3 ms·
Claude does clearly stupid things, even under auto mode, that no human would reasonably do. I had a sustained 500mb/s ingress to my machine that turned out to b
by 0xfaded 2mo ago
Claude does clearly stupid things, even under auto mode, that no human would reasonably do. I had a sustained 500mb/s ingress to my machine that turned out to be a background "find /" command on a multi-petabyte NFS system. I've now gotten serious about my deny lists, and it trips all the time.
The worst is when it works around the deny list by running an equivalent command like "bfs /" or just writes itself a script.
I wish we would get better sandboxing than more "safeguards", but the direction things are going seems inspired by craw.
- CableNinja 2mo agoThe real question here is why youre freely running it on a system and dont have it sandboxed in some way. Literally the first thing i did the day i signed up for an ai subscription. I have a base docker container and a shell script that "customizes" each instance for where its running (making sure user id matches for permissions, etc). Runs as non root in container, has minimal privileges, and only access to the repo or dir where the shell script was called You definitely let the ai shoot your legs off all on your own.