Earlier quoted context omitted.
I will keep banging this drum until people listen: Trying to use markdown files to limit access should never be treated as a security guarantee at all. This is a form of in-band signalling that goes into a machine that, among other things, tries to read between the lines of your requests, extrapolate user desires, and please the user. The only sane way to address this is using a control plane. A well-built harness ca…
It's wild that we've known for decades to use ACLs to make sure people don't have access to files we don't want them to have access to, but somehow a computer pretending to be a person doesn't get that same treatment.
Grok CLI uploaded the whole home directory to GCS
291–300 of 434 posts
Re: Grok CLI uploaded the whole home directory to GCS
#292Same tech bro: “Wow I can’t believe they would steal my anime girls!”
Re: Grok CLI uploaded the whole home directory to GCS
#293Earlier quoted context omitted.
I will keep banging this drum until people listen: Trying to use markdown files to limit access should never be treated as a security guarantee at all. This is a form of in-band signalling that goes into a machine that, among other things, tries to read between the lines of your requests, extrapolate user desires, and please the user. The only sane way to address this is using a control plane. A well-built harness ca…
Especially when I find that, when I ask an agent not to do something, the mere mention seems to put the "idea" in its "head," making it more likely to ultimately do that thing.
Re: Grok CLI uploaded the whole home directory to GCS
#294Earlier quoted context omitted.
The easiest, most guaranteed way to isolate it is to run it in a VM or container where it literally can't do the wrong thing without some kind of full container or VM exit exploit. It's not hard, it's trivial. Most folks here are constantly working with containers. You know how to run a container with a local directory mounted in it. For myself, I've been using Lima ( https://lima-vm.io/ ) to reduce even that little…
I seem to recall reading about agents already breaking out of containers.
It's a common misconfiguration and one of the footguns available through containers, which I don't say a wholesale condemnation of the technology, but certainly as a UX facet that could use reevaluation.
Re: Grok CLI uploaded the whole home directory to GCS
#295Earlier quoted context omitted.
I think there are arguments on both sides. People should look for guidance on how to use complex tools, but we know people will not. Whose fault is it if someone drives a car without learning how to and injures themselves? On the other hand if the manufacturer has promoted it as one you can drive without learning how to, then whose fault is it? A lot of users are fine with everything being uploaded. Most people's pri…
Every driver needs to learn how to drive, that's why it's called a "driver's license"
Re: Grok CLI uploaded the whole home directory to GCS
#296So many of the replies are saying that they should've restricted access using .md files and whatnot. Is really any guarantee that they even follow those? It seems like even if you ask pretty please don't touch those files, there's a chance they will. So many people have just willingly installed spyware on their computers and big tech calls this the next big thing.
That's the whole reason I refuse to install Google Drive or Dropbox's desktop applications. I only use the web interface so I know exactly what gets uploaded and when. I assume that anything running on my computer gets access to everything.
Re: Grok CLI uploaded the whole home directory to GCS
#297Not bad, but I think it should also encrypt the local files, to make sure you don't make conflicting edits in the local and remote copies.
Re: Grok CLI uploaded the whole home directory to GCS
#298Earlier quoted context omitted.
> They won’t stop abusing us until we stop using their products. I don't use AI at all in my daily life. Work however will demand you use it. AI is not here to help people.
> AI is not here to help people. True, but it isn't here to not help people, either. It's a spanner. Who wields the spanner, makes all the difference. We've spent the last couple of decades, cultivating a huge crop of ultimate scumbag billionaires, with comically exaggerated sociopathy, and that has filtered down to almost every level of society. They are treated as gods, these days (they certainly think of themselve…
The tool analogy is intentionally minimizing, and doesn't capture just how different rented tools with constant surveillance are.
Re: Grok CLI uploaded the whole home directory to GCS
#299Earlier quoted context omitted.
I will keep banging this drum until people listen: Trying to use markdown files to limit access should never be treated as a security guarantee at all. This is a form of in-band signalling that goes into a machine that, among other things, tries to read between the lines of your requests, extrapolate user desires, and please the user. The only sane way to address this is using a control plane. A well-built harness ca…
It's wild that we've known for decades to use ACLs to make sure people don't have access to files we don't want them to have access to, but somehow a computer pretending to be a person doesn't get that same treatment.
Re: Grok CLI uploaded the whole home directory to GCS
#300Earlier quoted context omitted.
I mean, do people expect companies to protect them from a tyrant they themselves elected? Not necessarily speaking of the present. This seems to be the general sentiment.
If the tyrant goes against established law, yes. (an aside but the majority of the US population didn't elect Trump. He is in office because of the electoral college. Might seem like a distinction without a difference but I think it matters when we're implying personal culpability)
First term he lost the popular vote, second term he won it.
If you just mean a majority of eligible voters did not vote for Trump, that’s true for every US President in my lifetime.