Right?
RIGHT??????
Are you sure that you need to grant the cloud full access to your desktop + all of its content to sort elements alphabetically?
Right?
RIGHT??????
Are you sure that you need to grant the cloud full access to your desktop + all of its content to sort elements alphabetically?
The reality is there are some of us who truly just don't care. The convenience outweighs the negative. Yesterday I told an agent, "here's my api key and my root password - do it for me". Privacy has long since been dead, but at least for myself opsec for personal work is too.
Unless of course they too turn to apathy and stop caring about being adversarial, but given the massive differences in quality of life between the west and the rest of the world, I'm not so sure about this.
That is of course a purely probabilistic thing and with that hard to grasp on an emotional level. It also might not happen during ones own lifetime, but that's where children would usually come in. Though, yeah, yeah, it's HN. I know I know.
Does the security team at your company know you're doing this?
Security as a whole is inconvenient. That doesn't mean we should ignore it.
[1] * dose
Hacker News in 2026.
Unfortunately I laughed reading this as there is never neither reputation nor legal consequences in the US of A. They can leak your entire life into my console including every account and every password you have and all PII of your entire family and literally nothing would happen… everything is stored somewhere and eventually will be used when “growth” is needed. some meaningless fines will be paid here and there but those bank statements will make their way to myriad of business that would drool to see them
(And yes, no one really says what that Something or Somehow may be, or how their underpants play into this.)
people should 1,000,000% be worried about AI company doing something kind of something with it which they are doing as we speak and if not now will be profiting soon-ish
[1]: https://www.ftc.gov/news-events/news/press-releases/2019/07/...
I mean we had these before in other very similar topics regarding e.g. Snowden leaks but really a lot of things. So.. uh..
The wording is just so on the nose I'm refusing to believe that this was written in good faith by a real person. Good engagement bait tho.
I conversely am confused by the amount of knee-jerk reaction to the word "privacy" people here have.
> I mean we had these before in other very similar topics regarding e.g. Snowden leaks but really a lot of things. So.. uh..
Yes, exactly. Now consider that the world kept on spinning anyway, and the revelations from the aforementioned leaks turned out to have exactly zero impact on the vast majority of people.
To be clear: I'm not questioning the ethical importance of all that privacy talk, just practical importance. It's bad that we don't have more control and protection of our data by default, but at the same time, excepting few people and organizations, the impact is so small in practice that it's not worth the energy spent being so militant about it.
That is fine. You can do that.
What is not fine however is discrediting the people that haven't given up as paranoid militant lunatics.
You can be nihilistic, disillusioned, <other adjectives> all you want, but it is not okay to pull other people down and attack them just because they still believe in something you do not appear to be doing (anymore?)
Apathy is okay. Sabotage is not
This is such an incredibly loser attitude and is why we can't have nice things.
I could spend an extra 5 minutes doing it "right" or I can get what I need done and have a 0.001% chance of there ever being a problem (since there are other security measure in place, like firewalls, api key rotation, etc.)
Even when security gaps are exploited, the fallout tends to be minimal. Companies that had their entire database of very sensitive information leaked are still growing users and at worst paid a tiny fine.
About 2.7 rolls per day for 100 years
Or end up bankrupt with criminal charges for CEO: https://yle.fi/a/74-20027665
The actual breach wasn’t that advanced hacking. They had copied their production data with all the patient information to test database which was publicly available and had default credentials.
I would challenge that, with the same challenge I've heard about how Microsoft and Google reading your email. The challenge is "ok, so can you please log me in to your mailbox and let me read through it?"
It's not that people don't care, it's most that they've been led, or convinced, or manipulated, into failing to notice and realize this state of affairs.
But they wish it would have been convenient to choose privacy.
For many, it may be rational to give away privacy for convenience. But many recognize the current decision space as suboptimal.
Remember smoke-infused restaurants? Opting out meant not going in at all. It was an experience that came home with you. And lingered. It took a tipping point to "flip" the default. [1]
[1]: The Public Demand for Smoking Bans https://econpapers.repec.org/article/kappubcho/v_3a88_3ay_3a... "Because smoking bans shift ownership of scarce resources, they are also hypothesized to transfer income from one party (smokers) to another party (nonsmokers)."
This is exactly what I expect out of…
Sorry, got interrupted by an email saying my bank was involved in a security incident.
But you're missing the point. It is doing all this stuff with user consent, yes. It's just that the user fundamentally cannot provide informed consent as they seem to be out of their minds.
So yeah, technically, all those compliance checkboxes are ticked. That's just entirely irrelevant to the point I am making.
The user is an adult. They are capable of consenting to whatever they want, no matter how irrational it may look to you.
What does that refute?
In any context, I really dislike software that prevents me from doing something dangerous in order to "protect" me. That's how we get iOS.
The user is an adult, they can consent to this if they want to. If Anthropic is using dark patterns to trick them that's a different story--that wouldn't be informed consent--but I don't think that's happening here?
Legally, yes. Yes, everyone can do that.
The question though is if that is a good thing. Do we just want to look away when large orgs benefit from people not realizing that they're doing self-harm? Do we want to ignore the larger societal implications of this?
If you want to delete your rootfs, be my guest. I just won't be cheering for a corp that tells you that you're brilliant and absolutely right for doing so.
I believe it's a bad thing to frame this as a conflict between individual freedom and protecting the weak(est) parts of society. I don't think that anything good can come out of seeing the world that way.
Fundamentally any security mechanism which relies on users to read and intelligently respond to approval prompts is doomed to fail over time, even if the prompts are well designed. Approval fatigue will kick in and people will just start either clicking through without reading, or prefer systems that let them disable the warnings (just as YOLO mode is a thing in Claude code)
v-- click!
[ACCEPT] [CANCEL]