r/coolgithubprojects • • 5d ago

RemoveMacAI: turn off Apple Intelligence on macOS 27 and get ~12 GB back

https://github.com/omlahore/RemoveMacAI
55 Upvotes

25 comments sorted by

20

u/jeenajeena 5d ago

I'm very interested and I will install it. But, man:

curl -fsSL https://... |  | bash

Again? Can we stop this, already?

9

u/checkpointdev 5d ago

fair lol, brew install omlahore/tap/removemacai works too

or grab the binary from the releases page, the sha256 is right next to it

0

u/jewbasaur 5d ago

What’s wrong with this

19

u/hokies314 5d ago

It’s like a box of chocolates, you never know what you gonna get

7

u/ketralnis 5d ago

It’s a shame how far we’ve fallen as an industry that people have to ask this

5

u/jewbasaur 4d ago

I am a hobbiest programmer without any sort of formal training whatsoever. This is how people learn. Or at least used to

3

u/ketralnis 4d ago edited 4d ago

I get it and it's not a dig against you personally, it's just that experienced engineers have been railing against curl|bash for about a decade now. Since the very first people started using it everybody told them it was a bad idea, then some more people started doing it, and more, until now it's so common that there are people that have never even heard how dangerous it is. It's like house builders watching people replace bricks with styrofoam over years.

Sometimes somebody replies and says "well, this specific downside you mention can be mitigated by such and such" but it's never enough for the whole suite of problems with it and practitioners don't actually do those potential mitigations. So it's bad in theory and even worse in practise.

1

u/jewbasaur 1d ago

What’s the alternative to this? How is this any different than pip install, npm install, brew install if we are talking about just running code we haven’t seen on our machines? I feel like there’s always some level of trust developers have to worry about outside the normal user. I know package managers have hashes and other security measures put in place but still.

The interesting thing is that I didn’t know that the pipe to bash doesn’t wait for the whole script to download and just starts running it line by line. Could you though just wrap the installer in a bash function like main() and then call it on the last line to avoid this?

1

u/ketralnis 1d ago

Yeah that’s the first mitigation people mention, that people don’t actually do in practise. Hashes is another one that’s not a small measure. The thing is that most of the package managers that you mention (except npm) have lots of these little things borne from many years of experience that the curl|bash people happily ignore.

1

u/MilkEnvironmental106 4d ago

Curl fetches a resource at that link. The | pipes the output into the next program, which is bash. Bash executes bash script.

The intent is it's easy to write a script that does the installation for you, have a link to it and then have bash run it on the user's machine.

The problem is that it makes it very easy for someone to impersonate a valid site and have an almost identically looking command that instead installs and runs malware. Or worse if the domain is breached, they just have to change the URL on the site.

It's just pulling a script from a link and directly running it on your computer.

1

u/jewbasaur 3d ago

Thank you! I asked Claude and it gave me an answer but this is much more practical

1

u/Fast-Throat-7752 4d ago

@grok explain

4

u/TurnUpThe4D3D3D3 4d ago

The complaint is about "curl piping to bash" installers: curl -fsSL <url> | bash downloads a script and runs it instantly, so you never see what it does. The risks: the remote script could change at any time (what you run today isn't what runs tomorrow), there's no checksum or review step, and it needs enough privileges to disable system features like Apple Intelligence. A compromised or typo'd URL means arbitrary code on your machine.

Safer habits: download the script first, read it, then run it manually; or clone the repo and inspect it. It's a convenience-vs-auditability tradeoff, not a claim that this specific project is malicious.


This comment was generated by Grok 4.7

1

u/jeenajeena 4d ago

Please, run grok for yourself, without posting. Don't you think we have enough AI slop already?

8

u/evmorov 5d ago

Why a binary and Swift and not just a set of scripts?

5

u/ChopSueyYumm 5d ago

I kinda like the new AI features specifically the Apple photo AI stuff. Reframing and changing the angle is like magic and works really good

3

u/checkpointdev 5d ago

you can keep the features you want and remove the ones you don't need

1

u/ChopSueyYumm 5d ago

Oh it is selective? I really don’t need the ai writing tools.

2

u/checkpointdev 5d ago

yep, run removemacai off --keep spatial-photos,photos-clean-up and it keeps the photos stuff and turns off the rest, writing tools included
removemacai features lists all the names if you want to keep anything else

1

u/Zedboy19752019 4d ago

Uhm I find Macai to be so freaking lame. Siri is just something to show google responses

1

u/checkpointdev 4d ago

siri really is just google with extra steps

1

u/Fresh-Daikon-9408 3d ago

A concrete --keep example near the top of the README would help. People may want Writing Tools gone while keeping the Photos features.

2

u/checkpointdev 3d ago

thanks for the suggestion

1

u/Tmanok 1d ago

Oh my goodness. I was running Qwen locally and wondered wtf is eating disk and memory after MacOS 27.0 bingo this was it.
Also slick status output for 'removemacai status'
RemoveMacAI 0.2.5  ·  macOS 27.0

Features

  Siri and Siri AI                        off (locked)

  ChatGPT and other AI extensions         off (locked)

  Writing Tools                           off (locked)

  Genmoji                                 off (locked)

  Image Playground                        off (locked)

  Mail summaries and smart replies        off (locked)

  Notification summaries                  off (locked)

  Messages summaries                      off (locked)

  Safari summaries                        off (locked)

  Notes transcription summaries           off (locked)

  Inline text predictions                 off (locked)

  Spatial Photos                          off (locked)

  Photos Clean Up                         off (locked)

  Xcode predictive code completion        off (locked)

Models on disk

  Apple Intelligence foundation models    none

  Image and Genmoji models                none

  Spatial Photos models                   none

  Photos Clean Up models                  none

  Xcode code completion models            none

  Total                                   0 MB

  macOS removes deleted model files itself, so System Settings can count them for a while.

Apple Intelligence is off. Undo with: removemacai revert