3 ms·
How do you have any kind of trust in these tools? They always feel like one prompt injection away, or one over eager agent away ("I'll lookup a forgotten creden
by FooBarWidget 2mo ago
How do you have any kind of trust in these tools? They always feel like one prompt injection away, or one over eager agent away ("I'll lookup a forgotten credential in an email to ssh into a server to hack a system in order to fulfill your request"), from disaster. I don't trust any AI session unless I carefully select the exact files they have access to. No way do I dare sharing my entire mailbox.
- FooBarWidget 2mo agoVery weird for this to be downvoted. It's a legitimate concern. It's also a legitimate question: where do you get your trust from? Do you have guardrails? Or is it really just blind trust?
- brazukadev 2mo ago> Very weird for this to be downvoted. sama was the CEO of YC. OpenAI knows the value of influencing the sentiment here and then naturally its competition too.
- FooBarWidget 2mo agoWhich is weird since this is not a criticism on AI. I really want to know how I can use things like Claude Work without the risk of it going rogue! Giving it access to lots of systems is potentially very valuable, but also so dangerous that I dare not to.
- ghshephard 2mo agoOur InfoSec teams are insanely restrictive. No Claude Code out of Sandboxes, MCP servers hyper locked down, etc.... I think your reservations are really good - but - at the end of the day - I need to do work - and CoWork does it for me. It doesn't just have access to my entire machine - it has access to all of our Corporations Google Docs, Google Sheets, Jira Tickets, Confluence, Slack - everything (Except, weirdly - our GitRepos - they aren't confident enough there to let CoWork talk to them) Weirdly - my work email is mostly irrelevant - nothing in their other than some sporadic company announcements - I'll go a week without looking at it - so it's the least concern. (Very different from personal gmail which, omg - if anyone got into - game over)