4 ms·
Just be aware that AI agents will explore alternate means of accessing said files: https://news.ycombinator.com/item?id=48348578 https://news.ycombinator.com/it
by lelandfe 4mo ago
Just be aware that AI agents will explore alternate means of accessing said files: https://news.ycombinator.com/item?id=48348578 https://news.ycombinator.com/item?id=48348578
- cowsandmilk 4mo agoIf you’re already running codex as a different user to limit its file permissions, why would you add it to the docker group?
- lelandfe 4mo agoA good but altogether separate note from the point I’m making: this lack of access is seen as an obstacle to overcome, and other means of access will be tried if available. It’s a different mental model than a first party solution to “ignore” files.
- TheDong 4mo agoWeirdly, the existing first party solutions around denying commands don't seem to help here. Often enough, when one of the agents prompts for running "sudo", and I reject it, it will do what looks very much like malicious exploration to figure out how to handle things anyway, including once hijacking a separate shell's pty where I did have a valid sudo session already in order to execute some commands. We don't yet have the capability to make these models behave in a consistent, deterministic, or safe manner yet, so a first party solution isn't even necessarily that much better. Especially if it gives a false sense of security.
- lelandfe 3mo agoOTOH it lets you file a bug report :) As opposed to, "well, you should have ran it in a container if you didn't want your baby photos deleted"
- jen20 4mo agoLack of knowledge and the desire to have it run containers for things.
- amelius 4mo agoYes. Any sane IT department would not allow external AI services, only local ones. It is just too easy for your company's data to end up on the wrong servers. If not through faulty file permissions, then through employees who simply post company ideas.
- brookst 4mo agoOr just have a corporate contract that provides assurances. Though really I’m skeptical that much corporate info is secret for competitive or privacy reasons. Mostly it seems to be for liability / discovery reasons. Which are still legit of course, but ideas are a dime a dozen and every company has more than they know what to do with. It’s the resourcing and execution that are hard.
- amelius 4mo ago> Or just have a corporate contract that provides assurances. After the massive copyright infringements and recent "who care's about the law anyway" stance of corporate America, trusting this could be a grand mistake.
- brookst 4mo agoIt’s a risk. But odds are the upsides from the legal settlements would far outweigh the losses from your super secret memos about q3 budget planning being trained on. Just treat it like a contract worker. They may violate their NDA. That doesn’t mean you never use any for any purpose ever. It’s a risk that’s been managed since before computers.
- SoftTalker 4mo agoYet many use public github, and human developers accidently push secrets and other "not for public" files all the time.
- amelius 4mo agoExactly proving the point.
- martylamb 4mo agoYes. I found this quickly after wrapping codex in a launcher that uses bubblewrap to exclude certain files and directories based on a config file at the project root. My best solution so far is to also include instructions for the agent that explain that it is not allowed to see certain files, and that their inaccessibility is not an error, and that it must not attempt to access them through other means (e.g. via git history, etc.). This has been a major improvement, but it's not foolproof.