Live data from Hacker News

Grok CLI uploaded the whole home directory to GCS

twitter.com

111–120 of 434 posts

Re: Grok CLI uploaded the whole home directory to GCS

#113

So many of the replies are saying that they should've restricted access using .md files and whatnot. Is really any guarantee that they even follow those? It seems like even if you ask pretty please don't touch those files, there's a chance they will. So many people have just willingly installed spyware on their computers and big tech calls this the next big thing.

[dead]

Re: Grok CLI uploaded the whole home directory to GCS

#116
post #40

Earlier quoted context omitted.

All those things are optional. Doesn't make uploading the keys that much better. Now is the time for key rotation everywhere. Fast.

How are they optional? You obviously haven't worked anywhere security sensitive. I'm not talking about whether what Grok did is bad or good, I'm talking about protecting your private key and the servers you connect to. An unencrypted private key is no different to an unencrypted password manager, and thats a fact. Dont store secrets in plain text.

Sigh.

Anything that isn’t a default is optional by default. Anything that’s toggleable or configurable is optional.

Security is, always, a trade off. It is hilariously common for private keys to work as a full identifier for a person, without concern of IP or anything of the sort. Should they? Maybe, maybe not, that’s the calculus of risk management; but victim-blaming the average person who is following best practices is a bad look.

Re: Grok CLI uploaded the whole home directory to GCS

#120
post #57

Earlier quoted context omitted.

I don't understand these people. Agent instructions in markdown is barely a suggestion. I have one which says "All code in this repository is executed in docker containers, run the services with `docker compose run --rm php-cli "$@"`. Gemini and Claude more often than not refuse to abide and will try to execute the environment using /opt/homebrew/bin/php on my host…

A frightening amount of people have no idea how AI tools work, even those that should know better. I have seen senior software developers fall for the mistake of believing an LLM output when it spews bullshit about how its own memory or restrictions work. LLMs will listen to you and follow your instructions and restrictions most of the time, which seems to be enough for people to believe that they will every time. I'…

There’s an aspect of extrapolation in the perception spike of the Dunning–Kruger effect.

In the same way smart people, doctors etc, can be better victims for scams I think tech skills can really give the wrong impression of how transformers and LLMs work. If someone has decades of relational database experience all their assumptions will be coloured towards data existing in the model accessible in a rational manner.

Post reply on HN