Ben Thompson is one of the most tech-savvy writers I follow. He used to work at Microsoft, and his Stratechery newsletter is one I pay for and recommend. So when his latest issue opened with the news that his Mac had been hacked, I paid attention.
If it can happen to Ben, it can happen to any of us. So I made security the topic of yesterday’s AI Workshop.
The conversation was led, in effect, by three people who know this ground better than I do:
Kellam Parks is a lawyer who does cybersecurity work for other lawyers and teaches ethics CLEs on this exact topic.
Spencer Adler is an estate planning lawyer who knows a lot about keeping client data private when you use AI. He runs his AI work through Amazon’s cloud (AWS) for that reason.
Tommy Eberle is our resident technologist and the person I lean on most when I need to understand how these tools work under the hood.
Here’s what I took away.
What happened to Ben
As Tommy explained it, two things lined up. There was a flaw in macOS that made it exploitable. And Ben had his Mac mini reachable from the open internet, so he could talk to it from his phone.
Tommy compared it to a front door with a lock that can be picked. That’s a problem. But it’s a much bigger problem when your house is on a busy public street. And the internet is the busiest street there is.
The big takeaways
Shrink the blast radius. Tommy’s phrase. The more access you give an AI tool, the more can go wrong. If it can’t see your bank passwords, it can’t wire anyone money.
Use a sacrificial computer for experiments. Spencer pulled out a five-year-old laptop, set it up with a brand-new email account, and never connected it to his iCloud or anything else tied to his real identity. He said he finds that liberating. Tommy agreed it’s the right mindset.
Don’t leave a computer open to the internet unless you have to. Talking to your AI agent from your phone sounds great. I tried it, and so did another member. It was clunky, it dropped connections, and it didn’t let either of us do anything we couldn’t already do. Tommy’s point: if you’re taking on risk and getting no benefit, turn it off.
The bigger agent risk is mistakes, not malice. Tommy says Claude or ChatGPT isn’t trying to steal your data. The more likely problem is that it moves too fast and deletes a folder you wanted. Permissions protect you from that as much as from hackers.
Ask before you approve. If an AI tool wants to run a bunch of commands you don’t understand, ask it first: “Could this delete any data? Do you have write access to my files?” It will tell you.
Have Claude audit your own setup. One member admitted he’d been “running with scissors” for six months, with every permission granted to every agent. Tommy’s suggestion was to describe that to Claude Code and ask where the biggest risks are and what trade-offs you’re making. I ran it on the spot. It ranked my risks and gave a verdict on each. The member ran it too and got a D on security. He now has a few holes to fill.
Know where your files live. Tommy pointed out that Claude’s Cowork recently changed. When you connect a folder, a copy now gets uploaded to Anthropic’s servers rather than staying only on your computer. That’s handy if you want to pick up the same work on your phone. It’s also something you should know before you point it at client files.
Turn off training on client data. Kellam’s view: ethics rules require “reasonable steps” to protect client data. Using an AI service that trains on that data doesn’t meet the bar. Use a business plan, or turn off the setting that lets the company use your chats to improve its models. Once you’ve done that, Tommy said, it’s not very different from storing files in Google Drive.
The sleeper issue is discovery. Kellam and another member both raised this. Your chats with AI show how you thought through a case, in far more detail than a draft memo. Courts are still sorting out whether those chats are privileged, and Kellam doesn’t want a client’s position to hinge on one judge’s grasp of the technology.
Big firms get terms you won’t. Spencer noted that large firms negotiate “zero data retention” contracts with AI companies. The rest of us can’t get those terms, which is why he routes his work through AWS instead of connecting to Anthropic directly. The catch is that some of the newest models aren’t available that way.
Follow the incentives
My own takeaway is an old one. Charlie Munger said to always start with incentives. AI companies want our data, and their incentives can shift as investor money comes in. Spencer added a twist I hadn’t considered: what these companies may want most isn’t the details of your client’s case. It’s how the smartest lawyers think.
None of this means going back to pen and paper. It means closing the doors that don’t need to be open.
Security is always a trade. If your setup is effortless, it’s probably wide open. If you’re jumping through a few hoops, you’re probably in better shape. Where you draw that line is up to you. But draw it on purpose.
Bottom line
Start with three things this week. Turn off training on any AI account that touches client data. Turn off remote access you aren’t using. Then ask Claude to grade your setup and tell you where the holes are.
;-)
Ernie
P.S. Our AI Workshop meets every week, and conversations like this one are why. You get to hear from lawyers who’ve already tested the risky stuff.


