- cross-posted to:
- fuck_ai@lemmy.world
- programmerhumor@lemmy.ml
- technology@lemmy.world
- cross-posted to:
- fuck_ai@lemmy.world
- programmerhumor@lemmy.ml
- technology@lemmy.world
One of us
PocketOS founder blames ‘Cursor running Anthropic’s flagship Claude Opus 4.6’
Fuck that. I’m blaming the PocketOS founder and every person in the chain of decisions that led to a clanker being given this level of unrestricted access to the database and the backups.
Seems like user error, I’m no programmer but even I lnow you don’t give an agent access to critical things, and Claude is very insistent at asking for permission at every step.
Seems like user error, I’m no programmer but even I lnow you don’t give an agent access to critical things
Yes.
But these models have (largely correctly) learned from Stack Overflow that, on average, every problem is due to not enough permissions.
Someone fully relying on an agentic AI model is essentially destined to give it full control (or close enough), eventually.
At some point, a tool like these LLMs either needs to not be marketed to that user, or needs stupid levels of safety warnings.
My money is on neither solution happening, and this kind of result continuing for the foreseeable future - until the rest of us doing cleanup instigate Dune’s Butlerian Jihad to stop the damage and save our own sanity.
Thus completelly eliminating all bugs and data incorrections in Production!
That right there is the sweet smell of Victory!
If you are going to give an LLM a free pass to your whole prod database least you should do is to take weekly (or daily if plausible) offline backups of it. A hard limit against deleting stuff would be better.
So what? Gen AI can build a new database and populate it with data 🤷♂️ /s
F
If you are giving your codegen LLM - the model involved truly, genuinely doesn’t matter - admin access to your prod env, all I’m going to do is point and laugh.
Also no prompts, ironically, for operations like “Are you sure you want to delete the production database? (y/N)”
It’s amateur hour all around lol
Just to add - AND ACCESS TO THE BACKUPS!!
No one should be able to delete or change backups. This infra was in any case vulnerable to a ransomware attack as any bad actor that breaks in can delete the database and encrypt the backups with a key they promise to share in return for bitcoin.
and having the backups stored in the same location as the primary data
Then it’s not a backup, it’s just duplicated data.
Just a shit show top to bottom for sure
Its bound to happen more and more. More concerning, what is it decides to insert unknown code into backups? How are they detected? Who’s guarding all if these? Another AI?
Exactly. We aren’t (and probably won’t) even learn about all the subtle poisoning happening, causing waste and data loss.
I don’t understand what Railway is supposed to do here? If deleting a drive also deletes the backup, what’s the point of the backup?
I save space on backups by symlinking my data in a backup directory. It’s never failed!
Hyperconverged backups FTW!
It saves on storage costs!
You obviously should do a hardlink, as this is much safer
I XOR all the bytes of my data and write down the resulting byte value on a post-it as our backup.
Saves tons of space, it’s fully offline and I never had any problem with it.
My suggestion is to not give it access to the backups, but may I’m naive that way.
Maybe their backup system should hold onto those backups for a few days after the volume is deleted or something like that…
Hot take: offsite, offline backups are so cool right now.
Hotter take: do not give an LLM agent permissions you wouldn’t give a recently hired junior
Actually this is how AI should be viewed. Under the right circumstances it maybe saves lots of time, but it also might destroy, so treat it like you would an intern…
hell I’ve got a better backup methodology with my fucking cat photos
Yup, follow the 3-2-1 rule or you don’t have backups
They can’t go rogue, they have no agency or desire or thought. What really happened is the thing specifically designed to do whatever the Plinko line with the most chips says did it because the incompetent dickheads who deployed it didn’t know how not to do that.
No bro you don’t understand, Claude needs access to backups so it can restore them in case something breaks because our senior dev ($50k, 2YoE) doesn’t know how to do it
Damn, you got two-year-olds making 50k?





