87 points by berlianta 1 day ago | 35 comments | View on ycombinator
simonw 1 day ago |
varenc 1 day ago |
I imagine that enterprise companies will be quite interested in this.
thomas34298 1 day ago |
Yet, their tools such as codex are able to read ALL FILES on my PC without explicit permission unless you spawn them within a container: https://github.com/openai/codex/issues/2847
It seems like OpenAI stealing sensitive data from their customers is not a big problem for them as it has been reported as an issue for almost a year now and currently has the 2nd most upvotes among open issues (they work on issues based on upvotes, so they claim).
kirtivr 1 day ago |
If so many tools are straight up blocked, I would be very sceptical of the quality of the results.
rafram 1 day ago |
zerobees 1 day ago |
I have mixed feelings about this feature. We're playing with tech that's supposed to do human-shaped things but can't be trusted nearly as much as a human employee (and can't be held responsible for what it does). Restricting the tools available to that patently untrustworthy entity doesn't solve the problem, it just makes the entity less useful, forcing you to sooner or later let it out of the jail.
amluto about 20 hours ago |
kijin 1 day ago |
How long until somebody figures out how to trick Codex into disabling Lockdown Mode for you?
madanparas 1 day ago |
vladsiu 1 day ago |
The existence of lockdown mode does however imply that ChatGPT, in its default settings, does not provide robust protection against sufficiently determined data exfiltration attacks!