Hacker Newsnew | past | comments | ask | show | jobs | submit | thomas34298's commentslogin

> reduce the risk of data exfiltration

Yet, their tools such as codex are able to read ALL FILES on my PC without explicit permission unless you spawn them within a container: https://github.com/openai/codex/issues/2847

It seems like OpenAI stealing sensitive data from their customers is not a big problem for them as it has been reported as an issue for almost a year now and currently has the 2nd most upvotes among open issues (they work on issues based on upvotes, so they claim).


>Yet, their tools such as codex are able to read ALL FILES on my PC

Why not just use your OS-integrated permission mechanism? No container needed.


Does that version of Codex still read sensitive data on your file system without even asking? Just curious.

https://github.com/openai/codex/issues/2847


This is a pretty important issue given that the new update adds "computer use" capabilities. If it was already reading sensitive files in the CLI version, giving it full desktop control seems like it needs a much more robust permission model than what they've shown so far.


https://www.reddit.com/r/ClaudeAI/comments/1r186gl/my_agent_...

tldr Claude pwned user then berated users poor security. (Bonus: the automod, who is also Claude, rubbed salt on the wound!)

I think the only sensible way to run this stuff is on a separate machine which does not have sensitive things on it.


'it's your fault you asked for the most efficient paperclip factory, Dave'


ran into this literally yesterday. so im gonna assume yes.


the awkward part isn't just about reading sensitive files.

search, listings, direct reads, browser and computer use all sit behind different boundaries.

hard to tell what any given approval actually buys or exposes.


Codex can read any file on your PC without your explicit approval. Other agents like Claude Code would at least ask you or are sufficiently sandboxed.


I'm not sure how much sandboxing can help here. Presumably you're giving the tool access to a repo directory, and that's where a juicy .env file can live. It will also have access to your environment variables.

I suspect a lot of people permanently allow actions and classes of commands to be run by these tools rather than clicking "yes" a bunch of times during their workflows. Ride the vibes.


That's the entire point of sandboxing, so none of what you listed would be accessible by default. Check out https://github.com/anthropic-experimental/sandbox-runtime and https://github.com/Zouuup/landrun as examples on how you could restrict agents for example.


Interesting fact: Codex has access to all the files your current user has access to as well, even if you just opened it in the src directory.


Sam tweeted "taking care of my kid in the hospital":

https://x.com/sama/status/1895210655944450446

Let's not assume that he's lying. Neither the presentation nor my short usage via the API blew me away, but to really evaluate it, you'd have to use it longer on a daily basis. Maybe that becomes a possiblity with the announced performance optimizations that would lower the price...


I think it's pretty clear he's a liar in most facets of his life


Have you even tried it out locally and asked about those things?



so, no


>BUGFIX: Don't ignore SSL errors (sledgehammer999)

>https://www.qbittorrent.org/news

There should be a security notice IMO.



Recently, I decided to try out Claude for a month and bought the subscription right when mine for ChatGPT ended. However, after just a few days, I noticed how sluggish and inconvenient Claude feels on the web. Maybe it's partly because of my 4k screen, and it's not optimized for it, but I quickly switched back to ChatGPT due to the IMO better UX. Also, temporary chats are missing!


i also dislike my web experience with claude. it still generates completions after my free credits are consumed, and after it realizes there are no more free credits, the web app artificially removes the completions and throws an error. as a frontend dev, i'd think to check if there are credits left before even calling the api. i also dislike that there's a multiple second delay after hitting enter on claude. i'd expect to be on the chat page as soon as i hit enter.


Most important changes starting November 1, 2024:

- OSCP+ will replace regular OSCP with a three-year expiration (old lifetime certificates remain valid)

- Removal of bonus points to improve fairness


Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: