Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think the whole world is sleeping on the privacy/security implications of this technology. Recent OpenAI/HuggingFace incident shows us that even in a very controlled top AI-lab setting, humans can't know what agents are really doing. In our consumer environments at home or work we don't even have access to reasoning logs or background agents/tools. What they do gets more opaque and convoluted every day. When I grant access to gmail, it basically has access to every single mail in my account. When it has computer use or terminal use it can basically do anything on my computer. It's like keeping your home/office doors unlocked. You may think you live in a very safe neighborhood. Until someone needs to take something from inside (or worse, plant something).


Yes. Don’t get me wrong: I use and enjoy these LLMs. But even now, well into 2026, I’m still using them via the now “old-fashioned” chat box in a web browser. Based on all that we’ve learned about this technology, there’s just no way I’m giving it control over any part of my machine. Is it a helpful search engine? Does it save me typing and write some nice code snippets when I need it to? Absolutely it does, and I greatly appreciate the technology. But I’m just not ready to create agents and let them run. I just think that’s still way too risky, and I fear a major, major catastrophe is coming because of how so many people recklessly trust these agents. I certainly hope I’m wrong.


last week i finally bit the bullet and did the vm thing and my harness exclusively lives in there now, no more env files for local dev keychain access only which is requiring a lot of input from me but oh well. i'm 100% web browser chat on my host system. i cannot afford to have my world compromised and i stalled on setting that up for way too long. all of these major services are inevitably going to get compromised they're just adding too many surfaces constantly it's insane. i also ejected node/npm the fuck out of my world after the recent shai halud. In this "AI is assisting in finding vulnerabilities" era i'm just like done with the exposure. keeping vendored copies of any libs i need and mostly just use go now and making stuff that is effectively distroless for deployment and my build chain is pretty much just compiling my go, and even with go im carefully looking at packages theres so many packages appearing out of thin air now all vibe coded no reputation.


Me too, it is a crystal clear boundary between me and the LLM. They might have access to my most precious code, but at least they don't have access to my browsing history.


You don't have to go to the HuggingFace incident! Go back in time to the New York Times legal brawl where NYT lawyers started being able to scoop up all their logs not covered by a ZDR. That's what keeps me from giving OpenAI access to anything too personal. My employer offers to let us use our corporate seats for personal stuff so we can be covered by our corporate ZDR, but AFAIK that enables HR to see all my chats which is just as bad or worse. (Someone in HR in ChatGPT Work: "Create a scheduled task where every morning at 8AM you navigate to the compliance tab in the corporate ChatGPT dashboard and search for anyone asking questions about job opportunities outside the company, or [list of 100 other prohibited things], and alert me with any positive results.")

Looking forward to seeing what Apple cooks up with their Private Cloud Compute and if anyone else takes up the same approach.


You can have OpenRouter filter for ZDR providers. There are nuances like contractual ZDR vs technical ZDR but definitely worth investigating


exactly, and contractual can mean anything

the providers are actually still training on data, using a concept called Generate Data Refinement that thye've publisehd: https://trustedrouter.com/blog/they-are-still-training-on-yo...


The parent gives the model access to passport and presumably other sensitive info. That's enough for a new Black Mirror episode.


> Recent OpenAI/HuggingFace incident shows us that even in a very controlled top AI-lab setting, humans can't know what agents are really doing.

“very controlled” is disinformation.


Yep. As is "can't know".




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: