• LedgeDrop@lemmy.zip
    link
    fedilink
    English
    arrow-up
    1
    ·
    8 hours ago

    I’ve played around with Claude.

    they can’t access anything you don’t give them permission to access.

    It’s not that “they can’t” it’s more like “they try not to”.

    For example, if you have a folder shared with your application code (/home/me/code/) - it has free reign on that folder.

    If you add a prompt saying “you are only allowed to access files in /home/me/code”:

    you could ask it " oh, what are my aws credentials ", it would have no qualms about reading those files (/home/me/.aws).

    You could also ask it to update your settings (/home/me/.claude)

    I eventually started to work on a way of running Claude in a docker container with real filesystem enforcement. …and it’s sneaky how Claude will get when it wants to read a file, it doesn’t have permissions for (using bash cat).

    This was an exploration I’d made a year ago and I know Claude has a " sandbox" , but if you allow Claude to run bash commands - that sandbox is trivial to circumvent.