3 ms·
At this stage with the latest models with "increased persistence" and the sheer amount of supply chain attacks, you'd be insane not running these tools in a san
by etoxin 2mo ago
At this stage with the latest models with "increased persistence" and the sheer amount of supply chain attacks, you'd be insane not running these tools in a sandbox.
- fender256 2mo agoExactly. Claude in a VM is the way to go.
- trvz 2mo agoA VM hosted by someone else. Somethig on your personal notebook or the proxmox server in your garage is still too risky.
- supermatt 2mo agoWhy are 3rd party hosted VMs safer than your own?
- trvz 2mo agoThey're not. When things go wrong it's better to compromise someone else's VM host than your own computer. It's only a matter of time now until AI will find novel ways to break out of virtualisation.
- faeyanpiraat 2mo agoIn the short term wouldnt a “dont escape” prompt prevent this? Also if it started being widespread wouldnt Anthropic specifically train new models against doing it?
- trvz 2mo agoNo. No.
- supermatt 2mo agoSo the concern is that the agent will discover a novel VM escape, exploit it and take control of your whole machine instead of working on its prompted task? That seems rather far fetched.
- pianopatrick 2mo agoMight be more secure to get a real laptop and treat Claude as any other human worker. I.e. apply all the normal sysadmin tools that manage laptops for people to manage the laptop for Claude
- deleted 2mo ago[deleted]
- user43928 2mo agoYet millions do just that without any widely reported issues yet. For supply chain attacks, there has not been a comprehensive solution, if for example you have to use a number of npm dependencies. No one has the capacity to review changes to these dependencies when you upgrade them. Now, if only we had an automatic tool that could intelligently review a large amount of code changes for malicious or vulnerable additions...