Muse privacy and trust
Sarah Perez has an update at TechCrunch on the story of whether Muse can read Messages.app’s database:
Meta is refuting a journalist’s claim that its AI agent Muse read the user’s private messages without permission. Following an earlier report from Inc. columnist Jason Aten that detailed the issue, Meta VP of Communications Andy Stone pushed back, making it clear that the company does not believe its product did this without the user’s consent.
I was curious about this too, so I added a bit of test code to Micro.blog for Mac (which like Muse is not sandboxed) to try to read Messages.app’s SQLite database on my own machine. It can’t do it. macOS blocks access at the system level unless Full Disk Access has been granted. No amount of mischief from Meta will be able to override this.
The other idea I had was that maybe Muse got clever and tried to script another app with Full Disk Access, like Terminal.app, to read the database. I prototyped this too. It triggers another modal system prompt to confirm access to control Terminal.app. Jason Aten would’ve noticed this.
Making everything murkier, Muse did clearly hallucinate the initial explanation of reading Jason’s notifications. But just because it made that up doesn’t mean that Meta is wrong that technically what happened shouldn’t be possible unless Jason allowed access. Unfortunately it’s really hard to go back in time and figure out exactly what went wrong.
Bottom line is that most people don’t trust Meta. Many people still think Instagram listens to your microphone to serve you targeted ads. There’s nothing to support that. I’m also pretty confident that Muse doesn’t read your Messages.app database without permission. But no amount of technical evidence from Meta is going to assuage people’s concerns, because Meta has a long history of other privacy violations. That trust will take a long time to rebuild, if it ever can.