3 ms·
I'm having trouble finding a use for this outside of virtualized unused environments. Why not instead give me a virtual machine that runs this in a confined sto
by byronic 1y ago
I'm having trouble finding a use for this outside of virtualized unused environments. Why not instead give me a virtual machine that runs this in a confined storage space?
I would _never_ give an LLM access to any disk I own or control if it had anything more than read permissions
- extr 1y agoWhy not? Have you ever actually used these things? The risk is incredibly low. I run claude code with zero permissions every day for hours. Never a problem.
- byronic 1y agoI have (not an exhaustive list) SSH keys and sensitive repositories hanging out on my filesystem. I don't trust _myself_ with that, let alone an LLM, unless I'm running ollama or similar local nonsense with no net connectivity. I'm a few degrees removed from an air gapped environment so obviously YMMV. Frankly I find the idea of an LLM writing files or being allowed to access databases or similar cases directly distasteful; I have to review the output anyway and I'll decide what goes to the relevant disk locations / gets run.
- Touche 1y agoThey don't have arbitrary access over your file system. They ask permission for doing most everything. Even reading files, they can't do that outside of the current working directory without permission.
- mark_undoio 1y agoI'm pretty comfortable with the agent scaffolding just restricting directory access but I can see places it might not be enough... If you were being really paranoid then I guess they could write a script in the local directory that then runs and accesses other parts of the filesystem. I've not seen any evidence an agent would just do that randomly (though I suppose they are nondeterministic). In principle maybe a malicious or unlucky prompt found somewhere in the permitted directory could trigger it?
- globular-toast 1y agoComments like this just show how bad the average dev is at security. Ever heard of the principle of least privilege? It's crazy that anyone who has written at least one piece of software would think "nah, it's fine because the software is meant to ask before doing".
- swader999 1y agoYour obviously skilled, spending the money on a Claude only machine would pay for itself in less than three weeks. If I was your employer, it would be a no brainer.
- alwillis 1y agoFor example, Gemini CLI [1] can use native sandboxing on macOS. It's just a matter of time before every major coding agent will run inside of an operating system's native sandbox/container/jail/VM. [1]: https://github.com/google-gemini/gemini-cli/blob/main/docs/cli/configuration.md#sandboxing https://github.com/google-gemini/gemini-cli/blob/main/docs/c...
- ygouzerh 1y agoThe permissions is quite well defined, by default it will ask you for your approval before every cli command that it will run
- leerob 1y ago(I work at Cursor) We also support running the agent in a VM at cursor.com/agents