Live data from Hacker News

Grok CLI uploaded the whole home directory to GCS

twitter.com

401–410 of 434 posts

Re: Grok CLI uploaded the whole home directory to GCS

#402
post #194

Earlier quoted context omitted.

Intricate sandboxing is a real solution in the same way bulletproof backpacks are a real solution to school shootings.

It’s not that intricate. A very simple docker and alias setup will get you an ephemeral container with your Claude (or whatever) config and the current wd bind mounted in. That’s a pretty good start. Or, the internal sandboxing.

You can sandbox a software codebase, you can sandbox a directory with documents. You can't sandbox internet access for any real network task. You can't sandbox any shared or public service. You can't sandbox you actual accounts to non-local services.

Sure, for IT crowd containers are a no-brainer and due to existence of validation software like compilers, linters, interpreters, analyzers etc. using LLMs is efficient, safe and rational.

But the problem is that they are also advertised to the remaining 99% of population too. You can't sandbox a bank, a broker or an exchange. You can't sandbox your email, calendar and other such tools (you can, but not in any way that will be used by non-IT people in any real work conditions). You can't sandbox messengers, social networks etc. And the list goes on. These people will either use so called "agents" in production under root, so to speak, or they won't use "agents" at all. They have no safety option, and they aren't properly informed about that by the peddlers of the LLM rapture.

Re: Grok CLI uploaded the whole home directory to GCS

#403

Earlier quoted context omitted.

> They won’t stop abusing us until we stop using their products. I don't use AI at all in my daily life. Work however will demand you use it. AI is not here to help people.

Not gonna argue about the utility of AI, but isn't the statement "AI is not here to help people" completely meaningless? AI itself is not "here" for anything; the problem is big tech doing big tech shit as always, not the current technology they're doing it with.

Doesn't matter. Big tech is not changing anytime soon. So if we see AI, we shouldn't see as some random tool, but as something in their hands.

Re: Grok CLI uploaded the whole home directory to GCS

#404

So many of the replies are saying that they should've restricted access using .md files and whatnot. Is really any guarantee that they even follow those? It seems like even if you ask pretty please don't touch those files, there's a chance they will. So many people have just willingly installed spyware on their computers and big tech calls this the next big thing.

I will keep banging this drum until people listen: Trying to use markdown files to limit access should never be treated as a security guarantee at all. This is a form of in-band signalling that goes into a machine that, among other things, tries to read between the lines of your requests, extrapolate user desires, and please the user. The only sane way to address this is using a control plane. A well-built harness ca…

I always run harnesses using devcontainers, gives me much needed flexibility and peace of mind with regards to data separation guarantees

Re: Grok CLI uploaded the whole home directory to GCS

#405
post #70

I'm dying to have proper sandboxing in macOS. I installed ChatGPT, I asked it to list files in my user directory and it did. I never gave it permission, how could it? My terminal has access and honestly it shouldn't either.

your terminal shouldn't have access to your user directory? As in the files owned by you?

I run Claude in that terminal. No, it shouldn't. Not without a prompt. This is how you get worms stealing your keys via some build tool you just run.

Re: Grok CLI uploaded the whole home directory to GCS

#406

I'm dying to have proper sandboxing in macOS. I installed ChatGPT, I asked it to list files in my user directory and it did. I never gave it permission, how could it? My terminal has access and honestly it shouldn't either.

Was it Codex or the desktop ChatGPT agent?

It was the standard ChatGPT chat app. I asked for commands and it ran them directly (after confirming)

Re: Grok CLI uploaded the whole home directory to GCS

#407

Earlier quoted context omitted.

Idk, did you see the whole DOGE thing? Maybe Edolf has resorted to hiring script kiddies because nobody with a developed moral compass will work for his companies anymore.

Hmm. This is striking me as low quality speculation based on Elon’s name being in both stories.

I didn’t say it wasn’t speculation, but low quality? That’s your own value judgement. Here’s anecdotal evidence on top of the speculation: I knew two guys with sub 2.5 GPAs in college, both work at SpaceX. Not the brightest tools in the shed…

Re: Grok CLI uploaded the whole home directory to GCS

#408
post #70

Earlier quoted context omitted.

your terminal shouldn't have access to your user directory? As in the files owned by you?

It was only like 1 year ago that the loudest complaint about macOS were complaining about needing to click Allow in a new dialog when they use Terminal (or various other apps). There are so many comments in here that are calling for nerfing something widely revered for giving us superpowers. Whether these are bots or not, they’re giving off NPC energy. If they don’t want to use power tools because they accidentally c…

Hello, are you aware that ALL the software you run on your computer can silently access your clipboard? Have you ever copied sensitive data? Perhaps a password?

Anyway, what I'm asking is a native way to run software in a real sandbox. It's really not a big deal to grant access when asked. Have you used any mobile OSes in the past 20 years? It's the default there and I can be certain that any random utility cannot read my clipboard or user directory without consent.

Re: Grok CLI uploaded the whole home directory to GCS

#409

Earlier quoted context omitted.

Hmm. This is striking me as low quality speculation based on Elon’s name being in both stories.

I didn’t say it wasn’t speculation, but low quality? That’s your own value judgement. Here’s anecdotal evidence on top of the speculation: I knew two guys with sub 2.5 GPAs in college, both work at SpaceX. Not the brightest tools in the shed…

Once again we are word associating. The claim was that xAI is doing obviously bad engineering. Your supporting evidence is you know somebody who works at SpaceX who isn’t smart.

> I knew two guys with sub 2.5 GPAs in college,

Gah! The horror! They should have been sent to the labor camps.

Post reply on HN