Apple and a Hacker’s Future (Stratechery Article 10-5-2026)
- 01Theme: Persistent agents are becoming a security asset, not just a risk
- 02Theme: Apple's permission model is architecturally misaligned with agentic computing
- 03Theme: Agents on the open web may undercut Apple's app-and-API integration advantage
- 04Theme: AI collapses the build-vs-buy boundary, making "hackers" of everyone
1. Key Themes
Theme: Persistent agents are becoming a security asset, not just a risk
Thompson's hack story inverts the conventional wisdom that giving agents machine access is primarily a liability. His always-on agent detected the intrusion, halted itself, and helped remediate.
Substantiation:
- The agent surfaced the intrusion: "Said monitoring tool stands down every 30 minutes, so my agent restarts it on a schedule; that is what triggered an URGENT notification from Claude."
- It behaved cautiously and diagnostically: "Claude had more diagnostic information, unilaterally stopped executing all commands, and noted that my account could now run admin commands without a password."
- It was used for incident response: "I used Claude to root out the malware — we eventually found the exact four second period where it gained access — create a tool to watch for it in the future, and then wiped the Mac Mini."
- His conclusion: "you could make the case that I would have been in much more trouble had I not had an agent running persistently."
Theme: Apple's permission model is architecturally misaligned with agentic computing
Apple's privacy and security controls (TCC, Full Disk Access restrictions) were designed to protect users from malicious apps. They are now friction for legitimate agent use, and the friction pushes users toward less safe workarounds.
Substantiation:
- Wrong abstraction layer: "What I need is a permission layer for agents, not the programs they create; TCC is operating at the wrong level of abstraction."
- Agents fail silently: "the TCC subsystem exposes its prompt in a protected space that no program can see; that means that programs silently fail and the agents don't know why."
- The workaround created the vulnerability: "TCC basically leaves me no choice but to have screen sharing enabled if I want to actually use my Mac Mini in the way I want to use it... almost every time it's to click 'OK' on a stupid prompt."
- Apple is tightening, not loosening: "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially."
Theme: Agents on the open web may undercut Apple's app-and-API integration advantage
Apple's historic strength (a deep developer ecosystem plugging into system APIs) becomes a liability when agents can use the web directly and need no per-app integration.
Substantiation:
- From the post-iPhone-event analysis Thompson quotes: "to the extent that agents can just use the web is the extent to which they get an integration with basically everything for free, and it's Apple, with its dependency on developers plugging into APIs, who is at a disadvantage."
- On the app paradigm: "Apple is so married to the app paradigm that they probably never even considered the alternative."
- His framing: "Apps get in the way, which is to say that integrating with them is to make your agent worse; I don't want a different UI per app, when I have at my disposal true UI — the Universal Interface for everything digital."
Theme: AI collapses the build-vs-buy boundary, making "hackers" of everyone
When agents can write software and decompile existing software, the value of a curated, locked-down platform declines and user-controlled software layers become more attractive.
Substantiation:
- "with AI you can decompile almost all existing software — there is a revolution happening in gaming over the past few weeks, as game after game is decompiled to source and ported to any platform you wish — and you can write your own."
- "The thing about AI, however, particularly agents, is that they make anyone a hacker. You really can do anything now, if only you have the volition and the ideas, and once you embrace that, a walled garden feels less like protection and more like a prison."
- On smart home: "What I'm much more interested in is controlling the software layer myself... that's way more exciting than praying Apple delivers the right API and that 3rd-party developers don't suck."
2. Contrarian Perspectives
The walled garden is turning from a feature into a prison for the power-user vanguard
The consensus view is that Apple's controlled ecosystem is its moat and a security advantage. Thompson argues that for agent-native users the same controls become the problem. Citing Paul Graham, he notes that early adopters foreshadow mass behavior.
Supporting evidence:
- Thompson, a Mac user since 2004, is already moving off-platform: "even before this incident I had already purchased a new server, which will run Linux; I will never put a Mac in a rack again."
- He cites Graham on hackers as a leading indicator: "When it comes to computers, what hackers are doing now, everyone will be doing in ten years."
- He is careful not to overclaim: "I'm not, to be clear, predicting Apple's downfall; I'm not even changing my computer or phone." The shift is that "I can, for the first time, envision a future where I don't buy Apple by default."
Apple's smart-home push may be a weaker bet than it appears, even with better Siri
Gurman's reporting frames the October 13 home hub as Apple's "next big category" and a showcase for new Siri AI. Thompson is unenthused, arguing the platform constraints and third-party ecosystem quality cap the experience.
Supporting evidence:
- Third-party quality: "the problem is that third party device makers mostly suck, particularly from a software perspective. Even if Siri were perfect, Apple will have the challenge of delivering an experience that isn't defined by the lowest common denominator."
- Siri credibility: "fatigue from a decade of Siri disappointment and skepticism about the company's ability to deliver on a voice-centric product."
- Gurman notes the product's purpose: "The revamped Siri suffered numerous delays, and the smart-home devices should help spotlight Apple's efforts to finally catch up in artificial intelligence."
- Thompson flags an alternative: Meta's open-source Muse Gadgets is "a stroke of genius" because "The payoff isn't in selling devices; it's in Muse being the interface for everything."
"Automatically install security updates" doesn't actually install most security updates
A trust-and-labeling critique of Apple: a sophisticated user believed he was protected by an auto-update setting that excludes CVE fixes delivered as point releases.
Supporting evidence:
- "What I didn't understand is that this setting does not in fact apply to most security updates. CVE fixes almost always arrive in point releases... I had been leaving myself more exposed than I should have been for years."
- On the asymmetry of trust: "if you're going to demand permission for accessing a network share can you at least patch my computer when I explicitly gave you permission to?"
- The vulnerability itself (CVE-2026-65400, a screen-sharing flaw) was exploited on machines with port 5900 exposed to the Internet, with attackers gaining root and planting "a Monero crypto miner."
3. Companies Identified
Apple
- Description: Consumer hardware and software platform company.
- Why mentioned: Central subject. Its security model, permission architecture, and smart-home plans are examined as increasingly misaligned with agentic computing.
- Quotes: "Apple doesn't seem too happy about agents"; "That's trust they have by-and-large earned; what is increasingly frustrating is that that is trust they increasingly demand, and the scope of those demands is continually increasing."
Anthropic (Claude / Claude Code)
- Description: AI lab; Claude Code is its agentic coding harness.
- Why mentioned: Thompson's primary persistent agent and the tool that detected and helped remediate the hack.
- Quotes: "Claude in its Code harness seems to handle wide-ranging discussions better than Codex, and it follows my instructions about writing things down in the way I want it to more gracefully."
OpenAI (Codex, Dots)
- Description: AI lab; Codex is its coding agent, and Dots is a new persistent-agent-style product.
- Why mentioned: Runs alongside Claude on the Mac Mini; Dots is cited as partially matching Claude Code's persistent monitoring functionality.
- Quotes: "OpenAI's new Dots achieve some of this functionality... which has been sorely needed in ChatGPT/Codex."
Meta (Muse / Muse Gadgets)
- Description: Meta's agent/AI product and an open-source device-seeding program.
- Why mentioned: Held up as a smart strategy for owning the agent interface layer rather than selling hardware.
- Quotes: "Meta is seeding an entire ecosystem of devices, some of which might become real products, and it's completely open source. The payoff isn't in selling devices; it's in Muse being the interface for everything."
Tailscale
- Description: VPN/mesh networking company.
- Why mentioned: The foundation of Thompson's security approach, which he admits he failed to apply consistently to the Mac Mini.
- Quotes: "Obviously I should have — and will be — using a VPN going forward (the foundation of my entire approach to security is Tailscale)."
Bynario
- Description: Security firm.
- Why mentioned: Credited by Apple for reporting the screen-sharing vulnerability.
- Quotes: "Apple credited security firm Bynario for reporting the vulnerability."
Bloomberg
- Description: Business and financial news publisher.
- Why mentioned: Published Mark Gurman's reporting on Apple's smart-home launch.
- Quotes: Gurman's article was titled "Apple Is Finally Ready to Enter Its Next Big Category: the Smart Home."
Ars Technica
- Description: Technology news publication.
- Why mentioned: Source for the technical details of the macOS vulnerability and mitigation advice.
- Quotes: "Security practitioners generally advise Mac users to keep the port closed even when using screen sharing and to instead connect over a VPN or through SSH tunneling."
Telegram
- Description: Messaging platform.
- Why mentioned: Used as an interface to Thompson's agent's inbox/status board.
- Quotes: "I utilize as an inbox to capture interactions with a status board I built... as well as interactions with a Telegram bot."
4. People Identified
Ben Thompson
- Description: Author of Stratechery.
- Why mentioned: First-person account of being hacked and of his evolving view of Apple.
- Quotes: "I can, for the first time, envision a future where I don't buy Apple by default."
John Ternus
- Description: Apple's new CEO.
- Why mentioned: Leads Apple's smart-home push and the "Intelligent Personal Hub" vision.
- Quotes: "a critical product expansion for the company under new Chief Executive Officer John Ternus."
Mark Gurman
- Description: Bloomberg reporter covering Apple.
- Why mentioned: Reported Apple's October 13 smart-home launch plans, including the J490 hub.
- Quotes: "Apple Inc. plans to make its long-delayed push into the smart-home market on Oct. 13."
Nat Friedman
- Description: Creator of Muse.
- Why mentioned: His X post on home automation was the other notable announcement alongside Apple's.
- Quotes: "Muse creator Nat Friedman posted on X."
Paul Graham
- Description: Essayist and Y Combinator co-founder.
- Why mentioned: His 2005 essay "Return of the Mac" is used to frame how hacker preferences predict mainstream adoption.
- Quotes: "Quite small, but important out of proportion to its size. When it comes to computers, what hackers are doing now, everyone will be doing in ten years."
Avery Pennarun
- Description: Tailscale co-founder and CEO.
- Why mentioned: Thompson's earlier interview with him underpins his security approach (linked, not discussed in depth).
- Quotes: "(the foundation of my entire approach to security is Tailscale)."
5. Operating Insights
Build a constrained "company" agent and a separate unconstrained personal agent
Thompson separates the agent for his team from his own: "Gecko, the agent that I have built for the people that work with me. It's awesome, but purposely constrained in capability and in what it can access. My real agent is a dedicated Claude Code thread that writes down all of my ideas and tracks the status of the myriad of projects I've spun up."
Isolate agents on dedicated hardware, and use persistent monitors for observability
The Mac Mini "has nothing on it except for Codex and Claude," which contained the blast radius. The persistent monitor, restarted on a schedule, doubled as an intrusion tripwire. Pair this with network isolation: "I should have — and will be — using a VPN going forward."
Audit "automatic" security settings and patch point releases manually
"I had been leaving myself more exposed than I should have been for years, under the mistaken assumption that checking 'Install…security updates automatically' would in fact install security updates automatically." Operators running always-on infrastructure should verify what auto-update actually covers rather than trust the label. The related advice from the vulnerability report is to "block screen sharing, enable it only when screen sharing is needed, and to turn the feature off once a session has ended."
6. Overlooked Insights
Apple may encrypt the iMessage store to block agent access
Thompson tosses off a prediction that could matter for agent builders and DRM-style platform control: "I bet that the iMessage store will be encrypted in the near future, a la iTunes in the 2000s." This implies Apple may use technical lockdown, not just permission prompts, to limit what agents can read.
Decompiling software to source is already reshaping gaming
Mentioned in passing: "there is a revolution happening in gaming over the past few weeks, as game after game is decompiled to source and ported to any platform you wish." If AI makes decompilation and porting cheap, it weakens platform exclusivity and the lock-in logic of closed software ecosystems well beyond gaming.