HNHacker News
TopNewBestAskShowJobs

maharshi365

113 karma · joined March 15, 2017

submissionscomments
maharshi365··on MCP was always a bad idea?
i think standards are good for low level things. APIs change, model behvaiors change, we basically are allowing an external service provider to control our agent prompts.
maharshi365··on MCP was always a bad idea?
1. Control can be done via CLIs --> api key based access controls. We have been doing it forever. 2. I think this really only applies to Oauth based MCPs. Many server support api key based auth, stored as files --> security is still flawed imo. 3. This can be done via apis/clis too --> not something unique to MCP iimo 4. Same thing, not unique to MCP --> api servers can also be logged

MCP doesn't inherently make this easier. its still requires engineering maintaincence.

maharshi365··on MCP was always a bad idea?
Were in a world where agents are more autonomous. Need stuff to be easier for agents and not humans
maharshi365··on Why MCP Was Always a Bad Idea
Yeah I think a better header is good. The idea isnt bad in concept.
maharshi365··on Why MCP Was Always a Bad Idea
In my experience they are very good at figuring out the apis. Well designed clis matter here but I've been able to give llms clis and its been pretty good.
maharshi365··on MCP was always a bad idea?
I've been thinking about this. Technically mcp auth is also not secure, the keys are in env or in file and accessible to the agent.

I think something like infiscial ai proxy could be useful here. Never store the creds on device.