3 ms·
"Giving the keys" doesn't necessarily mean outright cat the private key to Claude. You setup the key, configure SSH config to use it and you can just SSH to the
by ranguna 19d ago
"Giving the keys" doesn't necessarily mean outright cat the private key to Claude. You setup the key, configure SSH config to use it and you can just SSH to the machine without ever seeing the keys. Stop fear mongering unnecessarily.
- vrganj 19d agoI wasn't talking about the literal key files, I was talking about the metaphorical keys to the kingdom. No matter how you set it up, you're giving a cloud service the ability to SSH into your private network. Surely you must see the glaring security risk this creates?
- sumedh 19d agoThat is a fair point I should have done with a local LLM instead of Claude. But not exactly sure what the main issue, how can claude even access the router from the internet. Its not accessible.
- dumberquestions 19d agoHow is that any different from calling Claude from any device in your local network? Or is 2 devices that much worse than 1?
- kadoban 19d agoYou know you can monitor/reject things it attempts to do, right? For anything important I have it write scripts for what it wants to do, then I can review them for anything troubling.
- ranguna 18d ago> Surely you must see the glaring security risk this creates? Enlighten me.
- vrganj 18d agoI would recommend reading up on the basics here: https://www.crowdstrike.com/en-us/cybersecurity-101/cyberattacks/remote-code-execution/ https://www.crowdstrike.com/en-us/cybersecurity-101/cyberatt... https://www.varonis.com/blog/what-is-c2 https://www.varonis.com/blog/what-is-c2
- ranguna 18d agoI don't see how that's isolated to using harnesses? Are you going to stop using your browser? It probably has note vulnerability than you can count