, you’ve encountered TCC.
This system is annoying however manageable in your major Mac; it’s a catastrophe on a headless Mac working brokers, for 2 causes. First, brokers write new packages the entire time, and in my case, these packages want entry to units on my community (SMB shares, for instance, set off a TCC warning). What I would like is a permission layer for brokers, not the packages they create; TCC is working on the mistaken degree of abstraction.
Second, the TCC subsystem exposes its immediate in a protected house that no program can see; that signifies that packages silently fail and the brokers don’t know why; what I’ve to do is keep in mind that there’s most likely a permissions immediate on display, log into the Mac Mini with screen-sharing software program, and click on OK.
There are in reality good causes for this. The purpose of the TCC subsystem is to guard you from malware accessing your laptop nefariously; if the prompts had been accessible by software program working in userland then malware may work round it. Again, although, I’m working a pc that’s purpose-deployed for brokers: for my use case TCC is nothing however a headache — one which not directly led to my being hacked.
Apple Frustration
Again from Ars Technica:
As famous by the NCSC, the vulnerability is being exploited when port 5900 is uncovered to the Internet. When display sharing is turned on, the macOS firewall opens the port. Routers and devoted firewalls typically block the port until configured to override that setting. Security practitioners typically advise Mac customers to maintain the port closed even when utilizing display sharing and to as a substitute join over a VPN or via SSH tunneling. The alternate options require actions that aren’t inside the capabilities of most customers.
The most secure observe is to dam display sharing, allow it solely when display sharing is required, and to show the function off as soon as a session has ended. Screen sharing may be turned on or off by accessing System Settings > General > Sharing and toggling the change for Screen Sharing. Of course, putting in final week’s safety replace can be a should.
Obviously I ought to have — and shall be — utilizing a VPN going ahead (the muse of my total strategy to safety is Tailscale); what I’ll word, nonetheless, is that TCC principally leaves me no alternative however to have display sharing enabled if I need to truly use my Mac Mini in the way in which I need to use it. I exploit screen-sharing continuously — together with from my telephone — and virtually each time it’s to click on “OK” on a silly immediate that I’ve lengthy since stopped taking severely.
What actually irks me about this episode, nonetheless, is how Apple launched the repair. Obviously I do know that it’s best to at all times preserve your laptop up-to-date for safety functions; that’s why I’ve all of my computer systems set to routinely set up safety updates.

What I didn’t perceive is that this setting doesn’t in reality apply to most safety updates. CVE fixes virtually at all times arrive in level releases; in reality, the latest level launch was about fixing this bug. In truth, I immediately realized that I had been leaving myself extra uncovered than I ought to have been for years, beneath the mistaken assumption that checking “Install…safety updates routinely” would in reality set up safety updates routinely.
I’m admittedly being pedantic right here; on the finish of the day I hadn’t put in the purpose launch promptly sufficient. Still, it does bug me that an organization that’s so involved about entry to my Desktop wasn’t very involved about how a fairly essential setting reads to a reasonably subtle person. Again, that is my mistake, however the mistake was an sincere one downstream of trusting Apple to name a safety replace a safety replace, notably if they provide the choice to routinely set up them.
That’s belief they’ve by-and-large earned; what’s more and more irritating is that that’s belief they more and more demand, and the scope of these calls for is frequently rising. It could seem foolish to complain concerning the labeling of an replace, however in the event you’re going to demand permission for accessing a community share are you able to a minimum of patch my laptop after I explicitly gave you permission to?
This, by extension, is why the word about full disk entry is unnerving. I can perceive that customers might not perceive that granting an agent full disk entry signifies that that agent can learn your iMessages (for now — I wager that the iMessage retailer shall be encrypted within the close to future, a la iTunes in the 2000s); different customers, nonetheless, might want precisely that. Or, like me, they may need to truly use a Mac as their very own private laptop, not as an Apple-managed machine more and more akin to an iPhone. Maybe this episode exhibits I’m too dumb to danger that; possibly it simply means Apple and I are, after a few years collectively, talking previous one another.
Home Visions
Last week Mark Gurman wrote an article on Bloomberg entitled Apple Is Finally Ready to Enter Its Next Big Category: the Smart Home:
Apple Inc. plans to make its long-delayed push into the smart-home market on Oct. 13, marking a vital product enlargement for the corporate beneath new Chief Executive Officer John Ternus. At the middle of the technique is a smart-home hub code-named J490, in line with individuals conversant in the matter. Apple additionally plans to announce the primary replace to the HomePod mini since that machine’s 2020 debut and its first new TV set-top field since 2022…
The merchandise additionally function a showcase for Apple’s new Siri AI assistant, expertise that the corporate spent years creating. The revamped Siri suffered quite a few delays, and the smart-home units ought to assist highlight Apple’s efforts to lastly catch up in synthetic intelligence. The dwelling hub will take the type of a roughly 6-inch sq. show, with variations that may be mounted on a wall or positioned on a countertop, in line with the individuals, who requested to not be recognized as a result of the merchandise haven’t been introduced…
Apple envisions clients inserting a number of of the shows all through their properties. They might be used to manage thermostats, door locks and different related merchandise, in addition to for video calls, intercom-style communication, music playback and viewing slideshows of pictures saved in Apple’s iCloud service.
That wasn’t the one dwelling automation associated announcement final week; Muse creator Nat Friedman posted on X:

I get, very acutely, that I’m not consultant of the final inhabitants. I truly use brokers, for one. More than that, I’m not a goal buyer for Muse: I’m extra eager about constructing my very own agent than in utilizing Meta’s; one in every of my present initiatives is the development of a small dwelling electronics lab to make a few of my very own agent-controlled gizmos.
With that famous, what struck me about Gurman’s article is simply how unenthused I’m by an Apple smarthome product. Some of that is fatigue from a decade of Siri disappointment and skepticism concerning the firm’s skill to ship on a voice-centric product. More than that, nonetheless, I bristle on the concept of introducing Apple’s constraints to extra components of my life.
Those constraints aren’t nearly issues like full disk entry. To the extent that Apple delivers on integration with issues like thermostats and door locks is the extent to which they work with Third-party machine makers; the issue is that third get together machine makers largely suck, notably from a software program perspective. Even if Siri had been excellent, Apple may have the problem of delivering an expertise that isn’t outlined by the bottom widespread denominator.
What I’m way more eager about is controlling the software program layer myself. The truth of the matter is that with AI you possibly can decompile virtually all present software program — there’s a revolution taking place in gaming over the previous few weeks, as game after game is decompiled to source and ported to any platform you want — and you may write your personal. That means my software program that interacts with my agent in the way in which I would like it to for every little thing; that’s far more thrilling than praying Apple delivers the appropriate API and that Third-party builders don’t suck.
The App Limitation
This, by the way in which, is an issue going through Siri; I wrote after the recent iPhone event and Ternus’ imaginative and prescient of the “Intelligent Personal Hub”:
What is most attention-grabbing, nonetheless, is how the largest benefit Apple has historically had could also be a hindrance…it’s extraordinarily spectacular that Apple claims 300,000 apps work with Siri. Note, nonetheless, that the implication of it being “simple for builders to undertake new capabilities” is that builders have to truly put within the work — that’s work along with updating their UI for Duo.
In a globe the place everybody has to persuade builders to construct integrations, this wouldn’t be a problem. However, that is the place browser use looms massive: to the extent that brokers can simply use the net is the extent to which they get an integration with principally every little thing totally free, and it’s Apple, with its dependency on builders plugging into APIs, who’s at a drawback…
In Apple’s imaginative and prescient, the utility of Intelligence is outlined by its skill to enhance your present workflow. Thus the reference to updating your calendar and reminders. It’s very attainable, nonetheless, that the higher workflow is to outsource numerous work that used to occur in apps to the agent straight. What’s higher, utilizing a structured reminders app that you must test, or just being reminded straight by an agent? In fact the reply will possible fluctuate by individual, but it surely’s price mentioning that Apple is so married to the app paradigm that they most likely by no means even thought-about the choice.
Apps had been wonderful, and a greater expertise than what got here earlier than; that doesn’t imply they’re one of the best expertise, and anybody who has severely used an agent is aware of precisely what I imply. Apps get in the way in which, which is to say that integrating with them is to make your agent worse; I don’t desire a completely different UI per app, when I’ve at my disposal true UI — the Universal Interface for every little thing digital.
This is the place the Muse Gadgets program is a stroke of genius. Meta is seeding a complete ecosystem of units, a few of which could change into actual merchandise, and it’s utterly open supply. The payoff isn’t in promoting units; it’s in Muse being the interface for every little thing.
A Hacker’s Future
21 years in the past Paul Graham wrote Return of the Mac:
All one of the best hackers I do know are regularly switching to Macs. The purpose, after all, is OS X. Powerbooks are fantastically designed and run FreeBSD. What extra do it is advisable know?…
With OS X, the hackers are again. When I walked into the Apple retailer in Cambridge, it was like coming dwelling. Much was modified, however there was nonetheless that Apple coolness within the air, that feeling that the present was being run by somebody who actually cared, as a substitute of random company deal-makers.
So what, the trade globe might say. Who cares if hackers like Apple once more? How massive is the hacker market, in spite of everything?
Quite small, however essential out of proportion to its measurement. When it involves computer systems, what hackers are doing now, everybody shall be doing in ten years. Almost all expertise, from Unix to bitmapped shows to the Web, turned standard first inside CS departments and analysis labs, and regularly unfold to the remainder of the globe.
As somebody who switched to the Mac in 2004, a 12 months earlier than Graham wrote his article, this was edifying: “I simply switched to the Mac, I suppose I’m a cool hacker”. In fact, the Unix half didn’t matter a lot to me; I most well-liked the design and the UI, and actually needed to attempt GarageBand. And, over the following years, I appreciated the extent to which the Mac simply labored — slower than the alternate options at first, then at parity, after which, with Apple Silicon, higher than anything.
The factor about AI, nonetheless, notably brokers, is that they make anybody a hacker. You actually can do something now, if solely you could have the volition and the concepts, and when you embrace that, a walled backyard feels much less like safety and extra like a jail.
I’m not, to be clear, predicting Apple’s downfall; I’m not even altering my laptop or telephone. What is stunning to me, nonetheless, is that not solely am I uninterested within the firm’s dwelling machine, I can, for the primary time, envision a future the place I don’t purchase Apple by default. Indeed, this already occurred: even earlier than this incident I had already bought a brand new server, which can run Linux; I’ll by no means put a Mac in a rack once more.
That’s fantastic for Apple, after all; that’s not what their computer systems had been designed for. The query, nonetheless, is whether or not what they’re designed for is the long run I’m barreling in direction of, one the place agentic abstraction each renders conventional interfaces relics even because it makes computing all over the place extra accessible than it has ever been, the place the restrict will not be a developer constructing for scale however my very own creativeness constructing for myself.
