3 ms·
why do people give these LLMs full access to everything and then complain when it does somethign stupid? that is what sandboxes are for.
by vorticalbox 3mo ago
why do people give these LLMs full access to everything and then complain when it does somethign stupid? that is what sandboxes are for.
- deleted 3mo ago[deleted]
- dumberquestions 3mo agoOther ones aren't this invasive with user data.
- pixel_popping 3mo agonot true, Claude code on its own often create artifacts and straight up upload private stuff to Anthropic, without asking for it.
- John23832 3mo agoThen show us the example of Claude uploading a home directory to Anthropic because we have an example of Grok uploading a home directory to X.
- skeledrew 3mo agoMaybe possibly with --dangerously-skip-permissions. I've been using auto mode and enjoy how it blocks every tool use that could've allowed something potentially sensitive into context. Burns extra tokens though.
- folmar 3mo agoAuto mode will upload artifacts to Anthropic without asking at least sometimes, for example it did upload my slide decks.
- skeledrew 3mo agoNot auto mode itself (that's just Sonnet running a purely security prompt), but if you're working on a slide deck I can see an upload needed so the working model can "look" at the decks to fulfill your request. If that deck wasn't referenced at all in your prompting requirements... well at least we still have sandboxes.
- steve1977 3mo agoAre we sure about that?
- dumberquestions 3mo agoCodex is opensource, there are other opensource harnesses.
- steve1977 3mo agoBut Claude Code, arguably one of the most famous ones, is not. And recently got some heat about sending meta data that wasn't so obvious. Just as a counter-example.
- dewey 3mo agoWhen I give my text editor or file browser access to everything I wouldn't expect it to exfiltrate data without asking.
- docdeek 3mo agoIsn’t a file browser running locally, while Grok is running on someone else’s server?
- dewey 3mo agoThe point is more that you should not blame the user (why didn't you set up sandbox instead of directly using the tool of big corp) if a tool does something unexpected. If your Dropbox client would suddenly just upload your home directory instead of it's folder you configured you'd also not blame the user that they use Dropbox, you'd blame Dropbox for not doing their job correctly or being user hostile.
- freedomben 3mo agoAgreed. You can still encourage people to use defense in depth without actively blaming them for not having the deepest moat imaginable. Software creators still have some responsibility
- DanHulton 3mo agoWe are speedrunning the various phases of learning about victim-blaming, as a community. It’s kind of wild to watch in real time, instead of over the decades it took society for SA.
- dpoloncsak 3mo agoIs it 'unexpected' when we've been hearing stories like this every week for 2 years now?
- dewey 3mo ago
- wolttam 3mo agoThis wasn't the LLM, it was Grok CLI preemptively uploading the entire CWD, regardless of where that CWD is, to its own server. I don't think it is reasonable to expect every user (including those just starting out with the tools - maybe experimenting, maybe younger/less experienced in general) to think that the tool they're running for the very first time is going to automatically exfiltrate all of their data. It's a pretty serious fuck-up. This guy tweeted about it, who knows how many didn't even notice. It should have been opt-in, it should give user an indication that it's about to do this, etc.
- vorticalbox 3mo agoThe grok-cli is on github[0] there is nothing that I can see in the code that is activily looping ~/ and uploading everything. My two guesses would be one the LLM decided it needed these files for the task or two the user simple asked grok to do it so they could post the tool calls on twitter. [0] https://github.com/superagent-ai/grok-cli https://github.com/superagent-ai/grok-cli
- winstonp 3mo agoThat is not the Grok CLI being discussed. That's an open source, third party CLI. https://x.ai/cli https://x.ai/cli is the official Grok CLI being discussed, and it is not open source.
- vorticalbox 3mo agothanks for the correction
- graemep 3mo agoI think there are arguments on both sides. People should look for guidance on how to use complex tools, but we know people will not. Whose fault is it if someone drives a car without learning how to and injures themselves? On the other hand if the manufacturer has promoted it as one you can drive without learning how to, then whose fault is it? A lot of users are fine with everything being uploaded. Most people's primary computing device is now a phone that backs up everything to cloud and using apps that are thin front ends over cloud services.
- cush 3mo agoIf your immediate reaction to a new piece of software siphoning up someone’s entire system full of highly personal data is, “you’re holding it wrong”, it might help to take a beat and remember that software was developed by a multi-trillion dollar company’s entire business model revolves around siphoning up as much highly personal data as possible
- fwlr 3mo agoWell said. I hope one day it becomes possible for users who choose to install and run said software to also be able to remember this.
- jimbokun 3mo agoNot everyone is a software professional. How many non developers know what a “sandbox” is?