虎嗅

"Is the MacBook no longer secure?" OpenAI has hired an Apple employee to develop a plugin that allows users to write and send iMessages.

原文:“MacBook不再安全?”OpenAI招来个苹果员工做插件,可撰写并发送用户iMessage

Summary of Key Points

The relationship between Apple and OpenAI has descended into a dramatic situation of "fighting while also competing": Apple has sued OpenAI for stealing trade secrets, while OpenAI has released a plugin that can read and write iMessages on Mac devices. This plugin does not bypass Apple's security measures but instead utilizes permissions that Apple has itself made available to third-party apps (such as full disk access). Ironically, the team that developed the plugin consists of former key members of OpenAI who were once part of Apple's Shortcuts project. Meanwhile, Apple's own promised AI features have been delayed for two years, allowing OpenAI to take the lead and highlighting Apple's technical shortcomings and challenges in terms of security and privacy in the AI era.

Detailed Analysis

1. What can this plugin do, and why is it considered "legal" yet risky?

OpenAI's plugin is designed for macOS and can perform the following tasks: searching through iMessage/SMS/RCS message history, summarizing conversations, automatically drafting and sending replies, removing spam messages, and extracting birthdays from chat records to add them to the calendar (it can even handle messages from Android users). However, its "legality" is based on user authorization, which requires three critical permissions:

  • Full disk access: This is the most dangerous permission. Users may think it only allows the AI to read messages, but in reality, it gives the AI access to all protected content on the computer, including emails, Safari browsing history, and Time Machine backups.
  • Contact permissions: It allows the plugin to read contact names.
  • Automation permissions: It enables the AI to automatically send messages and perform other actions.

OpenAI claims that the plugin runs locally and does not index all messages. However, if users enable "persistent authorization" or scheduled tasks, the AI can send messages on their behalf without their confirmation, effectively handing over control of their messaging activities.

2. Why can the plugin work on Mac, but not on iPhone?

The security mechanisms between iPhone and Mac are vastly different:

  • The iPhone's sandbox: Each app runs in its own isolated environment and cannot access data from other apps, and there is no AppleScript (an automation tool), so the plugin cannot run on the iPhone.
  • Mac's historical background: Mac has a long history, and AppleScript has been around since 1993 (15 years before the App Store was established). These mechanisms were designed for enterprise automation and legacy software ecosystems. Apple cannot simply eliminate them without damaging a large number of applications and processes that rely on them. The plugin uses standard Mac system permissions, which Apple's review process and sandbox do not restrict. Any third-party developer can achieve similar functionality with user authorization.

3. Who developed the plugin, and why is it a blowback against Apple?

The team behind the plugin is made up of former key members of OpenAI who were once part of Apple's Shortcuts project:

  • The project leader, Ari Weinstein, worked on iOS automation apps called Workflow, which was acquired by Apple in 2017 and later evolved into the familiar Shortcuts. The team also includes former Apple employee Kim Beverett, who was responsible for Safari, Messages, and Mail. OpenAI has hired more than 400 former Apple employees, making this team well-versed in Apple's system permissions and automation frameworks. They know better than Apple itself which permissions can be effectively utilized.

4. The complex relationship between Apple and OpenAI

The relationship between the two companies is full of contradictions:

  • Litigation: Apple has sued OpenAI for stealing trade secrets, accusing former employees of using internal project codes to obtain information and of not returning computers and downloading confidential data after leaving the company. OpenAI has countered with claims that Apple sent incorrect emails and that the lawsuit is unfounded, submitting a motion to dismiss the case.
  • Cooperation: ChatGPT is still integrated into Siri, and Apple has stated that this cooperation is not covered by the lawsuit. However, Apple has also started collaborating with Google on AI (the new Siri uses Google's Gemini model), reducing its reliance on OpenAI. In other words, while Apple accuses OpenAI of theft, it continues to use its technology and seeks alternatives.

5. How can Apple respond?

Apple has remained silent about the plugin, but it could take the following actions:

  • Tighten permissions: In future macOS updates, Apple could refine the authorization process, for example, by separating the Messages database from the permission for full disk access and requiring additional confirmation from users.
  • Revoke the developer certificate: Apple could revoke OpenAI's developer ID, preventing the plugin from running on Mac, but this would lead to a complete breakdown in cooperation with Siri.
  • Use App Intents: Apple could use its new App Intents interface to restrict third-party apps, giving its own Siri more permissions and forcing third-party apps to use official, restricted channels.

However, no matter which option Apple chooses, it faces an awkward situation: It has been advocating for privacy as a fundamental human right for decades, but in the AI era, third-party apps are using these same permissions to provide services. Users want AI assistance, which means they have to share their data, creating a contradiction. Additionally, Apple's own AI features have been delayed, allowing OpenAI to take the lead and exposing Apple's technical weaknesses.

In Conclusion

Apple's security measures have not been "broken" but have been "legally exploited." This is more problematic for Apple because it has to balance protecting user privacy with maintaining its decades-old software ecosystem while trying to catch up with its competitors in the AI field. This battle is just beginning.