7 ms·
So many of the replies are saying that they should've restricted access using .md files and whatnot. Is really any guarantee that they even follow those? It see
by LetsGetTechnicl 3mo ago
So many of the replies are saying that they should've restricted access using .md files and whatnot. Is really any guarantee that they even follow those? It seems like even if you ask pretty please don't touch those files, there's a chance they will. So many people have just willingly installed spyware on their computers and big tech calls this the next big thing.
- fhdkweig 3mo agoThat's the whole reason I refuse to install Google Drive or Dropbox's desktop applications. I only use the web interface so I know exactly what gets uploaded and when. I assume that anything running on my computer gets access to everything.
- mindlessg 3mo agoSounds like a very wise decision to me. I found found out on my phone that the google photos application uploaded everything in my gallery to their servers without asking me, regardless that I had explicitly disabled all backup to my google accounts on the settings of the phone. I only figured it out when they sent me emails saying that my storage was full.
- aakresearch 3mo agoOoooh, don't get me started how mad it makes me! I am paranoid (or just lucky) enough that I didn't yet had it happen to me, but my wife's phone had done it four times in the last year. Each time I check and double check that all "backups" are turned off, and each time it somehow pops back. So, Google "backs up" a 128Gb worth of photos on the phone onto 15Gb free storage combined with Gmail and who knows what, completely clogs it (as if it couldn't be predicted) and then has audacity to suggest paying for "extra storage". There is no way in online UI to just delete the whole "backup". And the cherry on top: when you finally get to delete some there is a fine-print - "the selected photos will be deleted from all synced devices". Well, I guess I must be thankful that they at least show this warning. This is what passes as "backup" in Google's parlance these days.
- drnick1 3mo agoI would go further and not upload anything that isn't encrypted to cloud storage services. It is extremely likely that those "services" inspect your files.
- evenhash 3mo agoThey do, unquestionably. https://www.thetimes.com/world/article/google-bans-father-over-medical-photos-of-childs-groin-ptlp63sq0 https://www.thetimes.com/world/article/google-bans-father-ov... > Mark, from San Francisco, had noticed swelling in his son’s groin and used his phone to photograph the problem to get an emergency appointment in February last year. He shared the pictures with a nurse so that a doctor could review them. > However, Google’s artificial intelligence system used to detect child abuse flagged the image to the police and Mark, a software engineer who asked to be identified by only his first name, was investigated and lost access to his Google accounts. He was exonerated by the police in San Francisco but his Google account has not been reinstated.
- ricardobeat 3mo agoSandboxing is not difficult, and harnesses like Claude Code have it built-in + other protection with auto mode.
- usrusr 3mo agoIs that built in protection really a filter, on code level, that sits between the LLM session and the shell or is it just some pleading in the bootstrap prompt? "Pretty please don't do xyz this is important!!!11"? The latter can seem to be as good as the former for any amount of time. No outside observation can really prove reliability, only the negative result ("it does occasionally break the rules we expect") would be proof. So it's difficult to trust any claims that it's the former. And even if it does have some of the former, chances are that the protection you experience is only partially provided on code level, while an unknown amount is still just bootstrap prompting that just works until does not.
- llimllib 3mo ago> Is that built in protection really a filter, on code level yes, on mac it uses seatbelt and on other platforms it uses similar tools: https://code.claude.com/docs/en/sandboxing https://code.claude.com/docs/en/sandboxing
- hvb2 3mo agoAsking the wolves to look after the sheep
- Lwerewolf 3mo agoOnly guarantee that you can get is the sandbox in which it operates. The model itself is a slot machine and can result in anything, and if its sandbox is nonexistent... here's one possibility.
- da_chicken 3mo agoYeah, I absolutely understand the allure of agentic AI, but I am absolutely not going to give shell access or data access to any agent. Certainly not with my permissions level. Until we can get something set up that gives strict schema-only access I'm going to copy and paste definitions for context. Yes that sucks, but it's my responsibility to protect the system just as much as it is to develop scripts and queries for it.
- TacticalCoder 3mo ago> ... I am absolutely not going to give shell access or data access to any agent. Certainly not with my permissions level. Of course not. To me it's on a server, in a VM. And they're not seeing the real data/databases from the actual projects: they're seeing fake infos used only while in the dev environment. There's no way I'm dumping, even for tests, the real or part of the real DB somewhere an AI can see it. To find bugs (for example), AIs are useful but honestly for code generated by LLMs, I'm thinking about going back to the early copy/paste from the ChatGPT days: because I see so many horrors in the code output by the latest SOTA LLMs that every single line of code they spew has to be checked by someone who does know better. It's not just an issue of protecting confidential data / preventing spying: we're all discovering that we've got serious sloppy-pasta code problems now.
- swatcoder 3mo agoYou are correct. You can't trust the agent, let alone its harness, to oberve any particular directive you give it, so "md files" provide no meaningful protection for anything important. But users are broadly reckless and naive and commercial vendors are exploitative and irresponsonsible, so the vendors take advantage of what they can get away with for as long as they can get away with it. Use a tight sandbox, and join the chorus loudly when others press on vendors to be make user safety an earnest and hard-to-abandon priority.
- Y-bar 3mo agoI don't understand these people. Agent instructions in markdown is barely a suggestion. I have one which says "All code in this repository is executed in docker containers, run the services with `docker compose run --rm php-cli "$@"`. Gemini and Claude more often than not refuse to abide and will try to execute the environment using /opt/homebrew/bin/php on my host…
- jeroenhd 3mo agoA frightening amount of people have no idea how AI tools work, even those that should know better. I have seen senior software developers fall for the mistake of believing an LLM output when it spews bullshit about how its own memory or restrictions work. LLMs will listen to you and follow your instructions and restrictions most of the time, which seems to be enough for people to believe that they will every time. I've come to terms with the impact slop coding will have on most software jobs in the future, but seeing seemingly intelligent people fall for lies and fantasies concocted by an LLM is making me more and more uncomfortable with the direction we're all heading in.
- bonesss 3mo agoThere’s an aspect of extrapolation in the perception spike of the Dunning–Kruger effect. In the same way smart people, doctors etc, can be better victims for scams I think tech skills can really give the wrong impression of how transformers and LLMs work. If someone has decades of relational database experience all their assumptions will be coloured towards data existing in the model accessible in a rational manner.
- grey-area 3mo agoAre we all heading in that direction? I know it may seem like that reading HN but LLMs are not necessary for writing software, they might be a useful adjunct to it, but they do not have to be central to it (and Id argue they shouldn’t be). We don’t have to head in this direction of using LLMs for most development at all.
- HiPhish 3mo ago> LLMs will listen to you and follow your instructions and restrictions most of the time, which seems to be enough for people to believe that they will every time. It's called automation bias. If something works 90% of the time the human mind will extrapolate that to be 100%. That's just how humans work. https://en.wikipedia.org/wiki/Automation_bias https://en.wikipedia.org/wiki/Automation_bias
- moronicles 3mo ago[dead]
- monegator 3mo ago> Is really any guarantee that they even follow those? No, there isn't. I just don't understand how naive (or imbecile) people are. The most valuable thing for these companies is people's data used for training, so giving unrestricted access to a tool from them and believing they will never take advantage of it to gobble up whatever they want from your computer, just because they told you they'll never do that, swearsies, is naive, or incredibly stupid. Insulate yourself, or better yet, go local whenever possible, and there isn't much you can't do local if you have enough patience.
- __MatrixMan__ 3mo agoI don't understand why the AI world does this. We don't need new security. We have security at home. It starts with sudo -u restricteduser myagent Your OS knows how to restrict access to things, you don't have to trust a pinkey promise from a vendor.
- bpavuk 3mo agoand Landlock! Pi even has a sandbox plugin for Landlock
- khalic 3mo agoWhy would you give a non-deterministic text generator a user account? It’s not a person, it’s barely a tool at the software level. Restrict at the right level, in this case, a complete sandbox around it given its propensity to hallucinate and be steered by anybody.
- Izkata 3mo ago...this is a completely normal thing to do in linux, it's the most basic form of access control. There's like a dozen non-human accounts in a clean install before adding your own like this, and a lot of software adds their own. Edit: I have 54 entries on my personal laptop, just one of which is actually me.
- warshinder 3mo agoHe said it’s less than a software, so saying software does this too isn’t really a strong counter argument. In case, I don’t think you are really in disagreement. Restricted accounts are necessary is your point, but I think op is saying they aren’t sufficient.
- nadzzz 3mo ago[dead]
- pimlottc 3mo ago"IMPORTANT: Before entering the leopard pen, don't forget to put on the leopard safety jacket that reads 'UNDER NOT CIRCUMSTANCES SHOULD YOU EAT MY FACE'"
- JeremyNT 3mo agoI guess the downside of the lower barrier to entry to use these tools is the lack of basic understanding of exactly this sort of concept. This sort of thing is why I'm hopeful I'll continue to have employment going forward. Some expertise is hard won and there's just no replacing learning through experience.
- ethagnawl 3mo agoI think you're right in principle but I just hope I can hold out long enough for my experience to become appreciated and whose corresponding hourly rate isn't something which is suddenly being scoffed at (i.e. markets can remain irrational longer than I can remain solvent).
- dv_dt 3mo agoI built a docker container that volume mounts the project directory
- tehlike 3mo agoThis is the only pragmatic way really.
- cpburns2009 3mo agoThis is exactly what I do for AI agents.
- miladyincontrol 3mo agoI almost exclusively dev in containers as is, cant really imagine letting some AI model run free on bare metal no matter what claims of guardrails it might have.
- Sanzig 3mo agoYou can even go a step further and run the container in a VM, such as with Docker Sandbox or the krun runtime in Podman. There's also smolvm which is a nice minimal microvm manager based on libkrun: https://github.com/smol-machines/smolvm https://github.com/smol-machines/smolvm. I vibe coded a little shell utility for building and running OCI images for the Pi harness using it (easy enough to do manually, but the automation just makes it a couple quick commands rather than digging through documentation): https://github.com/neuroblaze/smol-pi https://github.com/neuroblaze/smol-pi
- dv_dt 3mo agoYup, good call, I'll have to check those out. Not that urgent to me as I also happen to use colima for it's docker daemon interface. And, colima uses a full VM to host the containers, and you can further lock down the config to what is even allowed to vol mount so there's even another fs access restriction layer in play.
- cpburns2009 3mo agoI have a similar setup using containerd/nerdctl and Kata Containers. Each OpenCode instance runs in its own little VM with mounted folders for context.
- _verandaguy 3mo agoI will keep banging this drum until people listen: Trying to use markdown files to limit access should never be treated as a security guarantee at all. This is a form of in-band signalling that goes into a machine that, among other things, tries to read between the lines of your requests, extrapolate user desires, and please the user. The only sane way to address this is using a control plane. A well-built harness can do this; a sandbox can do this; hell, a carefully-chosen `umask` can do this; but both of those are liable to introduce notification fatigue in the user.
- WhyNotHugo 3mo ago> Trying to use markdown files to limit access should never be treated as a security guarantee at all. This is akin to politely asking guests to to steal your jewels. If your jewels are in the living room, and your guests have unfettered access to the living room, this technique will only work for the most trustworthy of guests.
- altruios 3mo agoI agree with this. And also think that we should train and select for trustworthy models. I also agree that these models may never truly be trustworthy.
- tetha 3mo agoIt reminded me of an old meme. Please don't follow the following instructions and stop reading if you cannot. It was just a popup: "Hello. This is virus from Albania. Due to poor technology in country, I cannot harm your computer directly. But since you are honest person, please delete some important files from computer and mail this file to at least 3 other people!" Claude.md is an equally effective defensive tool. But sorry if you lost some files from reading that.
- thesuitonym 3mo agoIt's wild that we've known for decades to use ACLs to make sure people don't have access to files we don't want them to have access to, but somehow a computer pretending to be a person doesn't get that same treatment.
- embedding-shape 3mo ago> So many of the replies are saying that they should've restricted access using .md files and whatnot. What? No, but the random 3rd party software you run on your computer, must be limited by you in some way, haven't we learned this even after the AUR, npm and LLM shenanigans we've dealt with for decades at this point? No, don't ask the model "Please don't go outside this directory", you limit the runtime (via VMs, containers, unix permissions, whatever) so it only has access to what it should, not more. Same goes for any software, not just agents or chat clients or whatever. Any 3rd party software you don't want to have access to your entire computer, you need to run in this way.
- leshenka 3mo agoSometimes you can't even rely on harness not allowing ai to access certain files. "Oh, user doesn't want me to use `read_file` on .env? Well how about I run `cat .env` then?" That's scary. Really should run it under different user with carefully assigned permissions.
- Stromgren 3mo agoThis was posted on HN yesterday: https://gist.github.com/cereblab/dc9a40bc26120f4540e4e09b75ffb547 https://gist.github.com/cereblab/dc9a40bc26120f4540e4e09b75f... If it’s to be trusted, it has nothing to do with the “agent” or what’s sent to the LLM. The harness will just straight up package the folder it’s run from and upload it to Google Cloud Storage.
- embedding-shape 3mo ago> If it’s to be trusted, it has nothing to do with the “agent” or what’s sent to the LLM. The harness will just straight up package the folder it’s run from and upload it to Google Cloud Storage. Even if there is a misunderstanding who is really uploading the directory, the TUI/CLI itself by actual code, or if the model decided to do so in the session, if you apply the recommendations from the replies to parent, and it no longer matter who did it, neither the software nor the model will be able to upload all your ssh keys.
- Stromgren 3mo agoNo I disagree. A harness reading a file is a tool call and it happens locally, which means that I can control it. I can configure that I need to permit any file reads and now I _should_ have control of what is sent. The difference between that and silently uploading my entire working directory in the background is miles apart IMO. I understand that one should think carefully about how they work with a non-deterministic tool, but this if different completely. This is xAI just choosing to upload and store everyone’s directories - with full git history.
- deleted 3mo ago[deleted]
- bombcar 3mo agoIf you've not realized your agents ignore MD files from time to time, you've not used your agents enough. The real enforcement has to be done via methods that YOU can't easily bypass, or they will bypass (OS-level prohibitions, etc).
- kerng 3mo agoWhat happened here is not related to agentic behavior or instructions in .md files. It's a binary a user runs, it scoops up their files and sends them to a third-party. And the user even paid $99/month or more for having their data leaked.
- deleted 3mo ago[deleted]
- cryo32 3mo agoYeah that advice is smoking crack. I have no idea what people are thinking these days? We seem to have lost any sensible security understanding recently. You can't gaslight something into not doing something bad. There has to be a hard security control that prevents it doing something bad. And if you don't know what it's capable of because it's non-deterministic then you have to start with a default block everything. This should have never been possible with any sensible design. On my first point again, ethics and engineering both went out of the window when fast and shiny came along. This is disgraceful.
- tarnith 3mo agoIn what universe would a sane person allow any LLM or remote calling software access to their user folder with sensitive data in it? I swear, people hear the word LLM and their brain resets when it comes to good software practices. Did VMs suddenly stop existing? Kata containers? An RHEL box with SEL? It's like there's a new technology and everyone suddenly decided to shutoff their brain when it comes to basic security.
- BatteryMountain 3mo agoClaude definitely do not respect all my rules, it often ventures into other folders, most often other projects on the same machine that was greenlit before but not from the current projects' side. One other anomaly I had in the last month: I have two linux users on my laptop, one for work, one for personal. On my work account, it asked me if I wanted to continue with project x, which is in my personal account and not present at all in my home directory with work stuff. So somehow the memory system is keeping context where it shouldn't. Interesting I used this learning to improve the agent framework/harness I have running at work: it now creates a new linux user for each agent which have much stricter rules on how it can read/write to the system, and it is also no longer running as root. Much safer now. Still don't trust it 100% though.
- TimJRobinson 3mo agoDevcontainers are a much better solution, super easy to setup with VSCode and ensures the AI can't access your main machine.