5 ms·
Reminder to everyone, treat these as trojans. Run them isolated from the rest of your system. Give it a full desktop in a VM if you want to, just not direct ac
by cloudie78 2mo ago
Reminder to everyone, treat these as trojans. Run them isolated from the rest of your system.
Give it a full desktop in a VM if you want to, just not direct access to your system.
- perching_aix 2mo agoThey ship with their own sandboxing by default, and Codex specifically is open source.
- badcafe23423435 2mo agoif it is open source why no exist any fork? why I can remove openai model default from instalation?
- rawland 2mo agoI’d wait. Remember when Chromium downloaded and installed binary blobs. Also in the news: https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/ https://www.whitehouse.gov/presidential-actions/2026/08/expa... "The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States."
- wahnfrieden 2mo agoThis app is NOT open source
- embedding-shape 2mo ago> and Codex specifically is open source. Since we now have three "Codex"es, I think it's worth specifying you're talking about codex-cli/tui. Codex the hosted version and Codex the GUI are both fully proprietary I think (besides the codex-cli/tui parts they use, I'm guessing mainly the app-server stuff).
- deleted 2mo ago[deleted]
- avazhi 2mo agoIs this the same thing that broke out of the sandbox and into HuggingFace? Or we are just assuming that was a PR stunt, which it almost certainly was. Either way, this shit isn’t getting near my system.
- deleted 2mo ago[deleted]
- perching_aix 2mo ago> Is this the same thing that broke out of the sandbox and into HuggingFace? No. > Or we are just assuming that was a PR stunt, which it almost certainly was. It wasn't. > Either way, this shit isn’t getting near my system. Sounds about right.
- avazhi 2mo ago> > Or we are just assuming that was a PR stunt, which it almost certainly was. > It wasn't. Prove it. But you can’t, which is problematic for you. Nobody should believe anything OpenAI says about anything. They either lied about it breaking out of a sand box, or they’re incompetent by building a sandbox their AI could break out of. It’s a cute story, though.
- perching_aix 2mo ago> Prove it. But you can’t, which is problematic for you. More honestly: "Convince me. Except I've already made up my mind, so I'll never let you." And like yeah, that does seem to be the case, so that's a bit rough indeed. That said, if you feel like being a bit intellectually daring tonight, here you go: https://youtu.be/87DyyMV0kCY https://youtu.be/87DyyMV0kCY > Nobody should believe anything OpenAI says about anything. It's a great thing you bring up beliefs: it's the only thing people ever have, both you and me. Personally, after hearing their account (linked above), I don't find much to disbelieve on it. It's just a series of "oh okay, that's fun, makes sense" moments. It's normal stuff. They're definitely at least a little proud of having popped a few shops, but that's very realistic in its own way. I guess your best next option is waiting for a lawsuit to reach discovery or something, and then it's a matter of how dedicated you are to your disbelief. This indeed hasn't happened yet though, if it ever will, so nothing for me to provide (nor for you). Speaking of, note that I don't have any more reason to believe the likes of you than I do OpenAI. Especially because it all just comes across as trite cynicism, mixed with generous amounts of wishful thinking. I also happen to be simply using these things, so that further plays into why I don't find these events particularly miraculous. It's already existing capability for the most part, so why would I? The only difference is disabled guardrails and better temporal coherence, which is exactly what you'd expect from upcoming models still in eval. > or they’re incompetent by building a sandbox their AI could break out of. One could definitely make the argument that someone was at least a little asleep at the wheel, but I don't think that makes them particularly incompetent. Just the normal variety you'll find anywhere else.
- fragmede 2mo agoHow do I get it to fix my Bluetooth if I do that? If you've been AI-pilled, 2026 is the year of Linux desktop because instead of dicking around with config files, I can just tell AI to fix python.
- rawland 2mo agopi.dev, local model, (RAG-ed) copy of archwiki. You are more able than you believe. Already now, no permission needed.
- trvz 2mo agoLiterally the same security risk.
- embedding-shape 2mo agoThey're talking about letting the agent access the bluetooth stuff, not about where to get information/knowledge from.
- couscouspie 2mo agoHow is Hermes different in that regard? Also note, that RAG and even vector search are more paths of the early days that didn't prove too valuable. Just let your agent search it directly and optionally create an index as a default entrypoint for common topics.
- rawland 2mo agoFair points. Agreed.
- cyanydeez 2mo agoI just use a local model; its too dumb to hack into NSA just to fix my bluetooth.
- jwrallie 2mo agoBluetooth is the one thing I had problems in the past on GNU/Linux, Windows, macOS, Android and iOS. Linux is the only mentioned platform where you could technically give Codex root and let it fix it :) I guess OpenBSD is the only OS where I never had any problem with Bluetooth audio.
- debazel 2mo agoAnd that's not a joke, I made the mistake of installing this on my Windows machine just to test it out quickly last week. It created 2 new users and then assigned new NTFS permissions for every single file under my user directory to them. This of course wrecked havoc, ssh refused to work, several applications refusing to start and a ton of permission errors. It did this without even a warning in the background and it also does not undo any of it when you uninstall it. It took around 3 hours to fix it by updating ~10 million NTFS permissions for every single file under my user directory.
- semyonsh 2mo agoAt that point I'd rather re-install the whole machine. Beats 3 hours of wrangling NTFS permissions and inheritance.
- nehal3m 2mo agoIf you’re doing that anyway you might as well install a hypervisor and layer your OS on top. That way you can snapshot before your LLM with root fucks everything up again.
- CamelCaseName 2mo agoSorry, what was the problem we were originally trying to solve again?
- nehal3m 2mo agoLiving a meaningful life. My yak has too much hair though.
- spider-mario 2mo ago“Guys, guys, guys, can we take a step back here? What problem are we really trying to solve?” https://medium.com/conquering-corporate-america/10-tricks-to-appear-smart-during-meetings-27b489a39d1a https://medium.com/conquering-corporate-america/10-tricks-to...
- pjmlp 2mo agoWith exception of VSCode, because I have no choice due to some plugins, or apps required by customer projects where I have no other option as well, nothing else based on Electron pollutes my computers.
- cloudie78 2mo agoYou always have a choice to use/learn/make a different tool. It’s a prison of your own making. I’ve personally adopted a process where I structure my projects to ALWAYS keep credentials and sensitive information in a separate directory. The working copy gets rsynced to and from a dedicated VM with whatever $HARNESS.
- p-e-w 2mo agoMany official, high-quality language support plugins are only available for VSCode. For some languages, you have a “choice” to use another IDE in the same sense that you have a choice to do programming with a hex editor. Lean being an example, where every alternative is in its infancy.
- pjmlp 2mo agoIf I have to deliver in technology X, customer isn't going to be happy getting Y instead, and I am not making my life miserable to work with editors lacking the specific tools, or that are forbidden by customer IT to be installed on provided equipment.
- cloudie78 2mo ago