3 ms·
This article smells AI generated, which is _very_ funny given the argument being made. Either way, while this is true in the absolute, this is the value of bui
by nameless912 1mo ago
This article smells AI generated, which is _very_ funny given the argument being made.
Either way, while this is true in the absolute, this is the value of building good MCP servers: they should expose only exactly the surface you expect your agent to need, and adding functionality should be carefully considered. The best MCP servers I use day to day (Cloudflare sticks out) do a really good job of exposing only what an agent might actually want to do on my behalf, rather than just all and sundry. Unfortunately the Chrome Dev tools MCP is less discriminating and is only as secure as a browser sandbox with full JS access (not fatal but not as strong as a well scoped REST API).
All of this is sidestepped somewhat by using good isolation primitives - I'm running a Hermes agent as of recently on a DigitalOcean VM that only accepts connections from my devices over tailscale, and it has all its own credentials so I can revoke them easily should they be used maliciously. Giving an agent root on a box is not _necessarily_ a huge deal, you just have to make sure that box has nothing valuable on it.
I kinda feel like we're rediscovering "Cattle, not Pets" when it comes to the environments we run our agents: give it root, sure, but a root that is almost meaningless outside of the functionality you granted it.
- walrus01 1mo agoI also think it's really funny that it sort of comes to the conclusion of "we're gonna make something not that different than a FreeBSD jail 25 years ago" as the best possible sandboxing solution.
- lowcache 1mo agoI didn't know that a smug sense of superiority was a pre-requisite....oh wait forgot this was the internet.
- walrus01 1mo agoI mean, it's not like, rocket science to basically boil down your page (which I don't fundamentally disagree with) to "we should put these things in a jail". As I already commented here I implement this for myself at the whole operating system level. There's lots of ways that have existed for a very long time to do things like freebsd jail or chroot or similar so it's not really a novel concept. Edit: I am completely in agreement with you that we need to remind people that running a lot of these harnesses/agents and LLMs gives them access to everything in your user profile. Some of works so well now, so rapidly and so painlessly that it's easy to forget about what could happen if it went wrong.
- bayindirh 1mo agoThere's no smug sense of superiority. While we are a Linux shop primarily, we always admired BSD jails until Linux had proper containers, and installed BSD systems where we needed strong borders or boxes. Also, we need to accept that some of the "new" problems we face are already solved well decades ago, and many people are rediscovering these solutions... ...after yelling to the very same people who were kindly pointing the right direction for being old-school, backwards and luddite minded.
- cyanydeez 1mo agoright, and I dont understand or haven't looked long enough, why there isnt a centralized agent harness that just uses existing protocols like ssh or docker container exec to do all it's work. Why does every agent have to be deployed directly into a VM or whatever. Why arn't we pushing them through the narrowly defined hole of a protocol?
- bayindirh 1mo agoThat'll take time. In the AI bubble, nobody has time. Latest SOTA model should have came out last week, and the latest harness 5 days ago. Nobody has time to optimize for anything. They can run as fast as they can and regularly catch fire on the fly. It's dangerous.
- cyanydeez 1mo agowell, I wouldn't say they dont have time. It's probably better to say: they're dogfooding the cheapest route to the quickfix the agent provides. I remember a year ago we asked "Where are all the great products AI should be delivering" and now the answer is: tons and tons of AI products to consume AI, in a snake eating it's tail. I've stopped chasing the dragon for the moment so I can push out real products.
- bayindirh 1mo agoThat's a perfectly valid probability as well. I'm deliberately late to the game. I don't use any of the agents, harnesses, code generation, and what I see is mostly slop. Currently, for my use case, AI is a tool for finding entrances to rabbit holes with solid references, so I can take it from there and continue digging myself. I believe instead of diving to the deep end head-first, one needs to regulate their usage of AI, so they can get what they can get and accomplish real work with these nuggets.
- cyanydeez 1mo agoI agree, I started local-only about february of this year. I ended up with opencode and deer-flow. Deer-flow does wonders in the research and development. Opencode will produce whatever pratfalls you want. I put out a raspberry-pi based control system replacing a expensive $$$$ PLC system with all the trimmings. Portions of it I haven't a clue how it works, but because it's not complex, I don't really care. Prior to this, I was essentially doing the same kind of console.log/print programming, and just visually/interactively verifying the stuff I did. But there were never docs and occasionally I tried out how TDD felt, and it felt funcitonally a non-starter. I'm not a csci student. As such, AI feels a lot more "at home" to my development than any other tools I've come across. Whenever I see an IDE that pops up method selection, etc, my entire brain breaks because like an LLM, i'm just streaming in and need to litterally see the code block or flow I'm working on. So i've hated most complex IDEs.
- deleted 1mo ago[deleted]