And that's not a joke, I made the mistake of installing this on my Windows machine just to test it out quickly last week.
It created 2 new users and then assigned new NTFS permissions for every single file under my user directory to them. This of course wrecked havoc, ssh refused to work, several applications refusing to start and a ton of permission errors. It did this without even a warning in the background and it also does not undo any of it when you uninstall it.
It took around 3 hours to fix it by updating ~10 million NTFS permissions for every single file under my user directory.
I would love to see your prompt(s) and how you managed to make it do this.
I’ve been using Codex in full access mode constantly for the past couple months on a Pro plan and I haven’t had a single incident like this. I’ve used it across macOS, Linux, and Windows as well, so my usage isn’t limited to a specific setup either.
I never sent any prompts to it, it did all of this during the installation. Here is one related GitHub issue I found for it https://github.com/openai/codex/issues/12343 Looks like they don't intend to change this.
Your earlier post is misleading, since "it" sounds like the model, not the installer. (of course if the latter was created by the former, its basically the same complaint, but I suspect what you are talking about was a deliberate design decision by a human)
The problem doesn't exist when granting codex full access. Codex makes you choose upon first launch to "Set up default sandbox" or to "Use non-admin sandbox". The default option creates two new users and messes with NTFS permissions.
> I’ve been using Codex in full access mode constantly for the past couple months on a Pro plan and I haven’t had a single incident like this. I’ve used it across macOS,
That is not how it works: the "but it works for me" is a logical fallacy.
Haven't you followed a bit all the posts about models, for example, escaping their environments?
The "but it works for me" is a random data point: an anecdote.
That there are people / companies where models ran wild and destroyed files / messed up projects is a fact.
When there are documented cases of stuff gone wrong, people must find ways to protect their data.
We literally see posts frontpage, daily, about AI sandboxing and we regularly see posts about AI escapes or AI SNAFUs.
And you come and post "show me your prompt, for it works on my machine"...
If you’re doing that anyway you might as well install a hypervisor and layer your OS on top. That way you can snapshot before your LLM with root fucks everything up again.
I've been using GPT through opencode for quite some time on linux. I have had a great time with getting it to help me through computer use and it has been a game changer for me.
For instance recently, media downloads on my NAS became quite a bit slower. I asked it to investigate and it quickly got back to me saying the issue was the ethernet link had been downgraded to 100Mbps from 1Gbps. It even went through journalctl to tell me when this had happened. To fix it I just had to plug an ethernet cable out and back in. Now this is the kind of thing, earlier I would have to spend an evening on. But given an open system like Linux, a well made safe model just makes it so much more accessible than having to RTFM for one off things I am sure to forget in a month.
I dont really let it run loose through my systems, and keep an eye on the thinking traces it puts out and the permissions it asks for. But now I dont have to slog through manuals and deal with gruff people on the internet. I can choose to do so after the fact, depending on how much free time and curiosity I have.
With exception of VSCode, because I have no choice due to some plugins, or apps required by customer projects where I have no other option as well, nothing else based on Electron pollutes my computers.
If I have to deliver in technology X, customer isn't going to be happy getting Y instead, and I am not making my life miserable to work with editors lacking the specific tools, or that are forbidden by customer IT to be installed on provided equipment.
If your hypothetical client as security measure ONLY permits VSCode on a dedicated box you’re obligated to work on and have no control over - then I pray for you.
And for your hypothetical client.
Especially as judging by your description they despite this allow any VSCode plugin to be installed alongside it.
> and I am not making my life miserable to work with editors lacking the specific tools
And that’s the self-imposed prison I was talking about, there’s always alternative tools. In my mind a specific tool is something like Ghidra.
I see you never worked in enterprise consulting with either laptops or cloud VMs managed by customer IT, and where elevated actions require either IT tickets, or elevation tools with description fields why the operation is required, with development done with specific team accounts.
Sectors involved in, in no particular order: government, financial, telecom, energy (gas and electric), manufacturing (large european conglomerates), healthcare, logistics
In fact I was the one usually helping IT Teams put the torture devices and policies you’re subjected to in place lol.
Banks would usually give us laptops with smart card readers and only allowed access to their VPN from a limited set of public IP addresses.
Govt was a bit more lax, but same principles applied, was really fun doing any kind of work over a laggy VNC.
My favourite one was probably where you’d have to hop from one Azure cloud VM, to Citrix to a bastion windows box, off of which you’d RDP to the actual work VM only to putty to the actual damn Linux box you cared about.
Energy sector was more lax, they let us set up a GitLab instance and a small
CICD setup to which we’d push the code developed on our local boxes.
Oh and the ones I mentioned - they usually ask us what tools we wanted on our boxes as well.
Many official, high-quality language support plugins are only available for VSCode. For some languages, you have a “choice” to use another IDE in the same sense that you have a choice to do programming with a hex editor. Lean being an example, where every alternative is in its infancy.
"The American private sector is the most innovative and
technologically advanced in the world, and its scale,
speed, and capacity secure a critical offensive cyber
advantage for the United States."
Since we now have three "Codex"es, I think it's worth specifying you're talking about codex-cli/tui. Codex the hosted version and Codex the GUI are both fully proprietary I think (besides the codex-cli/tui parts they use, I'm guessing mainly the app-server stuff).
> > Or we are just assuming that was a PR stunt, which it almost certainly was.
> It wasn't.
Prove it. But you can’t, which is problematic for you.
Nobody should believe anything OpenAI says about anything. They either lied about it breaking out of a sand box, or they’re incompetent by building a sandbox their AI could break out of.
> Prove it. But you can’t, which is problematic for you.
More honestly: "Convince me. Except I've already made up my mind, so I'll never let you."
And like yeah, that does seem to be the case, so that's a bit rough indeed.
That said, if you feel like being a bit intellectually daring tonight, here you go: https://youtu.be/87DyyMV0kCY
> Nobody should believe anything OpenAI says about anything.
It's a great thing you bring up beliefs: it's the only thing people ever have, both you and me.
Personally, after hearing their account (linked above), I don't find much to disbelieve on it. It's just a series of "oh okay, that's fun, makes sense" moments. It's normal stuff. They're definitely at least a little proud of having popped a few shops, but that's very realistic in its own way.
I guess your best next option is waiting for a lawsuit to reach discovery or something, and then it's a matter of how dedicated you are to your disbelief. This indeed hasn't happened yet though, if it ever will, so nothing for me to provide (nor for you).
Speaking of, note that I don't have any more reason to believe the likes of you than I do OpenAI. Especially because it all just comes across as trite cynicism, mixed with generous amounts of wishful thinking. I also happen to be simply using these things, so that further plays into why I don't find these events particularly miraculous. It's already existing capability for the most part, so why would I? The only difference is disabled guardrails and better temporal coherence, which is exactly what you'd expect from upcoming models still in eval.
> or they’re incompetent by building a sandbox their AI could break out of.
One could definitely make the argument that someone was at least a little asleep at the wheel, but I don't think that makes them particularly incompetent. Just the normal variety you'll find anywhere else.
You are correct you have no reason to believe OAI compared to me. But I’m sure you’re aware that they are the ones making the extraordinary claim here. I’m simply saying it sounds like something that advertising would come up and it’s right on brand for the likes of Altman and ‘how quickly can I make my first billion?’ They did successfully dominate AI-related news for a few days and get free publicity, which I’m sure is nice when you’re bleeding money and losing the benchmarks race and getting dropped by Apple in favour of Gemini.
So the best part for me is I don’t have to prove anything. I’m not the one claiming it happened.
The onus is on them. Clearly HF did get hacked, but there is no unbiased evidence that this thing broke out of a sandbox unbeknownst to OAI, except OAI saying so.
How do I get it to fix my Bluetooth if I do that? If you've been AI-pilled, 2026 is the year of Linux desktop because instead of dicking around with config files, I can just tell AI to fix python.
> How do I get it to fix my Bluetooth if I do that?
Manual tool calls. I ask AI to give me all the necessary reconnaissance commands, then I run them myself on the host and paste the output on the terminal with the SSH connection into the guest virtual machine where the harness is running. The AI then either figures it out and gives me the answer or runs additional tool calls by me. Repeat until annoying task is done, interrupt if anything suspicious shows up at any point.
If you want to be security conscious don’t give it access to your system directly. Ask it to guide you through the information gathering part of the problem solving process and use your brain and judgment if it actually needs the information/data it’s attempting to access.
If you can’t make that judgement call because of lack of knowledge/familiarity it’s okay - spawn a new fresh chat, get up to speed on the topic first and then resume.
That way you accomplish three things: you learn something new, you fix your problem and you don’t let a Trojan do whatever the hell it wants to your box which among other thing contains all the browser sessions and cookies :)
Also note, that RAG and even vector search are more paths of the early days that didn't prove too valuable. Just let your agent search it directly and optionally create an index as a default entrypoint for common topics.
Bluetooth is the one thing I had problems in the past on GNU/Linux, Windows, macOS, Android and iOS. Linux is the only mentioned platform where you could technically give Codex root and let it fix it :)
I guess OpenBSD is the only OS where I never had any problem with Bluetooth audio.
I haven't had bluetooth issues in years, but I did have an agent reverse engineer a smartphone app that was required for programming some BT headphones. Now I can push my desired runtime settings automatically to the headphones when they connect to my computer
So, yes, I would say agents are pretty good at working with Bluetooth on Linux
That is also what I do now (both with NixOs and Guix Os), both for personal computers and for servers.
- I inspect the agent's changes, and only apply them - at once - if they are OK. So I have no half applied bad changes to my system, and I can catch critical mistakes before they are applied.
- I can roll back the changes by just doing a `git revert` and reapplying
- The agent cannot read secrets or unrelated data, just config.
- The agent gets the full configuration of all systems at once, without having to maintain parallel documentation (which can get out of sync) or rediscover each time from scratch (access my running systems, for example with `ssh root@server`).
- It's harder for the agent to miss some aspect of the configuration, because it's all in my dotfiles. If it's not there, it's nowhere
Give it a full desktop in a VM if you want to, just not direct access to your system.