‹ BackHN Continuity

Thread

MCP was always a bad idea?

335 points · 331 comments · maharshi365

  1. simonw · · focus · HN ↗
    This article entirely misses the value that MCP brings today.

    Sure, there's almost no reason to use MCPs if you are running a full-blown terminal agent (Claude Code, Codex, Meta Muse, OpenClaw etc) with unfettered internet access - just let it call APIs directly.

    If you want to operate something that's less YOLO than that, you'll find yourself wanting:

    1. Control over exactly which external services it can access

    2. A way to handle authentication that doesn't allow the agent to directly access API keys

    3. A sensible UI to allow users to connect and authenticate further services

    4. Strong audit logging for what's going on

    MCP makes all of that so much easier to provide.

    Thinking MCP is obsolete because full coding agents don't need it misses out on all of the other things we might want to build.

    1. pragma_x · · focus · HN ↗
      As someone who has never used MCP, or allowed an AI to directly talk to APIs, putting something between a model and a service just seems like common sense. If nothing else, it presents an opportunity to tightly control what the AI is allowed to do with external services, especially if the MCP code is outside of the AI's context. I would go as far as to say it's a necessary security measure.
      1. dominotw · · focus · HN ↗
        well if you realease an api you should make sure its usable for ai out of box without 'something in between'. You should always assume ai might be directly calling your api.
        1. anamexis · · focus · HN ↗
          And if you don't have a public API, you should always assume AI will be using your UI, reverse engineering your private API, and driving it directly.
          1. cruffle_duffle · · focus · HN ↗
            I absolutely love when they do that unprompted. I once asked a Claude work agent to go pull comparable apartment listings and somehow it’s subagent reverse engineered like rentcafe or whatever’s private API to get the data. All unprompted.

            So yes. Absolutely assume AI agents acting on behalf of their humans are finding all the token efficient ways to get at your sites data.

        2. Tractor8626 · · focus · HN ↗
          Ai can't use any api out of box. It requires thing called "harness" to use anything.
      2. jimbokun · · focus · HN ↗
        The service itself needs to control what the agent can access.

        Relying on an intermediary to provide access controls, and that agents will never access the service directly, seems dangerous and naive.

        1. jayd16 · · focus · HN ↗
          What? Why? More is more but you're arguing a security proxy is a dangerous and naive pattern?
          1. jimbokun · · focus · HN ↗
            What’s the advantage of MCP over a regular old security proxy?
            1. Sattyamjjain · · focus · HN ↗

              [dead]

        2. anon84873628 · · focus · HN ↗
          And it's easy for the service to do that by hosting a remote MCP server.
        3. Tractor8626 · · focus · HN ↗
          Agent doesn't have api key to access service directly
      3. ActorNightly · · focus · HN ↗
        The better solution for security is sandbox execution. Most agents used in practice, if given terminal access, can find ways to get around most of the MCP restrictions.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.