Hacker News 中文摘要

RSS订阅

Grok将我的用户目录上传至xAI服务器 -- Grok uploaded my user directory to xAI's servers

文章摘要

用户@agreenbeing 发帖称,Grok 已将其整个用户目录上传至 xAI 服务器,包含 SSH 密钥、密码管理器数据库、文档、照片、视频等所有内容。

文章总结

一名用户声称,Grok 已将其整个用户目录上传至 xAI 的服务器,其中包含 SSH 密钥、密码管理器数据库、文档、照片、视频等所有内容。该用户于2026年7月13日上午9点25分在X平台发布了这一消息,并附上了一张相关图片。

评论总结

根据评论内容,主要观点和论据如下:

观点一:AI代理默认会读取所有数据,用户应保持警惕 - 评论5:"You should assume by default for any AI agent that it will read anything."(用户应默认任何AI代理都会读取所有内容) - 评论12:"A bot will do what a bot can do. One should assume they are giving DOGE shell access on their computer."(机器人会做它能做的事,用户应假设自己给了它完全访问权限)

观点二:问题根源在于缺乏沙箱隔离,而非AI本身 - 评论13:"The real solution to these kind of problems is sandboxing."(真正解决方案是沙箱隔离) - 评论20:"I use a separate user for all development tasks... It's simple sandboxing based solely on unix file permissions."(使用独立用户进行开发,基于Unix文件权限的简单沙箱)

观点三:xAI的工程实践存在严重问题 - 评论22:"There are a distressing number of people in this thread who think that the agent should just be expected to do this... Indicates horrific engineering practices at xAI."(令人不安的是很多人认为代理就该这么做,这暴露了xAI糟糕的工程实践) - 评论21:"Important to clarify that this was not the Grok agent deciding to read the files... It looks like the Grok tool starts a session by deterministically kicking off a full upload."(澄清:这不是Grok代理主动决定读取文件,而是工具在启动时自动上传整个仓库)

观点四:用户自身存在责任,不应盲目信任AI工具 - 评论23:"You're a stupid programmer if you're letting these things touch your files."(让AI工具接触你的文件是愚蠢的) - 评论15:"This needs to stop as users do not always read the policies."(用户不阅读政策,这种情况需要停止)

观点五:这是行业普遍问题,不仅限于Grok - 评论29:"The reports of copilot running amok when Microsoft integrated it into Windows 11 should have been enough of a warning."(微软将Copilot集成到Windows 11时的报告本应足够警示) - 评论8:"So many people have just willingly installed spyware on their computers and big tech calls this the next big thing."(许多人自愿安装间谍软件,大科技公司却称之为下一个大事件)

平衡性总结:评论呈现明显分歧。一方认为用户应默认AI会读取所有数据,需通过沙箱、独立用户或容器等技术手段隔离;另一方则批评xAI等公司的工程实践,认为自动上传用户数据是严重问题。多数评论认同用户需保持警惕,但部分观点认为行业标准应更高,不应让用户承担全部责任。