In a completely unsurprising turn of events, Meta’s Muse AI is stealing Apple Messages, past and present, and uploading the contents to its cloud, even if explicitly told not to.
How many times does it have to happen for folks to understand “telling an AI not to do something” doesn’t work reliably? Feels like the AI providers need to explicitly direct them to provide an explanation that such directives aren’t reliable and any expression of an agreement/promise doesn’t mean what one word intuitively think.
Same as Google reading the mail. Fuck US big brother tech.
Meta apps are usually spyware, yes.
Wait, Apple Messages aren’t e2ee? Or is it a question of color: green v. blue?
I don’t know the answer to this, but the AI agent would be at one of the “ends” of the conversation, so e2ee wouldn’t be a particularly relevant promise to that scenario.
They are stored in an sqlite database which hasn’t changed format all that much
Long story short, don’t install AI on your phone or the AIC will enjoy your conversations?
Just an FYI for anyone that didn’t know, your iMessages on your computer are literally just stored in a SQLite db. They’re very very easy to read without the app.
Source? AFAIK iMessages are stored encrypted by the Secure Enclave and can only be read through the same process that Touch ID works through. That’s why they can’t do iMessage through a browser because there must be a Secure Enclave present on the device. Pretty much the same reason Graphene OS only works on some devices.
Me? I wrote an app to read my iMessage database to pull two factor codes out and type them in automatically cause I was lazy.
Link to repo?
Seriously, this is the Internet… pics or it didn’t happen.
https://spin.atomicobject.com/search-imessage-sql/
This article is from years later. Seems like it got harder, but it’s still dead simple. Just give permission and then open the file.
This is describing the ability to read the messages from the actively booted and decrypted partition. This would absolutely not work without being able to log onto the machine. So while you are technically correct you are leaving out the caveat that this only works when you can also access the app not strictly without the app.
But the context is, that Meta’s software can extract them. For the software to run the system must be booted and the partition is likely already decrypted. So we’re exactly in this state.
Yes but the comment I was replying to implied that it could be done not in that state hence my question.
Is Android any better in this regard?
Not whatabouting, generally ignorant and curious.
I don’t think Android has a corresponding computer operating system so no? This doesn’t apply to iPhones or iPads. Just Macs. And I’m not even sure if it applies to M series MacBooks, but it applied to the old intel ones about 5 years ago at least which was the last time I read my messages that way.
Hard to have sympathy for anyone who willingly installs this on their device
Hard disagree! Yes, we know that Facebook does this. The average person doesn’t necessarily, and they still deserve privacy!
This victim blaming nonsense plays right into the corpo playbook. It’s the privacy equivalent of “with what she was wearing she was practically asking for it” and we all know that’s bullshit.
There’s a Metamucil joke somewhere in there, but I haven’t the energy
I am shocked.
Is the muse.ai logo supposed to be a sheep? If so, this story is pretty funny. Talk about the wolf in sheep’s clothing.
without consent
I’m surprised the EULA doesn’t say “by using Muse you agree to any fuckin’ thing Meta/Muse wants to do including ones we haven’t thought of yet”.
Not that that constitutes “consent” in my book, but I wouldn’t think the article would say “without consent” if there was something in the EULA permitting them to do basically anything.
wow. very shocker, many incrdible. wow!
Give apple $10,000 for a bigger drive to fix this one issue










