@nandanpri yeah, that's the other hole. TCC only gates Desktop / Documents / Downloads. a .env anywhere else is just another path the user account can read.
CLAUDE.md is a useful reminder to the model. I wouldn't treat it as the lock — deny rules are what actually stop the read.
Claude code told me, in an earlier session, that it couldn't reach outside the repo - not Desktop, not Documents, not Downloads. Today, when I asked it to compare a file sitting in my Documents, it just went and read it (w/ auto-approve).
Turns out the fix is quite simple, and claude itself suggested it - macOS TCC. System Settings -> Privacy and Security -> Files and Folders -> Turn off Desktop, Documents, and Downloads for your terminal and your IDE. Two minutes, and the agents can't touch those folders even if they try (also check Full Disk Access, which overrides Files & Folders).
Many of us run these agents on a personal laptop, not in containers or cloud dev boxes. With auto-approve on, it can reach anything your user account can. I'm a security freak for things like bank statements and tax files, and want access to them not left to an inference decision. The July incident where an OpenAI eval agent escaped its sandbox and broke into Hugging Face was a different failure, but similar blind spot: trusting the wall. There, agent jumped a real wall. On laptops the working directory restriction is just a convention (claude code's words), and auto-approve means nobody's watching.
FWIW I too hated those persistent permission prompts that after a while you just start approving blindly - but I feel guardrails like TCC should be more widely known.
@trq212 not a complaint - auto mode is why I stopped rubber-stamping prompts. Posting this because the macOS Files and Folders gate isn’t obvious, and it seems like the kind of thing worth saying out loud next to auto mode. knowing Desktop / Documents / Downloads are actually out of reach would help a lot of people sleep better with auto mode on.
@bokuwalily Yeah. That's the part that got me too. One session it swears the repo is the box, next session it just reads Documents. I stopped treating the model's answer as the policy.
Ugly reminder that the folder you launched in is not a sandbox.
Different incident on my side, same shape. Found that claude can read files in ~/Documents with auto-approve on - without any permission prompt. That’s where a lot of people’s stuff like taxes/finances lives. I was still under the impression boundary is the project directory (which it explicitly told me earlier).
If you’re still on a personal mac TCC can help. Privacy & Security → Files and Folders -> turn off Desktop/ Documents/Downloads for Terminal and the IDE. Won’t save you from rm -rf inside the project, but it keeps impact to projects, which could be recovered with git.
useful that auto mode rules are now visible in /permissions.
One thing those rules don’t cover: Desktop/Documents/Downloads on a personal mac. I thought the launch folder was the boundary. Asked claude to compare a file in Documents and it just read it - no prompt.
macOS already has a gate for this - TCC. Privacy & Security → Files and Folders, turn off for Terminal and the IDE. feels like it belongs next to the auto mode docs.
sudo + auto mode is the spicy version. Even just auto mode on your own laptop can quietly surprise you.
I thought the folder I launched in was the boundary. Asked claude to compare a file in Documents and, well, it just read it. No permission prompt. Auto access to all docs like taxes can surprise you.
Thankfully there's TCC on mac. In Privacy & Security -> Files and Folders, turn off Desktop / Documents / Downloads for Terminal and the IDE.
very cool - esp procedural over wav files. I've been riffing w/ Fable on what I'd do when I get mine (getting ahead of myself :D).
I was thinking on the lines of voice commands in. Simplest ones like "follow me", "let's dance buddy" or whatever tricks the community builds will be such an enabler. Plus, some follow-ups like "no, on your right" when it's deciding could help.
For complex convo, a full blown openclaw agent - small local STT model, then an LLM w/ camera frames + convo memory - turning "hey buddy, I graduated, let's celebrate" into duck commands, somersault included (or whatever tricks you've trained). But ofc wake-word needs to be on device (household audio leaving device is a non-starter), plus the simplest phrases could live there too - fixed-phrase models are tiny, and your same-code-to-ARM point makes me think the budget's there - so the everyday "follow me" stays instant even w/ wifi down. Thoughts, @onusoz ? @victormustar - something like that on the plans?
Super cool - ordering one :) Been dragging my feet on teaching daughter coding, given how the value of "turn an intent to code" has & will change in this "Decade of Agents". But learning to shape a model’s behavior through rewards & feedback, and then watching that behavior show up in a little robot - well, that feels like native to this era. Maybe this is the next-gen version of learning to code by building games. @Thom_Wolf
Well, Apple's always been slow and often not "first", but still ends up on top - some mix of quality, polish, and existing customer trust, I guess. But kinda agreed, maybe not this time. Agents feel like a far bigger disruption than the ones they've ridden out before. Maybe the whole apps and app/play stores itself up for disruption. And there are some things brewing w/ OpenAI & Jony Ive, and @elonmusk/@SpaceXAI occasionally saying don't wanna build a phone, more like an edge node for agents.
But imo the interesting bit is going to be the money, not the tech. Agents doing things for you across providers kills the search box and the app grid - literally the two cash cows, google's ads and apple's 30% cut. Sure there's money in the new world too, on agents and APIs instead of apps/ads, but that's rebuilding the business model from scratch. It's more a nerve question - who's willing to bet against a cash cow that took 20 years to build and basically runs the company? Apple will follow, as always. Will be interesting to see who's bold enough to start.
Vamos, @RafaelNadal!
As you get ready to graduate from tennis, I’ve got a few things to share before I maybe get emotional.
Let’s start with the obvious: you beat me—a lot. More than I managed to beat you. You challenged me in ways no one else could. On clay, it felt like I was stepping into your backyard, and you made me work harder than I ever thought I could just to hold my ground. You made me reimagine my game—even going so far as to change the size of my racquet head, hoping for any edge.
I’m not a very superstitious person, but you took it to the next level. Your whole process. All those rituals. Assembling your water bottles like toy soldiers in formation, fixing your hair, adjusting your underwear... All of it with the highest intensity. Secretly, I kind of loved the whole thing. Because it was so unique—it was so you.
And you know what, Rafa, you made me enjoy the game even more.
OK, maybe not at first. After the 2004 Australian Open, I achieved the #1 ranking for the first time. I thought I was on top of the world. And I was—until two months later, when you walked on the court in Miami in your red sleeveless shirt, showing off those biceps, and you beat me convincingly. All that buzz I’d been hearing about you—about this amazing young player from Mallorca, a generational talent, probably going to win a major someday—it wasn’t just hype.
We were both at the start of our journey and it’s one we ended up taking together. Twenty years later, Rafa, I have to say: What an incredible run you’ve had. Including 14 French Opens—historic! You made Spain proud... you made the whole tennis world proud.
I keep thinking about the memories we’ve shared. Promoting the sport together. Playing that match on half-grass, half-clay. Breaking the all-time attendance record by playing in front of more than 50,000 fans in Cape Town, South Africa. Always cracking each other up. Wearing each other out on the court and then, sometimes, almost literally having to hold each other up during trophy ceremonies.
I’m still grateful you invited me to Mallorca to help launch the Rafa Nadal Academy in 2016. Actually, I kind of invited myself. I knew you were too polite to insist on me being there, but I didn’t want to miss it. You have always been a role model for kids around the world, and Mirka and I are so glad that our children have all trained at your academies. They had a blast and learned so much—like thousands of other young players. Although I always worried my kids would come home playing tennis as lefties.
And then there was London—the Laver Cup in 2022. My final match. It meant everything to me that you were there by my side—not as my rival but as my doubles partner. Sharing the court with you that night, and sharing those tears, will forever be one of the most special moments of my career.
Rafa, I know you’re focused on the last stretch of your epic career. We will talk when it’s done. For now, I just want to congratulate your family and team, who all played a massive role in your success. And I want you to know that your old friend is always cheering for you, and will be cheering just as loud for everything you do next.
Rafa that!
Best always, your fan,
Roger
It has only been 4 days since the Trump landslide and RFK Jr is already on the job to Make America Healthy Again!
Here RFK Jr now lays out the specifics for their “MAHA” plan.
God bless Donald Trump & RFK Jr.
Speculative execution for LLMs is an excellent inference-time optimization.
It hinges on the following unintuitive observation: forwarding an LLM on a single input token takes about as much time as forwarding an LLM on K input tokens in a batch (for larger K than you might think). This unintuitive fact is because sampling is heavily memory bound: most of the "work" is not doing compute, it is reading in the weights of the transformer from VRAM into on-chip cache for processing. So if you're going to do all that work of reading in all those weights, you might as well apply them to a whole batch of input vectors. I went into more detail in an earlier thread:
https://t.co/Lbtpq4VDeY
The reason we can't naively use this fact to sample in chunks of K tokens at a time is that every N-th token depends on what token we sample at time at step N-1. There is a serial dependency, so the baseline implementation just goes one by one left to right.
Now the clever idea is to use a small and cheap draft model to first generate a candidate sequence of K tokens - a "draft". Then we feed all of these together through the big model in a batch. This is almost as fast as feeding in just one token, per the above. Then we go from left to right over the logits predicted by the model and sample tokens. Any sample that agrees with the draft allows us to immediately skip forward to the next token. If there is a disagreement then we throw the draft away and eat the cost of doing some throwaway work (sampling the draft and the forward passing for all the later tokens).
The reason this works in practice is that most of the time the draft tokens get accepted, because they are easy, so even a much smaller draft model gets them. As these easy tokens get accepted, we skip through those parts in leaps. The hard tokens where the big model disagrees "fall back" to original speed, but actually a bit slower because of all the extra work.
So TLDR: this one weird trick works because LLMs are memory bound at inference time, in the "batch size 1" setting of sampling a single sequence of interest, that a large fraction of "local LLM" use cases fall into. And because most tokens are "easy".
References
https://t.co/sIBCSmsyKN
https://t.co/uSpmTzfWhR
https://t.co/7t7orHBybo