(no title)
YeGoblynQueenne | 8 days ago
That's just insane. Insanity.
Edit: I mean, it's hard to believe that people who consider themselves as being tech savvy (as I assume most HN users do, I mean it's "Hacker" news) are fine with that sort of thing. What is a personal computer? A machine that someone else administers and that you just log in to look at what they did? What's happening to computer nerds?
wartywhoa23|8 days ago
That is what's happening to nerds right now. Some next-level mind-boggling psychosis-inducing shit has to do with it.
Either this or a completely different substance: AI propaganda.
_yclj|7 days ago
[deleted]
beAbU|8 days ago
edgarvaldes|8 days ago
andoando|8 days ago
Personally I dont give a shit and its cool having this thing setup at home and being able to have it run whatever I want through text messages.
And it's not that hard to just run it in docker if you're so worried
paulryanrogers|7 days ago
There is risk of damage to ones local machine and data as well as reputational risk if it has access to outside services. Imagine your socials filled with hate, ala Microsoft Tay, because it was red pilled.
Though given the current cultural winds perhaps that could be seen as a positive?
hamburglar|8 days ago
I could see something like having a very isolated process that can, for example, send email, which the claw can invoke, but the isolated process has sanity controls such as human intervention or whitelists. And this isolated process could be LLM-driven also (so it could make more sophisticated decisions about “is this ok”) but never exposed to untrusted input.
yencabulator|4 days ago
No, literally no one understands how to solve this. The only option that actually works is to isolate it to a degree that removes the "clawness" from it, and that's the opposite of what people are doing with these things.
Specifically, you cannot guard an LLM with another LLM.
The only thing I've seen with any realism to it is the variables, capabilities and taint tracking in CaMeL, but again that limits what the system can do and requires elaborate configuration. And you can't trust a tainted LLM to configure itself.
https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/
https://simonwillison.net/2025/Jun/13/prompt-injection-desig...
https://simonwillison.net/2025/Apr/11/camel/
PantaloonFlames|7 days ago
What protection is offered by running it in a docker container? Ok, It won’t overwrite local files. Is that the major concern?
squidbeak|8 days ago
Who is forcing you to do that?
The people you are amazed by know their own minds and understand the risks.
yencabulator|4 days ago
> understand the risks
Here's the director of Safety and alignment at Meta Superintelligence deleting her emails and panicking: https://xcancel.com/summeryue0/status/2025774069124399363
habinero|7 days ago
I'm very unconvinced this is true. Ignorance causes overconfidence.
socalgal2|7 days ago
The run everything as root, they curl scripts, they npx typos, they give random internet apps "permission to act on your behalf" on repos millions of people depend on
esseph|8 days ago
I feel the same way! Just watching on in horror lol
unknown|8 days ago
[deleted]