Discussion about this post

User's avatar
Michael's avatar

good discussion of security issues around LLMs https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/

the cybersecurity way of thinking is its own highly paranoid thing. it's comparable to, but different from, "equilibrium thinking", it has to be taught and learned. unfortunately everyone who uses these tools will have to learn it at least a little bit.

one solution to many of the problems described here is just to run everything inside a sandboxed virtual machine (managed by Docker most likely). the technical tools to do this exist, but it's all kind of a pain in the ass to manage. making it easier and building it into the products will hopefully help.

John Haugaard's avatar

Great post and insights. Then, exhibiting weirdly uncanny timing, I watched this video posted 1/12/26. The potentially catastrophic rm -rf command unleashed in a livestream of first use of Claude Cowork. https://youtu.be/_6C9nMvQsGU?si=2u_sfy6pWinMKPbi

8 more comments...

No posts

Ready for more?