Menu
Log in


  • 8 Jul 2026 8:25 AM | Terry Findlay (Administrator)

    ADAM ENGST 24 June 2026

    If you’ve been reading any media coverage of AI, you’ve probably gotten the idea that Silicon Valley has decided that we’re all going to be using AI agents to help with the tedium of our everyday lives.

    I’m pretty technical, generally game for trying new things, and reasonably enthusiastic about the benefits of AI in general. I think AI chatbots backed by Web searches significantly outperform classic search engines, AI editing tools like Grammarly do an excellent job of eliminating mistakes and infelicitous wording, and AI coding is the most fun I’ve had building something on a Mac since HyperCard.

    But I’m baffled by the talk of autonomous AI-powered agents like OpenClaw. The breathless examples that are bandied about seem either trivial, impossible for an AI to complete without reading my mind, or something I wouldn’t delegate to hardly anyone. Among much else, AI agents are supposedly going to:

    • Schedule meetings and appointments
    • Make restaurant reservations
    • Buy event tickets
    • Book flights and hotel reservations
    • Research and buy products
    • Respond to email, messages, and social media posts
    • Plan group events with friends
    • Deal with customer service disputes

    Even setting aside my skepticism that an AI agent could actually accomplish any of these tasks, I’m horrified at the idea of one doing them for me. I may be a bit of a control freak, but the only person I’d trust to do most of these things is Tonya, and even then, she’d confirm with me before committing to anything. (As I would with her.) That trust was built over decades of living together, but AI agent proponents seem to expect the same level of trust on day one.

    I’ve identified a handful of reasons why all this AI agent talk fills me with dread. See if my reticence resonates with you or if you think I’m merely yelling at the AI agents to get off my lawn:

    • Minimal labor savings: Some of the supposed ways an AI agent will save me time are simply spurious. There’s minimal effort in clicking an Unsubscribe link in a newsletter I no longer want (and only I know when I no longer want it). I rarely want to track a package, but when I do, it’s merely a matter of clicking a link if I haven’t already been inundated with delivery status emails.
    • Missing my internal context: No matter how much context an AI thinks it will have, it can’t know everything I know, particularly my internal goals and desires. How will it reply to emails or texts for me without knowing how I want to respond, especially since each response will be tailored to the individual and situation? How could it guess where I’d want to eat dinner without knowing what I’m in the mood to eat and how far I’m willing to drive that particular night?
    • Lost information I need: Information that comes through my devices falls into three categories: important details that I have to know, information that interests me but I don’t need to retain (see “Reading Doesn’t Fill a Database, It Trains Your Internal LLM,” 28 February 2026), and stuff that’s neither important nor interesting… unless it becomes one or the other for some reason. For instance, I don’t care about email from Tompkins County about roadwork unless I need to drive on one of those roads that day. The relevance of those emails is contextual and changes daily, and only I know which bucket a given piece of information falls into on a given day. An AI agent would constantly have to ask me to recalibrate, which defeats the point of delegating.
    • Unacceptably high stakes: For many tasks, the risks of having them done badly are too high to even consider handing them off to an AI agent. I always double and triple-check my own travel arrangements because getting it wrong could mean missing part of a conference. If I have to check an AI’s work that carefully, I might as well do it myself.
    • Discomfort with mimicry: Even if an AI could respond to email or text messages accurately and at least roughly in my voice, I’m uncomfortable having someone or something speak for me. It’s not just my comfort at stake—the person on the other end thinks they’re hearing from me, not an AI, and that’s a deception even if the content is accurate. If they later find out an AI wrote that text, they’ll reassess how they read other things I’ve written. That’s why my Driving Focus auto-reply is upfront about who’s actually talking: “Good day, human! This is Adam’s iPhone. He’s driving right now, and while he swears he’s an Above Average™ driver, it’s best not to interrupt him unless it’s urgent. I’ll inform him of your message once he parks the car.”
    • Problematic spending: When I do manage to overcome my innate frugality, I want to be certain I’m getting precisely what I want. I can’t imagine giving an AI agent permission to spend money on my behalf.
    • No net benefit: I’m a great believer in automation, but as Randall Munroe has pointed out in xkcd (more than once), it’s important to ensure the effort saved outweighs the effort invested. Training a human assistant is time-consuming; training and maintaining an AI assistant feels like it would be vastly more work than just doing the tasks myself. Even getting a chatbot to respond to simple queries in ways I want has taken non-trivial amounts of training.

    Ultimately, I wonder if some of the enthusiasm for AI agents comes from people who are sufficiently busy, wealthy, and senior that they’re accustomed to at least the idea of having human assistants. 

    Years ago, when Tonya and I were struggling with an overwhelming amount of work on TidBITS, Take Control, and parenthood, advice pundits were recommending offloading and outsourcing mundane tasks. We tried hiring a personal assistant for a while, but the experiment wasn’t a success, for many of the same reasons as I’ve outlined above. Too many tasks required personal knowledge, needed a personal touch, or were beyond our assistant’s skill set.

    So I’m sure some people benefit from having an AI agent manage aspects of their lives, but I can’t imagine how it would work for me or for most people. And since even one hesitation about what an autonomous AI agent might do is to stop someone from trying one, it’s hard to see this field taking off.

    But how about you? If you’ve tried an autonomous AI agent, how has it worked out for you? Have you worked with a human assistant, and if so, what lessons from that would you apply to an AI agent?

  • 8 Jul 2026 8:25 AM | Terry Findlay (Administrator)

    ADAM ENGST 22 June 2026

    Ryan Moulton writes:

    There are colors that I want to show you, but I can’t. They exist in the real world. You probably saw some of them today, but I can’t show them to you on a screen. A digital photograph can’t capture them, and your screen can’t display them. No game you’ve ever played has contained them. Unless you have specialized equipment, they are entirely absent from the digital world.

    Moulton’s article is necessarily a bit technical, but he does a good job of explaining why colors in the real world—a butterfly’s wing, a peacock’s plumage, a tropical lagoon, a deciduous forest on a sunny summer afternoon—are so much more visually arresting than images that can be displayed on screen. Apple makes much of its display specs—the Studio Display has support for 1 billion colors with a P3 wide color gamut—but as Moulton shows, the technology involved in mixing red, green, and blue as the three primary screen colors creates a situation where some colors—most of the cyans—simply can’t be reproduced. Read it to understand why your digital photos don’t always fully capture what you saw, and savor the next time you find yourself in the presence of real-world color that no Retina display can deliver.

    Forest in summer

    Read original article

  • 8 Jul 2026 8:22 AM | Terry Findlay (Administrator)

    Andrew Orr

    1

    Thu Jul 02 2026, 09:02 AM EDT · 3 minute read

    PamStealer

    A newly discovered macOS infostealer verifies Mac login passwords before stealing sensitive data, giving attackers immediate confirmation that compromised credentials will actually work.

    Researchers at Jamf Threat Labs have documented a new macOS malware campaign built around an infostealer called PamStealer. PamStealer disguises itself as the Maccy clipboard manager and uses AppleScript alongside a Rust payload to infect Macs.

    Jamf found that PamStealer verifies login passwords through Apple's Pluggable Authentication Modules before stealing additional data. Password verification sets PamStealer apart from most macOS infostealers, which typically capture whatever password a victim enters without confirming that it's valid.

    The campaign begins with a fake website that closely imitates the legitimate Maccy clipboard manager. Next, the fake website delivers a malicious AppleScript application disguised as Maccy.

    Once a victim opens the download, the malicious application checks the system and retrieves a second-stage Rust payload. PamStealer then establishes persistence before collecting data.

    Webpage showing Download Maccy button with text describing a free, open-source clipboard manager for macOS, plus small tags listing version, macOS compatibility, Apple silicon support, license, and file sizeThe campaign begins with a fake website that closely imitates the legitimate Maccy clipboard manager

    Jamf also found that PamStealer checks system characteristics, keyboard layout and regional settings before running. System, keyboard and regional checks suggest the operators configured PamStealer to execute only on systems that match their intended targets.

    Password verification improves the value of stolen credentials

    PamStealer's most notable feature is the way it captures login credentials. During execution, the malware displays what appears to be a legitimate macOS authorization prompt asking the user to enter a password so Maccy can make changes.

    Instead of just recording whatever the victim types, PamStealer validates the password through Apple's Pluggable Authentication Modules before continuing. Jamf said PamStealer doesn't replace or bypass Apple's authentication system.

    Instead, the malware abuses a legitimate macOS framework to validate credentials after convincing the victim to enter a password. Attackers can then discard invalid credentials before moving forward with the attack.


    Rust payload steals browser data and establishes persistence

    After validating the password, the second-stage Rust payload collects a wide range of information from the infected Mac. Jamf said PamStealer targets browser cookies, browsing history, saved credentials, SQLite databases, clipboard contents and cryptocurrency wallet data.

    PamStealer also encrypts stolen information before transmitting it to command-and-control infrastructure, making network traffic more difficult to inspect.

    PamStealer creates login items through both modern and legacy macOS mechanisms so it relaunches automatically after a user signs in. The malware also impersonates Finder while attempting to convince victims to grant Full Disk Access.

    Full Disk Access is a permission that would significantly expand the amount of information it can access without additional prompts.

    Two dark-themed code editor windows on a desktop, each showing different JavaScript code snippets with syntax highlighting, toolbar buttons at the top, and a small description area at the bottomPamStealer's most notable feature is the way it captures login credentials

    Jamf said much of PamStealer's second-stage malware is written in Rust instead of AppleScript. Using Rust makes reverse engineering more difficult because many strings and code paths are resolved only while the malware is running instead of appearing directly in the compiled binary.

    Native macOS features help make the attack more effective

    PamStealer shows how macOS malware increasingly abuses legitimate operating system features instead of relying solely on malicious code. Jamf said Apple's authentication framework, Rust and encrypted communications work together to make the malware more difficult to analyze.

    The researchers said the combination reflects the continued evolution of macOS-focused malware without relying on previously unknown vulnerabilities.

    Jamf recommends downloading software only from trusted sources. The company also urges users to be skeptical of unexpected administrator password prompts and avoid unnecessary Full Disk Access requests.

    Organizations using Jamf can configure Threat Prevention, Advanced Threat Controls and Web Protection to help block similar malware before it executes.

    How to stay safe

    PamStealer still depends on users downloading software from an untrusted source and approving multiple prompts before the malware can complete its attack. Users should download Mac apps only from trusted developers and verify website addresses before installing software.

    Unexpected requests for an administrator password deserve extra scrutiny, especially when they appear during an app installation. Users should also review Full Disk Access requests carefully and grant the permission only to applications they trust.

    Users should also review requests for Full Disk Access carefully and grant the permission only when it's necessary for software they trust. Keeping macOS and security software up to date can also help detect or block known malware before it compromises a system.


  • 8 Jul 2026 8:21 AM | Terry Findlay (Administrator)

    ADAM ENGST 8 June 2026

    I was looking for a tip to write for our TidBITS Content Network subscribers recently, and I remembered that iOS 26 added a feature that promised to alert you if your iPhone’s lens needed cleaning. Indeed, in the PDF listing all iOS 26 features, there it is, with a footnote that says it applies only to the iPhone 15 and later:

    Lens cleaning hint
    Camera will detect if the lens is smudged and display a message recommending cleaning it for the clearest possible photo.

    The feature is on by default, but if you don’t want these reminders for some reason (a lens that you know is scratched but aren’t fixing?), you can turn them off in Settings > Camera > Lens Cleaning Hints.

    iOS 26 lens cleaning hint switch

    Great! But before I started writing the tip, I thought the screenshot would be better as a two-up illustration, with one screenshot showing the message suggesting that I clean the screen. So I smudged the lenses on my iPhone 17 with fingerprints. But no message appeared.

    That sent me down to the kitchen to find something else that would smudge the lens more seriously. I dismissed anything greasy, like olive oil or salad dressing, that would make cleaning the lens after the test difficult. After casting around briefly, I saw a bowl of cherry tomatoes—perfect! I cut one in half and smeared its juices all over both lenses, complete with some seeds. (Yes, I subsequently ate the tomato.)

    Smudging the iPhone camera with a tomato

    Shockingly, when I opened the Camera app to take a picture, no message appeared, even though the resulting photo was an impressionistic masterpiece. I call it Landscape with Solanum Occlusion. If that doesn’t count as smudged, I don’t know what would.

    Smudged photo

    Curious as to whether this feature has worked for anyone, I did some searching and found a few postsnews articles, and YouTube videos that show the “Clean the camera lens” message appearing at the top of the Camera app’s viewfinder (though several were from the beta). So the feature has worked for some people in some situations, though no one was forthcoming about how they triggered it.

    Fearing my fingerprint test was too subtle and the tomato smear too extreme, I wondered if a light dusting of flour might hit the sweet spot. It didn’t—no message appeared. I’m not alone. Most of the videos I watched about the feature either failed to trigger the message or didn’t even attempt to show it, though only a few presenters acknowledged that fact.

    I give up. I can’t say that the lens cleaning hint feature is categorically broken, but I can say with some assurance that it doesn’t work on my iPhone 17 running iOS 26.5.1. Let us know in the comments if you’ve ever seen this message or if you can get it to appear reproducibly on your iPhone.

  • 8 Jul 2026 8:20 AM | Terry Findlay (Administrator)

    ADAM ENGST 26 June 2026

    When Tim Cook very carefully told the Wall Street Journal about upcoming price increases (see “Tim Cook Confirms Apple Will Raise Prices Due to Memory and Storage Costs,” 18 June 2026), we didn’t know whether it would happen right away or with the release of new products. Now we know—the company has just raised the prices of Macs and iPads, plus the Apple TV, HomePod, and Vision Pro. It also issued a statement to the press, saying:

    The consumer electronics industry is facing an unprecedented challenge. The rapid expansion of AI data centers has created an extraordinary surge in demand for memory and storage. We have never seen a component price increase this much, this quickly. We have shielded our customers from these increases so far, but we have now reached a point where we need to begin raising prices on a number of products, including today’s increases for iPad and Mac. We know this is not welcome news, and we are working tirelessly to find solutions.

    Unaffected—at least for now—are the iPhone, Apple Watch, AirPods, and Studio Displays. I suspect that the AirPods and Studio Displays have little enough memory that their margins are relatively unaffected by higher component costs.

    The iPhone and Apple Watch are a different story. The fact that Apple is willing to accept lower margins on them may mean that Apple feels that keeping prices lower will result in enough additional sales to offset the reduced profit per unit. It’s also possible that new models are due soon enough—probably in September—that it’s worth keeping prices stable until then.

    For the products whose prices did go up, the range is quite significant, as you can see in this spreadsheet I built with assistance from Claude and ChatGPT. The Apple TV 4K increased from $129 to $199, a $70 or 54% increase. That’s particularly odd, since the Apple TV only has 64 GB of storage and 4 GB of memory. It was already priced at a premium compared to competing products from Amazon, Roku, and Google, and the increase would put it at an even greater disadvantage. Community discussion suggests that Apple may be increasing the Apple TV’s price now in advance of a major hardware refresh that will seem more reasonably priced given the features it offers.

    On the low end is the Vision Pro, which increased from $3499 to $3699, a $200 or 6% increase. I’m surprised that Apple bothered to increase the Vision Pro’s already steep price, though I suppose that anyone willing to spend so much on such an unnecessary piece of hardware won’t blink at another $200.

    The average price hike was $266, and the average percent increase was 21%, although both were jacked up by a few outliers: the M3 Ultra Mac Studio’s $1300 price bump and the Apple TV 4K’s 54% increase. Speaking generally, it seems safe to say that Apple raised prices by 20%.

    But beyond that, I can’t really see any obvious trends. Devices with more memory and storage saw greater raw price increases, of course, but they already had higher prices, so their percentage increases weren’t necessarily larger.

    It’s also important to note that memory and storage upgrade prices have also increased. I wasn’t able to find a good source of data on what each upgrade cost previously, but some have jumped significantly. At Daring Fireball, John Gruber says most went up by 50%–67%, with the 64 GB and 128 GB memory upgrades for the M5 Max models of the MacBook Pro doubling in price.

    Ultimately, I suspect there’s little to be gained in trying to understand specific increases. Apple undoubtedly has a big-picture view of its product line that takes into account unit sales for each product, the type and quantity of chips each requires, and how soon a revision will be available to adjust pricing variables. In other words, each individual price increase—or lack thereof, in the case of the iPhone and Apple Watch—is just one piece of data in a much larger equation.

    Practically speaking, some retailers may not have raised prices yet, so you might still be able to score a Mac or iPad at the previous price, but that won’t last long. If you’re thinking of buying an iPhone in the near future, I would normally recommend waiting until September for the new models, but they’ll likely debut at higher prices. Buying a current-generation iPhone now may be the better deal. I’ve also seen rumorssuggesting that Apple will introduce only high-end iPhone 18 models in September, with the more affordable models held until the second quarter of 2027, which would encourage buying sooner rather than waiting. That iPhone 17 is looking pretty good at the moment.

  • 8 Jul 2026 8:14 AM | Terry Findlay (Administrator)

    Wesley Hilliard

    2

    Mon Jul 06 2026, 05:05 PM EDT · 2 minute read

    Apple warns users before sending prompts to Google Cloud

    Image generation features found in Apple Creator Studio rely on Google Cloud servers, but users will be warned before prompts are sent to the third-party AI tool.

    Apple Intelligence is powered by Apple Foundation Models found on your iPhone and in Apple's Private Cloud Compute servers. Those are distinct features and models from the integrations that utilize third-party AI tools like Google Cloud and ChatGPT.

    After updating to the latest Apple Creator Studio version, users are encountering a new pop-up, whether they are running iOS 26 or iOS 27. That pop-up warns that the user's prompt will be sent to a Google Cloud server, but won't be used for training.

    The warning is similar to what would appear when user queries were being sent to ChatGPT in previous versions of Apple Intelligence.

    To be perfectly clear: This is not a part of Apple Intelligence or Apple Foundation Models.

    Apple Foundation Models, not Google

    There has already been some confusion around this new warning and Apple's work with Google to implement Gemini technology in the new Apple Foundation Models. The Apple Foundation Models and resulting Apple Intelligence and Siri AI upgrades do not use any Google services, Google Search, Gemini Assistant, or Google frameworks.

    The Apple Foundation Models on your device and in Apple's Private Cloud Compute servers are Apple technology all the way down. Yes, the new models were built with Gemini Frontier models and servers at the foundation, but nothing Google remains in the shipping models.

    Apple is working to bring its most powerful Apple Foundation Models to Google servers with Nvidia GPUs, but via Private Cloud Compute. Those Google servers Apple uses for Private Cloud Compute are fully Apple's in operation, just like iCloud servers are when using AWS.

    When you go to generate a shape or image in Pages, Freeform, or any other Apple Creator Studio app that has these features, it is using Google Cloud. Users have the ability to accept the warning each time, or set it to always accept.

    The only data being sent in these instances is the text you've typed in the prompt or image sent to edit. And even then, just like with OpenAI's partnership, Google is unable to train on sent prompts or retain data from the interaction.

    The feature is wholly isolated to Apple Creator Studio, so if a user would prefer to avoid using Google Cloud, it is easy to do so. Although, those that do choose to use it can know that their data remains private for the interaction.

    Apple Creator Studio use of AI

    Since Apple Creator Studio AI features rely on external AI tools, there are limitations to what can be done. Apple shares the percentage of AI usage in app settings, and that usage gets reset each month.

    OpenAI provides ChatGPT for slide generation, and users can generate about 50 presentations with 8-10 slides each with their allotment. Google Cloud can generate 50 images or 250 shapes with its monthly allotment.

    Apple doesn't specify how many tokens a user has nor how many an event expends. It's up to the user to keep queries short to minimize use, and to monitor usage manually.

    The support document defining these features reiterates that zero data is used for training models.

Powered by Wild Apricot Membership Software