πŸ›  🍎 πŸ‘Ύ Objective-See'ing & DoubleYou'ing

Maui, HI
Stoked for the next (ad)venture: "DoubleYou" techcrunch.com/2024/04/25/ex… Cofounded w/ long-time friend @hexlogic, we're empowering those building security tools for Apple devices πŸŽπŸ›‘οΈ And by bootstrapping this venture, our core value of democratizing security remains our focus!
22
31
186
45,469
security? privacy? 😬
what we've shipped: muse β™₯️ ton of connectors πŸ”§ muse invite codes πŸ’Œ muse phone call beta ☎️ muse for mac ο£Ώ muse in canada πŸ‡¨πŸ‡¦ muse connector platform πŸ› οΈ muse mac computer use πŸ’» muse for small business πŸ’Ό muse gadgets πŸ•ΉοΈ muse memes 🀑 no butthole 🍰 what should we ship next?
2
3
33
2,874
Patrick Wardle retweeted
Replying to @patrickwardle
I read: "We will add more prompts or clicks to approve FDA". 🀯 The entire FDA thing should be redesigned from scratch, it's been always horrible and it just gets worse.
3
1
11
1,906
Last week, our @patrickwardle spoke with @ThomasClaburn at @TheRegister about this exact issue: AI apps "undoing" Apple's hard work on security & privacy. Great to see @Apple jumping into action to protect the security & privacy of its users. Read: theregister.com/ai-and-ml/20…
Apple is already understandably annoyed by poorly written/insecure/greedy AI agents/assistants insisting on Full Disk Access, and then once granted/obtained, abusing that, to access <all the things>. ...that didn't take long!
1
2
7
1,440
Replying to @patrickwardle
Those apps behave maliciously by any standards. Yet Apple provides them in the App Store and notarises those delivered direct. Doesn't Apple accept any responsibility for approving them?
1
2
7
1,300
Smart way to limit AI agents! πŸ‘ But, @Apple, please don't make Full Disk Access changes harder for macOS Endpoint Security tools! They (per your design) require FDA plus a special entitlement you only grant after vetting, so please keep them easy for users to install! πŸ™
Apple is already understandably annoyed by poorly written/insecure/greedy AI agents/assistants insisting on Full Disk Access, and then once granted/obtained, abusing that, to access <all the things>. ...that didn't take long!
4
2
55
4,151
Patrick Wardle retweeted
A fake Zoom installer found by #JamfThreatLabs hides a stolen macOS password inside a config file using invisible Unicode characters. CloudSyncD uses that password once to launch a backdoor with elevated access. okt.to/SHA3m2 #CybersecurityAwarenessMonth
3
7
1,456
But its not secure 😩 Exhibit A: prompt injection (via local attack against ChatGPT)
dot is my favorite openai product so far! it is amazing to me that each day it feels noticably better as it learns more of my workflow and style. having it do the stuff i don't like doing--and usually just builds up as a gravity well of dread--has me very happy.
6
46
8,283
Maybe Apple read about our research 🀭 Either way, happy to see them taking steps to limit the granting of Full Disk Access (FDA)! techcrunch.com/2026/10/02/ap…
Mahalo to @WIRED for covering our initial research into ChatGPT (CVE-2026-100754) Traditionally, protecting the privacy & security of Apple users meant focusing on malware & attackers...now, AI agents belong in that threat model too πŸ€–βš οΈ More bugs reported, so stay tuned... πŸ‘€
3
5
36
3,821
Apple is already understandably annoyed by poorly written/insecure/greedy AI agents/assistants insisting on Full Disk Access, and then once granted/obtained, abusing that, to access <all the things>. ...that didn't take long!
Apple says it will add new controls around macOS’s Full Disk Access permission, warning that increasingly capable AI agents make broad access to users’ files, messages, mail, and browsing history riskier. spr.ly/6010BGvtfn
23
33
584
36,471
Patrick Wardle retweeted
Apple just announced big changes to Full Disk Access in macOS! When will it ship? What will the new approval look like? Will existing FDA approvals be affected? What about existing MDM/PPPC profiles? Will enterprise & security tools get different treatment from AI or other apps?
3
14
121
7,730
Patrick Wardle retweeted
Shots fired? Apple plans to introduce new privacy controls for Mac users, warning of the growing risks around granting broad data access to third-party software, including AI agents bloomberg.com/news/articles/…
69
58
780
427,924
I'd say patch, but at this point, it (still) doesn't matter 🫠
Mahalo to @WIRED for covering our initial research into ChatGPT (CVE-2026-100754) Traditionally, protecting the privacy & security of Apple users meant focusing on malware & attackers...now, AI agents belong in that threat model too πŸ€–βš οΈ More bugs reported, so stay tuned... πŸ‘€
2
1
17
2,691
The hardest part was getting Dots working in Europe, to test the exploit πŸ˜…
0-day flaws in ChatGPT let a local unprivileged attacker bypass OpenAI's safeguards, subvert the agent on macOS, and take over your Dot. Responsibly reported to (and ack'd by) OpenAI. Our research into the (in)security of AI agents continues... 🫠
2
1
25
3,050
Patrick Wardle retweeted
Lot of people are misunderstanding this. This was NOT an LLM going off reservation. This was a *product* decision that the @Muse team made to tell the LLM to go search things daily, and *that* is what made Muse go against my instructions. This is not an AI problem. This is a problem with the Muse product team.
So @Muse said it only searched gmail when I asked. But it scanned my email daily without permission, then made up explanations twice when I caught it. No setting to stop the surveillance β€” only a kill switch for Gmail completely.
18
17
105
18,201
One of my favorite parts of #OBTS is the students. Congrats to this year's scholars, stoked to meet you all!
Congrats to our #OBTS v9.0 student scholars! From ~100 applications (thank you all!), our Objective-We program is supporting these scholars with full or partial scholarships, covering tickets, training, travel, & lodging at #OBTS v9 Mahalo to our supporters @OpenAI & @addigy πŸ™
3
15
1,990
Patrick Wardle retweeted
a tale of agentic ai in 3 tweets
24
84
3,652
172,992
Patrick Wardle retweeted
On today's front page of @nytimes OpenAI Failed to Heed Alerts About Security and Breach at F.B.I. Leaves Workers Fearful of Risks
2
4
27
3,040
Patrick Wardle retweeted
CVE-2026-86950: The Great Glyph Grift calif.io/research/the-great-…
4
77
240
43,245
CVE-2026-100754: ChatGPT's code-signing checks on macOS/Windows can be bypassed by (local, unprivileged) attackers, who then inherits the agent's trust: πŸ’‰ Inject prompts πŸ‘€ Read private chats πŸ”“ Access TCC-protected files πŸͺ Steal cookies/auth tokens/browsing sessions
Security & privacy used to mean fighting malware and hackers ...now, we have to add "AI agents" to that threat model πŸ€– πŸ˜… Mahalo to the @nytimes for spotlighting some of our recent ChatGPT research & bugs! nytimes.com/2026/09/29/techn…
5
24
114
9,718