5 ms·
The fact people are giving credentials to all these MCP tools keeps amazing me. Ten years ago if you built a service that asked you for permissions to everythi
by progbits 1y ago
The fact people are giving credentials to all these MCP tools keeps amazing me.
Ten years ago if you built a service that asked you for permissions to everything imaginable most people would keep well clear. I guess the closest was Beeper which wanted your social passwords but that was heavily criticized and never very popular.
Now you slap an AI label on it and you can't keep people away.
- wirehack 1y agoWe also provide an open-source version for Strata so that you can have full control. You can self-host it on your own infrastructure, so your credentials never have to touch our servers.
- progbits 1y agoThat's nice, kudos. But trusting you is only half of the problem. I don't trust the LLM either.
- wirehack 1y agoYeah I see what you mean. Many MCP clients has the ability to ask human for confirmation before a tool call is executed. In this way, you can check the tool call before it executes.
- gk1 1y agoWhat do you propose they do? Because although something like Strata makes it easier, the reality is people are piling up MCP servers like they're free cupcakes. There's no getting the cat back in the box. (I'm not in security so I genuinely don't know and am curious.)
- deleted 1y ago[deleted]
- smrtinsert 1y agoWe're keeping an unofficial allow list at work. Basically just major software companies only. Third party mcp servers at this point are basically just attack vectors. How do you even vet them continuously? Honestly vetting MCP seems like a YC company in and of itself.
- wirehack 1y agoWe build our MCP servers ourselves and many of them are open source. You can check out our github repo.
- mikestorrent 1y agoYeah, we face this issue as well. Folks are super keen to just download code from random people's githubs and run it with their credentials and grant it access to contexts that have all kinds of abilities to cause damage if there was ever a supply chain attack.
- electric_muse 1y agoMCP is like the "app store" for LLMs. LLMs can only do so much by themselves. They need connectivity to pull in context or take actions. Just like how your phone without apps is pretty limited in how useful it is. Sure, teams could build their own connectors via function calling if they're running agents, but that only gets you so far. MCPs promise universal interoperability. Some teams, like Block, are using MCP as a protocol but generally building their own servers. But the vast majority are just sifting through the varying quality of published servers out there. Those who are getting MCP to work are in the minority right now. Most just aren't doing it or aren't doing it well. But there are plenty of companies racing into this space to make this work for enterprises / solve the problems you rightfully bring up. As others have said here, the cat is out of the bag, and it is not going back in. MCP has enough buy-in from the community that it's likely to just get better vs. go away. Source/Bias disclaimer: I pivoted my company to work on an MCP platform to smooth out those rough edges. We had been building integration technology for years. When a technology came along that promised "documentation + invocation" in-band over the protocol, I quickly saw that this could solve the pain of integration we had suffered for years. No more reading documentation and building integrations. The capability negotiation is built into the protocol. Edit: a comma.