Elektrine lite

← Feed

@mpe@hcommons.social

Post #1376248

2026-04-19 08:00 UTC

Some thoughts on how Claude can still read your .env files even if it's told not to, which could compromise secrets. My colleague had this issue despite using specific instructions. I'm experimenting with 1Password environments to protect sensitive data. I think Claude's current mechanisms need strengthening for better security. https://eve.gd/2026/04/19/claude-code-can-consume-transmit-and-compromise-your-env-files-even-if-you-tell-it-not-to/

Replies (1)

  • @djl@mastodon.mit.edu 2026-04-19 11:18

    @mpe "even if it's told not to, " ... "despite using specific instructions" LLMs have no theory of, or mechanism for, relating text to "meaning". That is, "giving instructions to" an LLM is completely meaningless. They couldn't care, even if they wanted to. It's all random text all the way down, from start to finish. That the random text generation stuff often randomly happens to do the right thing is no guarantee of anything. It's the most unreliable technology in human history.

    Open ##1545724