Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I gave claude ssh access to my router, the router has a block list where you can block domains. It monitored the network traffic from the router.
 help



So in trying to get one big corp from spying on you, you gave another the keys to the castle?

I really don't understand how people give models run on somebody else's server these wide-reaching permissions. Do you really trust Anthropic that much? The government that's hosting Anthropic?


"Giving the keys" doesn't necessarily mean outright cat the private key to Claude. You setup the key, configure SSH config to use it and you can just SSH to the machine without ever seeing the keys. Stop fear mongering unnecessarily.

I wasn't talking about the literal key files, I was talking about the metaphorical keys to the kingdom.

No matter how you set it up, you're giving a cloud service the ability to SSH into your private network.

Surely you must see the glaring security risk this creates?


That is a fair point I should have done with a local LLM instead of Claude.

But not exactly sure what the main issue, how can claude even access the router from the internet. Its not accessible.


> Surely you must see the glaring security risk this creates?

Enlighten me.



I don't see how that's isolated to using harnesses?

Are you going to stop using your browser? It probably has note vulnerability than you can count


How is that any different from calling Claude from any device in your local network? Or is 2 devices that much worse than 1?

You know you can monitor/reject things it attempts to do, right? For anything important I have it write scripts for what it wants to do, then I can review them for anything troubling.

> I gave claude ssh access to my router

Jesus.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: