Live data from Hacker News

Grok CLI uploaded the whole home directory to GCS

twitter.com

11–20 of 434 posts

Re: Grok CLI uploaded the whole home directory to GCS

#13
So many of the replies are saying that they should've restricted access using .md files and whatnot. Is really any guarantee that they even follow those? It seems like even if you ask pretty please don't touch those files, there's a chance they will. So many people have just willingly installed spyware on their computers and big tech calls this the next big thing.

Re: Grok CLI uploaded the whole home directory to GCS

#14

why do people give these LLMs full access to everything and then complain when it does somethign stupid? that is what sandboxes are for.

Other ones aren't this invasive with user data.

not true, Claude code on its own often create artifacts and straight up upload private stuff to Anthropic, without asking for it.

Re: Grok CLI uploaded the whole home directory to GCS

#17

why do people give these LLMs full access to everything and then complain when it does somethign stupid? that is what sandboxes are for.

When I give my text editor or file browser access to everything I wouldn't expect it to exfiltrate data without asking.

Re: Grok CLI uploaded the whole home directory to GCS

#18

Earlier quoted context omitted.

Other ones aren't this invasive with user data.

not true, Claude code on its own often create artifacts and straight up upload private stuff to Anthropic, without asking for it.

Then show us the example of Claude uploading a home directory to Anthropic because we have an example of Grok uploading a home directory to X.

Re: Grok CLI uploaded the whole home directory to GCS

#19
post #7

TLDR: Ran grok in $HOME. Surprised agent read content of folder. On the other hand, I specifically had grok try hard NOT to read a known key in the project dir (it only saw the first part using a tool, to verify it was present). So there's that.

I'm not seeing the information about it having been run at $HOME, where are you seeing that?

The `repo_path` field.

Re: Grok CLI uploaded the whole home directory to GCS

#20

So many of the replies are saying that they should've restricted access using .md files and whatnot. Is really any guarantee that they even follow those? It seems like even if you ask pretty please don't touch those files, there's a chance they will. So many people have just willingly installed spyware on their computers and big tech calls this the next big thing.

That's the whole reason I refuse to install Google Drive or Dropbox's desktop applications. I only use the web interface so I know exactly what gets uploaded and when. I assume that anything running on my computer gets access to everything.
Post reply on HN