Become a Member!
Become a Six Colors member to read exclusive posts, get our weekly podcast and regular newsletters, and much more!by Jason Snell
Lex authors the apps, but Claude writes the code
Back in June, I tried to elaborate on why building software is more than coding in an age of AI coding assistants:
Whatever you call it, whether it’s being a producer or product manager or something else that isn’t a programmer, creating good software in the AI era still requires the power of a human brain: being creative, solving problems, and making decisions. Some people will be better at it than others. It’s a skill, and a bit of an art. I’m excited that modern coding tools have given people with vision and desire the ability to make software.
My friend Lex Friedman, who is staggeringly productive at releasing apps, decided to address a social-media comment about how that productivity was “suspicious” on his tech blog, and in doing so, detailed how much of his app building was Claude and how much was his own background as a developer and user of computer software:
The question, to me, isn’t how much code was written by a human. It’s how much the app was authored by a human, which I think is a more nuanced question. How much care, thought, and humanity went into the app matters far more than tabs vs. spaces or a manually-vs.-machine-built HStack.
This is the truth of it. Slapping a quick prompt into Claude is not going to get you good software. Envisioning how a product should work, in detail, is hard work—and not everyone is going to be good at it, or want to do it. If pure coding skill is no longer the differentiator it was, taste and organization and attention to detail and many other intangible features that great developers have always had will still matter.
By Glenn Fleishman
Is your secure iMessage conversation actually secure?

Apple introduced iMessage within Messages in 2011 as its house-brand, end-to-end encrypted messaging product. The promise of iMessage is that posts are always encrypted, using servers and technology developed by Apple and controlled by it. The encryption keys reside on your device, stored so Apple can't access them, and no third party should ever have the leverage to retrieve them. (There's a big proviso there, which I'll explain at the end of this article.)
Despite exploits uncovered over the many years since iMessage first appeared, the core protocol has never been breached, only device exploits or iCloud-backup extractions that allowed access to stored messages. That's a strong track record. Apple has continued to tinker with improving iMessage encryption, while also adding an optional method of ensuring conversation integrity, Contact Key Verification.1
But in researching the update for Take Control of FaceTime and Messages, a lengthy ebook that covers those two apps plus the Phone app 2, I discovered you could be lulled into a false sense of security based on what you assumed iMessage was and was not.
The odds of this change in standards causing a security breach and your messages being exposed seem unlikely, at least right now. But after scrolling through conversations and seeing what's going on, I feel Apple has omitted important signals for users when iMessage suddenly stops being used during a conversation.
- Contact Key Verification may be overkill for most people, but it's still good that Apple made it universally available. I explained how it works in 2023 for TidBITS. ↩
- The update to this book is due out in the next week or so, covering the version 27 operating systems. However, you can purchase the current version now and receive a free update. ↩
Continue reading “Is your secure iMessage conversation actually secure?”…
by Dan Moren
Apple’s new parental controls are having a messy roll out
Jennifer Pattison Tuohy, writing at The Verge, illuminates some challenges with the new parental controls Apple added in this year’s software updates:
I’m not even trying to use Screen Time on my son’s devices. He’s 18, away at college, and well beyond my parental controls. The problem is I apparently need him to update his MacBook Neo before I can use Apple’s new Screen Time features on my 15-year-old daughter’s iPhone. His college is four hours away, and like many college kids, he’s an expert at ignoring text messages from his mom asking him to do a boring chore.
The underlying issue here is a technical one: there’s a new architecture on which the entire system is based, not unlike when Apple updated its home architecture a couple of years ago. So you end up with kind of an all-or-nothing approach here.
My hurdle with the new parental controls is that the iPad my kid uses is an old one—a hand-me-down 2017 iPad Pro that can’t even be updated to iOS 27. That, unsurprisingly, makes the new parental controls a non-starter. The likely answer? Buy a new iPad. But the kid is four and currently only uses the iPad for watching videos on long trips, so that seems like overkill. It also means there isn’t really a deep need for parental controls, since we’re still in a world where the iPad is never used on the internet and without some degree of supervision—it can still just be removed.
Unfortunately, this isn’t the only issue Pattison Tuohy ran into; other devices didn’t register as updated, ghost devices lingered, and the new controls took time to roll out even after the updates. While these issues will likely get ironed out in time, it does seem like a bumpy launch for a much-touted new feature.
Credit cards, dryers, and, if we have time, the two Apple events expected this month.
Together in Memphis, Myke and Jason discuss John Ternus prodding Apple to move faster, Apple’s regret about giving apps Full Disk Access, and the impending release of Apple’s long-rumored home hub product.
By Dan Moren
Secretive helps you keep your SSH keys secret, keep them safe
Way back in January I noted that one of the features that had kept me from using Passwords as my only password management app was its inability to manage SSH keys, a feature offered by competitor 1Password. What I liked about 1Password’s approach was that it abstracted this feature, letting me authenticate my keys using macOS’s built-in authorization system. So instead of typing in a passphrase for that key, I could just use Touch ID or type my 1Password password. This still seems to me like the kind of thing that Passwords should offer, and I still hope that it might in the future.1

In the meantime, I’ve recently turned to Secretive, an open-source tool by Max Goedjen and others that allows you to store your SSH keys inside your Mac’s Secure Enclave. Doing so means that your keys can’t be exported and are protected by the same level of security as your system’s most sensitive data. In addition to ECDSA-256 keys, running Secretive on macOS Tahoe and later lets you create post-quantum keys using the MLDSA-65 and MLDSA-87 algorithms. If you don’t know what any of that means, don’t worry about it—you’re fine.
Using Secretive still requires some technical know-how. You’re going to have to edit some configuration files and, if you’re using the keys to log in to remote servers, install them yourself. There are instructions for much of this both in the app and online. Other apps can work with Secretive too, assuming the developers have built in support: right now, it’s mainly targeted at developer tools like git and GitHub, as well as secure file transfer clients like Transmit and Cyberduck.
The one major downside of this system is that since the private keys are stored in the Secure Enclave, they cannot be backed up or transferred elsewhere. That’s more secure, but it’s more inconvenient as well; if your Mac gets hosed, or you migrate to a new device, you’ll have to recreate your keys all over again. It also means that if you maintain SSH keys on multiple Macs, you have to set up Secretive on all of them. That’s another reason that I’d like to see Apple find a way to abstract this process further via the Passwords app, if it can figure out a safe and secure way to do so—not to mention, potentially making it available on iOS as well. Like passkeys, ssh keys offer more security and less reliance on passwords.
Secretive’s not for everybody, but there are certainly a subset of users who will be very interested in the security it offers. But until such a time as Apple makes this process part and parcel of its operating system, I’ll be relying on Secretive to help me manage it.
- It also might help more people who would like to move away from 1Password for…reasons. ↩
[Dan Moren is the East Coast Bureau Chief of Six Colors, as well as an author, podcaster, and two-time Jeopardy! champion. You can find him on Mastodon at @dmoren@zeppelin.flights or reach him by email at dan@sixcolors.com. His next novel, the sci-fi adventure Eternity's Tomb, will be released in November 2026.]
By Dan Moren
Apple is changing Full Disk Access in macOS
In a post on Apple’s Developer News site, the company says it will be updating the Full Disk Access permissions:
Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.
Nick Heer has a detailed analysis of this announcement, though, as he points out, it’s impossible to make any conclusive judgments as we don’t yet know exactly what these “additional controls” will look like. But the reactions from some developers whose apps rely on this permission were wary, at best.
Security and convenience are a tough line to walk, there’s no question. The competing models of macOS and iOS take very different approaches to the idea of, oh, let’s call it “messing around and finding out.” Even giving an app access to every single permission on iOS—unwise as it might be—can’t touch certain parts of the system; that’s not true on the Mac. But, on the flip side, it unlocks a world of possibilities for apps on your Mac that simply aren’t possible on the iPhone.
Specifically, as Apple calls out here, AI agents. The AI agents that you can use on your phone can get access to information that you granularly share with them, but there are limits. An AI agent with Full Disk Access to your Mac is capable of much more. If I can draw an imperfect analogy, it’s akin to giving the agent power of attorney to act autonomously on your behalf, without your full knowledge. At least until after the fact.
But there are plenty of legit uses for Full Disk Access. Just looking at my MacBook Air this morning, I’ve given that permission to three apps1: Terminal, BBEdit, and SuperDuper. All apps that I trust with that level of power because of their long history and because in order to do what they do best (or at all), they need that access.2 (Interestingly, on my Mac mini, that list also includes SpamSieve, KnockKnock, and Shortcuts—though not BBEdit, for whatever reason.)
As Nick explains, this move was likely a response to Jason Aten’s recent story in Inc. about Meta’s Muse having access to his Messages, despite supposedly not permitting it.3 But it’s also a recognition that this is going to become more and more of an issue as AI agents become more commonplace, and no doubt ask for Full Disk Access, because these kinds of apps want as much power and information as you will give them, and it’s far more efficient for them if they can just ask for disk access than enumerating all the individual data stores. Especially, in an era where we’re besieged by permission dialogs.
I don’t think Apple has done the best job with its permissions user experience—it surely could be improved. But I also have to admit that my own behavior has changed over time as Apple has instituted more and more granular controls. Perhaps it was simply the callowness of youth, but I was once far more willing to grant permissions to apps I installed4—these days, I find myself scrutinizing them more and more: Why do you need Bluetooth access, app? What devices on my local network are you really accessing? My default is to not allow things, unless I have a very clear understanding of why the app is requesting them—and, in the cases where I am overly cautious and impeded an app’s functionality, going and turning on a permission I disabled.
But I also realize that I’m hardly the average user. I think there is a good argument for protecting Full Disk Access further, but there’s also only so much you can do to protect a user from themselves. Ultimately, this is a cat-and-mouse game, and while I don’t want my data purloined or misused, I also don’t want my computer locked down to the point that I can’t use it for all the things I want to do.
-
The Privacy & Security panel also shows that two system level processes have access:
smbd, the file-sharing daemon, and sshd-keygen-wrapper, which helps manage the remote login protocols. ↩ - Perhaps another argument for the existence of some sort of trusted developer program? ↩
- The story here, as several people have noted, is a little confusing; it’s unclear exactly how this happened. ↩
- It was also the earlier days of computing, when our devices were neither as capable nor as far-reaching in their data as they are now. ↩
[Dan Moren is the East Coast Bureau Chief of Six Colors, as well as an author, podcaster, and two-time Jeopardy! champion. You can find him on Mastodon at @dmoren@zeppelin.flights or reach him by email at dan@sixcolors.com. His next novel, the sci-fi adventure Eternity's Tomb, will be released in November 2026.]
By John Moltz
This Week in Apple: Feeding the rumor monster

Mark Gurman makes the news, the iPhone Duo is still in trouble, and Apple faces a big payout.
Finally, a white guy podcasting about Apple
Unlike some sites, I’m just gonna tell you all the things that Bloomberg’s Mark Gurman wrote this week in one section instead of spreading it over five or six articles, several podcast episodes, and an interpretive dance.
Gabby Gurman has the beans and he’s spilling them everywhere. Then pouring the tea on top of them. It’s a whole thing.
The biggest dirt he’s dishing is that Apple will hold its fall iPad, HomePod, and HomePad event on October 13th. The likelihood of that being the date is something even John Gruber agrees with Gurman on, despite their bitter blood feud that was sparked, not over the veracity of Gurman’s Apple rumors, but the ownership of a mule named Paco.
True story.
Paco has been sent to a mule sanctuary where he is reportedly happy to be free of all the drama.…
This is a post limited to Six Colors members.
by Jason Snell
Support St. Jude and watch the 2026 Relay Podcastathon
Hello from Memphis, where we are currently hosting the 8th annual 12-hour Podcastathon. I’m here for the fourth straight year, along with Stephen Hackett, Myke Hurley, Kathy Campbell, Casey Liss, and Brad Dowdy. It will be guaranteed to be a fun watch.
Please drop in if you can.
by Jason Snell
Amazon introduces new Kindles and accessories

Amazon on Thursday announced new Kindles, including a new base model, Paperwhite, and Colorsoft. All three models come in multiple varieties (plastic and aluminum) and in a variety of new colors.
The cheapest model is $170 ($150 with ads), and the priciest new model is the $319 Colorsoft Signature Edition. (I admit that I find it somewhat shocking that even a basic e-reader costs $170 these days, but here we are.)
More notable, I think, is that Amazon is embracing page-turn buttons again—but with a very Amazon twist. After systematically removing page-turn buttons from its Kindles over the years, it’s brought them back—on a $80 case. Following in the steps of competitor Kobo, Amazon has also added a page-turn remote control for people who prefer to read while their device is not in their hands. (I know multiple people who place their e-readers in a stand and rely on page-turn clickers.)
I gotta say that I don’t love that Amazon has decided that to use page-turn buttons, you need to pay $80 and keep your Kindle in a case. But at least they’re finally offering an option. (For the record, Kobo’s Libra Colour is priced similarly to the Paperwhite Signature Edition and has buttons right on it, no case required. It’s the e-reader I use the most these days.)
Still, I must begrudgingly admit that Amazon has provided some much-needed page-turn options for people who don’t want to endlessly tap or swipe on a touchscreen. And over the last few years, Amazon has addressed many of the limitations of the Kindle software platform, making it much more competitive with Kobo. Given the outsized place Kindle has in the e-reader world, it’s good to see that someone at Amazon still cares about Kindle.
By Glenn Fleishman
Silencing AirTags enables stalkers and domestic violence
ElevationLab has released an AirTag product I find appalling, and I strongly urge they immediately withdraw it from sale and recall all inventory. The AirTag Silencer is a simple device: remove the back panel and battery from an AirTag, position the Silencer’s highly engineered pin over the speaker, tap the pin with a hammer, and the AirTag’s speaker is destroyed. This prevents it from emitting an alert in three circumstances, only one of which is triggered by an owner. The other two scenarios aid stalkers and perpetrators of domestic violence, among others. I will not link to it.
Disabling an AirTag speaker is a way for an unwanted party to more easily track someone without their knowledge and consent. Apple designed the AirTag to alert people when an unknown tracker was moving with them (via software), or when a tracker moved or was bumped (via a sound) after remaining in a location for a period of time. The latter case is critical, as Find My items have been found in purses, luggage, vehicles, and other things that move, left there either provably or putatively by a party attempting to track someone otherwise unaware they’re under remote observation.
You can find sites selling AirTags with the speaker disabled all over the Internet, as well as instructions to do so, and some even state outright that the action helps with unwanted tracking. ElevationLab’s AirTag Silencer is certainly the only mainstream device that performs this task with the exacting design one has come to expect from the company since the introduction of their 2012 iPhone dock—now with the proviso of “unfortunately.”
I’ll take ElevationLab at their word that they intend this for use with, as the product description states, “Anything you wouldn’t want the speaker tipping off a thief. (We originally designed this for our own bikes that have been stolen).” This also guided their 5-year and 10-year AirTag cases, which can be secreted in a hard-to-remove location deep within something expensive.
It is true that the “moving with you” and audio alerts make an AirTag and similar items less ideal for recovering stolen items than for finding lost ones, tracking luggage in transit—or being alerted that you left something behind.
Eva Galperin, Director of Cybersecurity at the Electronic Frontier Foundation, was blunter than I. “Honestly, this is just another example of the mindset that things are more important than people,” she said via email. “There is a reason why the AirTag makes that noise, and it is because you cannot make a tracker that does not alert a thief without also making a person a tool for stalking. I think these people have, in fact, considered the implications and decided that they don’t care.”
I posed the question of potential misuse to Casey Hopkins, ElevationLab’s CEO. He replied via email, “We make products we want for ourselves. And we’ve had expensive bikes and other gear stolen and then recovered using AirTags. We have also silenced our own AirTags on those items using DIY methods available online and on YouTube. If someone is determined enough, they could already silence it themselves, but the person would still get phone notifications. With roughly 200 million AirTags in use, extreme edge cases will make news, but the overwhelming number of people just want to track their own gear.”
I see his point, but I don’t accept it, as the viewpoint is either naive or uninformed about the scale of abusive tracking. Yes, AirTags are used mostly for good purposes—my family must own 20 Find My items at this point—but there’s a difference between what a product might be used for and making a tool that expedites bad behavior, disabling both a component and a strategy created by Apple. Making it easy to remove the speaker also makes it simpler to engage in consent-free tracking—there are no two ways around it.
Silent tracking
Apple’s Find My items and Google’s Find Hub trackers securely relay a signal from trackers through nearby iPhones, iPads, and Macs (Apple) and Android devices (Google), letting us keep tabs on our stuff and then potentially find it when it’s lost or stolen. The AirTag is a sword with two edges: one allows desired finding by yourself or others you share an item’s location with; the other, privacy-invading stalking, is often employed by those attempting to control someone, as part of ongoing domestic violence or stalking an acquaintance or stranger.
This isn’t speculative. You can find hundreds of newspaper articles and television reports about specific cases, and many write-ups of the broader problem. In New South Wales, Australia, a local commission on crime was able to compel retailers to provide information about who purchased tracking devices in 2023. Their analysis revealed one in four of the purchasers—about 750 of 3,000 people—”had a history of domestic violence, while a further 126 were apprehended violence order defendants at the time the items were purchased.” A lawsuit filed a few days ago in Oregon is the latest example.

The speaker is a primary component of the company’s anti-tracking strategy, so much so that the second-generation AirTag, released this year and replacing the original, emits a 50% louder sound. While that aids in finding stuff you’ve misplaced, it definitely increases the likelihood that a victim of stalking will hear an alert sound. Apple and Google, not notable collaborators, worked together in 2023 to release an anti-stalking proposal, which both companies have adopted, including audio alerts.
Apple originally had an AirTag (and third-party devices certified as Find My items) emit a sound when it was moved after three days in the same location. Advocates for victims of domestic violence and groups concerned with privacy urged a shorter time period. Apple updated the alert, just a few months after the product’s 2021 release, to trigger at a shorter and random interval. Since mid-2021, an AirTag or any Find My item chirps when moved between 8 and 24 hours after its paired device was last within Bluetooth range; the randomness makes it harder for a tracking party to predict when it might make a sound.
If you have an iPhone, iPad, or Android device and an Apple or Google tracker moves with you for a short period of time, your device will alert you and provide a map of where you’ve been tracked so far. This also lets you play a sound on the tracker device—something that’s not possible if the speaker has been removed.
Not being a lawyer, I can’t argue whether or not ElevationLab’s product comes with liability. However, using an AirTag, Find My item, or Google Find Hub tracker to acquire the location of someone without their permission may be a crime or risk a lawsuit, depending on the jurisdiction.
There are different ways to disable an AirTag or other tracker you discover, typically by rotating the back case and removing its battery. EFF’s Galperin has more direct advice: “I think that encouraging people to hit their AirTags with a hammer is a fine idea. They may need to hit it several times.”
A misfired pin
I’ve been purchasing products from ElevationLab since their 2012 ElevationDock. The company has always had an eye for elegance coupled with problem-solving.
This is what makes the company’s AirTag Silencer an absolutely baffling misfire, something that you would have thought would have called out as enabling behavior by some customers that no company would want to be associated with.
ElevationLab can’t prevent speaker-removing hardware from being sold or instructions from being disseminated. But the company should not be producing a case-hardened steel piece of precision goods that may look like a pin, but is a razor-sharp double-edged sword. Pull this product from sale.
[Glenn Fleishman is a printing and comics historian, Jeopardy champion, and serial Kickstarterer. His current books in preparation, which you can pre-order, are Flong Time, No See, and That One Matt Bors Comic. Other books include Six Centuries of Type & Printing and How Comics Are Made.]
By Jason Snell for The Wall Street Journal
‘Shop Different’ Review: The Genius of Retail
Apple has become one of the world’s most valuable companies because of its products: the Mac, the iPad, the Apple Watch and most especially the iPhone. But the company’s product sales have been aided over the past 25 years by the presence of its iconic brand in more than 500 retail stores scattered across 27 countries and regions. Anyone who has ducked into an Apple store for a new iPhone or toted a broken Mac through the mall for a repair appointment at the Genius Bar has experienced what Steve Jobs and Ron Johnson built.
In “Shop Different: How Retail Revealed Apple’s Genius,” Mr. Johnson details the remarkable story of how, in 1999, Jobs recruited him from Target to join Apple as head of retail and launch perhaps the biggest long shot of Jobs’s entire tenure as chief executive. At a time when computer stores were a moribund category and Apple’s brand was near its lowest ebb, the two men concocted a daring strategy: find some way to connect with the millions of consumers who had no interest in or understanding of Apple’s products.
By Dan Moren
The Back Page: Know when to fold ’em

The verdict is in: It took only one thing to reignite enthusiasm in Apple’s product line-up, and that thing was apparently an only just barely visible crease.
Yes, just weeks after its announcement, the iPhone Duo has taken the mantle of “most foldable Apple product”, besting the previous title-holder, iPod Socks.
But it’s the iPhone smushed together with an iPad in a laptop-ish form factor that has captured the imagination of the world at large, spawning countless breathless questions, such as “can I run iPad apps?”, “how many cameras does it have?”, “is it a taco or a sandwich?”, and “I’m sorry, it costs how much?” Everybody’s talking about the iPhone Duo, even your grandfather who still insists on force-quitting all of the apps on his “iTouch.”
“Honestly, if we’d known two displays was going to be this exciting, we’d have stuck screens on the outside of our laptops twenty years ago and called it a day,” said one source who was definitely not the retired Apple hardware chief Bob Mansfield looking rueful as he teed up his next round of golf.…
This is a post limited to Six Colors members.
Minor bugs that drive us mad, app blasts from the past, smart home infrastructure, and our non-car navigation systems.
by Dan Moren
Numbers update get statistical and trigonometry functions, and Apple tells you what they all are
When Apple updated its iWork suite in April of last year, I complained that the company didn’t break out the full list of functions that it had added to Numbers in its 14.4 release. Subsequently, a reader did the legwork of digging into the Wayback machine to identify the additions.
Well, this week, Apple updated iWork again, including new functions for Numbers, and glory be—this time it did provide a full list of all the new functions available in the release notes. Can I hope that I played a part in this change? I’ll take it.
Of those new functions, it’s the additions of XOR (exclusive or) and DAYS (returning a number of days between two dates) that I’ll likely find the most helpful, though there are a bunch of statistical functions in there as well. I’d still love to see a MEDIANIF, alas. Maybe someday!
Torn between Be and NeXT, Gil Amelio tries to analyze it all scientifically, including final demos from both teams. But was the end result a foregone conclusion?
Scary children, speculating about Apple’s October event and touchscreen Macs.
Apple’s slow move toward a fitness band makes us wonder if the company has lost its ability to execute quickly. Also, it’s time for a MacBook Neo check-in, and Myke questions Jason’s Apple Watch use.
By Glenn Fleishman
Why Stolen Device Protection makes Passwords safer

After my massive article on migrating your passwords, passkeys, and other secrets from third-party password managers to Apple’s Passwords, Wallet, Safari, and general ecosystem—potentially with help from another app—reader Scott asked whether I was directing people into weaker security. He wrote:
If someone manages to steal my device and its passcode, they have access to the contents of my phone, including all of the information stored in Apple Passwords. This is not the case if I use a third-party password manager and have set a separate password for access, as the thief will not have access to my other passwords…I’m surprised this liability is not discussed and considered more frequently.
This is a great follow-up question, and one that I didn’t address within the scope of the migration article, which was already long. Let me pick apart how to answer that by looking at risks and mitigations.
The risks of cracking our eggs at once
I understand the fear of losing everything, whether it is a set of material objects or digital secrets. One of the most heartrending stories I ever heard was from a photographer who lost all his work in an apartment fire shortly after moving to New York City to start his career. He rebuilt. That’s harder to do digitally, where if our privacy is “burned,” we might see bank accounts drained and potentially have to get our Social Security number or other identity number replaced.

Continue reading “Why Stolen Device Protection makes Passwords safer”…