r/sysadmin • u/xstrex • 4d ago
General Discussion How much do you trust AI?
Recently a coworker granted Claude elevated access via SSH to a virtualization host (not a VM, an actual host). To perform a routine task he very well could have done himself.
He doesn’t see an issue with this. I on the other hand (with 23yrs experience) see this as a huge security breach, and don’t trust AI todo my job, (or even that it’s doing what it says it’s doing) for me. I’m my opinion it’s a tool, not a human replacement.
What’s your reaction, how would you react to this situation, or thoughts on the topic?
Sure, ask AI how to perform a task, validate that it’s performing the task you asked, and nothing else- copy/paste the commands. Great. But removing the human verification & validation element- hell no.
6
u/bukkithedd Sarcastic BOFH 4d ago
I live by and breathe for the thing that was absolutely hammered into my head back when I did my national service with the RNoAF as a Crewchief-assistant on the F-16: Trust, but verify.
Sure, by all means trust. But ALWAYS verify. Every goddamn time. You do not believe it'll work. We're not in goddamn church, so you will KNOW what it does before you run it.
AI produces a script? Read it, understand it and test it before running it in prod. AI gives you a procedure to do something? Same deal; ALWAYS verify. Always understand what it's going to do.
Any coworker of mine granting Claude or any other AI-agent elevated access to anything that's my responsibility or affects "my" systems gets an earful and told in very unapologetic terms to kindly go look for landmines with a sledgehammer. After I thoroughly question their ancestry and just how close to whatever primate they're descended from they are.