I see a lot of people focused on servers and production environments, and of course that's needed, because that's business after all — but the personal computer seems to be absent from this discourse. Not everyone can buy a spare mac studio, and they might still need to install these tools on their personal computing devices, like their personal/home laptops. At that point, it's not even about whether a Claude Code, an OpenCode, or a Pi will steal/sniff personal data, but whether it can — though I think saying "it's a matter of 'when'" might be hyperbole. As of now, it's just: keep giving access and permissions or struggle while working, or create another user, or use Docker, run inside sandbox-exec, a VM, etc. As an end user, I am really scared. Someone who has been very disciplined and vehemently privacy- and security-conscious feels the ground below has just shifted.
OEM/OSes don't seem to have woken up to it yet. A mild proof is Apple's own special folder access reporting. When you go to Privacy & Security > Files & Folders, for a certain app, "Full Disk Access" is shown greyed out and mentioned in both cases — whether you had given Full Disk Access to that app or not. This directory-level permission UX is itself broken — there's Full Disk Access, and there's Files & Folders, and Full Disk Access gets shown in Files & Folders as well. This is, for lack of a better word, such an undesirable mess.
As of now I am debating between: creating a new user and just move everything work/learning to that user. Or just run all of it inside sandbox-exec (and maybe even block it from the shell if it tries to run outside it). Or use a tool that makes the latter easier and better. I even came across such a tool here on hn few weeks ago. agent-safehouse, yet to try it.
I understood by just looking at the title and after reading what is going on I am still concerned and not for some .name domains but I've .net and .com domains.
The main issue here is the way VeriSign and ICANN are operating. Unchecked, hostile, and without consequences (even the ombudsman okay the move). Someone might come along and say but you can always fight in the court - and that's the problem! Some company or entity claims one of those .net/.com domains I "use" and just gets us suspended and handed over, as someone not living in the USA I will literally be out of any option. This "then go to the court" is a very dangerous setting. We all know this but this squarely rigged to be in favour of the offenders with means and power.
Is there a case in which a heavy agentic coding user of mid or mid++ tier (remotely hosted) models is better off using PAYG/API pricing than just getting a subscription? (Assuming no easy access to high end local hardware and I've deliberately left the top tier/cutting edge models out becau).
I have also noticed a general drop in fawning over and deification of 'made a billion, must be a visionary' figures, and a receding tolerance for every sundry kind of hot take and proclamation. Mustn't be related.
> A representative from that airline was asking internally if they could put me on the no-fly list.
These are the kinds of scary scenarios that people should fight and push back on opaque, unaccountable laws that other people and organisations in power try to enact in the name of safety and security, and we need to collectively fight back when someone is charged, or worse "taken away", without due process and visibility.
This is basically what my take has been after chasing everything else for way too long. Though I've not moved back and Gmail honestly isn't something I can now move back to (and no tracking/etc are not the reason). I just wrote a too long comment and I realise now most of that you've said in your short comment.
Email for me is just a communication tool that the world still uses. Nothing else.
Having started down this path of non-big-corp hosted email and my own personal domain (which is definitely not self-hosting, though I'd never want that inflicted upon me) almost a decade ago, I won't say it's been a rabbit hole. But there have been some learnings over the years — realisations, rather. The biggest: I went overboard with everything around moving my email away from Gmail. Almost like what I did with seedboxes over the years, until I realised I didn't need most of what a seedbox offers, and that I didn't need a seedbox in the first place.
Whenever this discussion comes up here, or say on Reddit, the focus immediately moves to privacy, anonymity, tracking. Those are valid points, no doubt. What takes a back seat, I suspect, are aspects like reliability and some sort of accountable customer support — and no, a smaller company doesn't need an army of support agents, just a few people and an intention to help and solve problems, delays being okay. Many utterly irresponsible hosted email providers get a pass just because they posture with an activist flag. The whole virtue signalling in this sub-industry muddles things.
Some are worse. Some deny you basic email access in the name of things like e2ee. Now e2ee is a fine idea, but enforcing it unilaterally — and yet not really enforcing it, because let's face it, you can't until you "move" your ecosystem, the way Signal has been "moving" it. Locked to the app, locked to the web app, yet your emails flow to other systems and addresses that aren't e2ee (as they should!). You just can't use IMAP, among other things. This has become such a toxic topic on certain forums that I start wondering if maybe I'm the one holding it wrong.
Another observation: bundling things that aren't email. This is another contentious topic. I wish there were more mainstream, custom-domain-hosted email providers that just did email, nothing else. I first started using disposable email designed to route to my domain via my mail host (a German one). It was as convoluted as it gets, and still is. Then came Apple's HME, with limitations I wouldn't wish on an enemy. Finally settled on SimpleLogin. Not the best, but what I like is that it gets out of the way — I can receive emails on those addresses and send from them easily. It's also a separate service, not hooked to my mail host, and I wouldn't want that now.
What would I do if I had to go back to when I was starting?
1. I wouldn't look for a "private" email provider — just get my own domain (which I did) and sign up with a better-priced, responsible, email-only provider (preferably something larger).
2. Never use the free email that comes with the mail host account.
3. Let go of privacy and tracking on email. It's almost painful to say, but I'm tired of that part.
And if Gmail hadn't done idiotic things like forcing "folders" on my account with no way to change or delete them (Important, and whatnot), I might have just stayed with them. At least my emails would have been delivered — unlike with my current host, which doesn't do "emailing" up to standard. For heaven's sake, just let my email through, and let senders get through to me as long as their ID is verified and they're not on any spam list.
Hell, I am thinking of moving a domain of mine to Zoho. A company I'd have never imagined thinking of in the same breath and it has not become "better" somehow. But here we go, a decade later. This is just a rant I guess. But I am really exhausted and yes switch mail providers even with your own domain is daunting! The apprehension of downtime, fear of losing emails, something breaking etc are just too much. But at least there's a possibility.
tl;dr: If I do it over and Gmail stayed what it was back then, I'd just go back to them, just with "my own domain." Not that Google got better; just shows how disillusioned I am with the personal-domain-hosting hype.
My own domain, nothing else. Not the rest of what I've done chasing for "this kind of" mail hosting.
This scares me! Denial of service (in some cases you may not even have an alternative), in some cases custody, et cetera and that too based on a false positive or a flimsy match. And no one doubles checks it, no one bothers to make sure, and they are allowed to do that! All this is actual legal and no one pays for it once it's found out, and even if you have suffered. None.
And heaven's forbid if your actual ID and references (i.e you) have ended up in such places (or such list/s) by mistake or malice.
Very soon, everything easily accessible on the Internet will be a never-ending loop of AI slop. Will this push us back to analogue things? Not in an apocalyptic scenario, but in general, and by analogue, I don't mean no use of computers but use of computing with a firm and predictable human touch and control.
Will there be venues left (largely) unencumbered by AI to even turn analogue? The top-down control of our industries, financial systems, education, etc by a few mega corporations and fewer mega rich people, who also have vested interests in the advent of AI as AI corps are trying to be, means there's nothing left where AI is not inserted in every vein and nerve and nerve centre.
It is as if a few people in the world are trying to turn this world into something Frankensteinian because they think that then they will get the chance to be the only ones to control this Frankensteinian. They might as well succeed. To what end? I do not believe even they know that. Blindness of greed.
tl;dr: if I run claude/harness inside "code" at "~/<some path>/work/code", it would be great if the harness can't even see "code" is inside "work" (and even I can't make it know that by some quick "Yes(y)")
I want something like: claude/opencode/pi/etc has no existence or capacity outside a file access boundary, say a given folder that (e.g.) lies here "~/<some path>/code". Even if I want, I can't run claude outside it, because it isn't installed outside it. Even if Claude wants it can't read/write/execute/install anything outside it.
Basically I want the harness(es) and my code folder(s) sandboxed [0] inside just one folder and below it in folder hierarchy at least for file access limitations.
Will this pose the challenge of using the system wide cli tools like ls, cd, git et cetera? If it gets a handle on those tools outside that sandboxed folder then pretty much can it execute it in any other folder? So should those tools also be part of that container?
I guess something like docker does that, but do I necessarily need a docker like app/tool? It will use a lot of system resources on its own. A different mac login won't be great either.
I do not want to use claude's /sandbox (or something like this), that will defeat the purpose. Because it's not about "it won't", but because "it can't".
https://github.com/apple/containerization doesn't sound like what I am looking for. So is docker, lima etc are my only options? Not to mention I will lose access to a lot of cli tools I use on mac.
I use bubblewrap, which I believe claude code also has internally but not for its `Bash()` tool.
I wrap bubblewrap in a script that supports config files to allow different "profiles" of use (analogous to eg firefox profiles). The bwrap starts with the whole filesystem mounted read-only, then mounts the current directory read-write and then applies further bind mounts for devices, special case other read-write (eg, ~/.cache/) and to mount empties to cover sensitive directories (eg, ~/.ssh/). The profile also specifies the default command to run and for claude, it gets yolo mode.
On a Mac, you can do this via OS-native Seatbelt sandboxing - you define a static text file and it locks down the process so it can't read/write anything it's not supposed to. The syntax is a bit archaic, so I built a Bash wrapper around it to dynamically detect which agent you use and from what dir, and then generate the policy to lock down its process - https://github.com/eugene1g/agent-safehouse
Hey, thank you. Looks like a tool easy enough to use and start with the agentic world in a sandboxed and much safer manner.
Just clarifying a bit (haven't gone through details yet):
1. So, a harness gets installed within the bounds of this script via agent-safehouse? (I doubt this is the case)
2. Or they are installed as a normal app, but when I run them in the terminal within the bounds of "safehouse <harness>" (saw this) they are bound by the rules I set, right?
I feel it's the latter and I think it's good enough for the time being.
.....
Mac offers some controls at least for personal files and "Full Disk Access" etc. But it's so badly implemented and poorly shown that it's confusing.
Like I can see in "Privacy & Security > Full Disk Access" OpenCode is listed and and "Full Disk Access" toggled off. (I anyway remove OpenCode from here completely by the "-" button after selecting it, just to make sure).
Then I go back a step and in "Privacy & Security > Files & Folders > OpenCode" has "Full Disk Access" is listed there. Strange!
“safehouse <harness>” hides and protects your filesystem from the agent CLI - it cannot read/write/delete anything outside of the current folder, no matter what Bash/code it tries (short of finding some 0-day within MacOS sandboxing). We added exceptions for dev tooling (so eg NPM works), but generally keep same defaults (eg no Docker access by default as having that socket bypasses all protection)
OEM/OSes don't seem to have woken up to it yet. A mild proof is Apple's own special folder access reporting. When you go to Privacy & Security > Files & Folders, for a certain app, "Full Disk Access" is shown greyed out and mentioned in both cases — whether you had given Full Disk Access to that app or not. This directory-level permission UX is itself broken — there's Full Disk Access, and there's Files & Folders, and Full Disk Access gets shown in Files & Folders as well. This is, for lack of a better word, such an undesirable mess.
As of now I am debating between: creating a new user and just move everything work/learning to that user. Or just run all of it inside sandbox-exec (and maybe even block it from the shell if it tries to run outside it). Or use a tool that makes the latter easier and better. I even came across such a tool here on hn few weeks ago. agent-safehouse, yet to try it.
reply