4 ms·
This was of course dependent on yolo mode, but automatic approval has also been pulling stunts like this. A recent example is data that was purposely kept away
by nialse 4mo ago
This was of course dependent on yolo mode, but automatic approval has also been pulling stunts like this. A recent example is data that was purposely kept away from Codex in a folder far far away. When it found a single reference it just went for the data when having an issue. Lesson learned, keep essential data and Codex separated on different machines. Codex remote ssh actually helps here.
- eqvinox 4mo agoWhat in heaven's name is a "folder far far away"? (It sounds like you put it on an SSD on an extension cord and moved it to the kitchen or something.)
- embedding-shape 4mo agoOr, learn your local OS' permission system, have it in a directory right next to your banking credentials (or something even more outrageous) and nothing could go wrong even if you tried to.
- AnotherGoodName 4mo agoThis very thread was an example where it unintentionally got root access though.
- embedding-shape 4mo agoBecause of how Docker works, not because of how Unix permissions work.
- f33d5173 4mo agoUnix has always had incredibly weak protections between users. You shouldn't rely on it as a security boundary. Think of it as a "keep honest users honest" protection. And llms are not honest.
- ElectricalUnion 4mo agoThe protections between users are reasonably strong. Android uses them with great success, by isolating every vendor within their own user. Things start going to hell when everything runs under root for "practicality reasons", like the default, not-rootless Docker setup.
- amarant 4mo agoI've seen this sentiment a few times on HN recently I wonder where it comes from? The only thing I can think of is that if the protected files are on a unencrypted drive, then you could boot from a live-usb(or similar) where you have root and read anything. But that's completely irrelevant as we're talking about a piece of software running on a system without root. In this scenario Unix user permissions are safe, barring user error (such as accidentally granting root, like in this instance) Of course security holes happens, such as copy-fail, but it's pretty rare in the grand scheme of things, and tend to get patched quickly(like copy-fail was)
- CGamesPlay 4mo agoThat's a terrible distinction to make on a topic about how the coding agent gained root inadvertently.
- AnotherGoodName 4mo agoFwiw separate machines for the agents is awesome in general anyway. I have agent frontends running on a low power server where every session is in tmux. So i can just resume from my home pc and pickup where i left off without reestablishing context. I do have to manually feed it data it can access bit that’s also a feature. Also let’s me shutdown the home pc if it’s some long running task since the server is much more power efficient.