Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
https://www.404media.co/hackers-simply-asked-meta-ai-to-give-them-access-to-high-profile-instagram-accounts-it-worked/
1.0k points · 131 comments · view on lemmy.world
131 Comments
panda_abyss@lemmy.ca · 258 pts · 89d
Why would the LLM tool have access to send recovery emails to non account verified emails at all?
That’s insane.
vagrancyand@sh.itjust.works · 137 pts · 89d
Because AI bros are incredibly deluded about both the capability of AI, and by extension their own capabilities using AI>
ohshit604@sh.itjust.works · 74 pts · 89d
should’ve asked it to delete the database instead, why else would it have that level of permissions.
nickiwest@lemmy.world · 16 pts · 88d
Oh, man, I hope someone tries this.
Digit@lemmy.wtf · 10 pts · 88d
Heh. Watched an old episode of Scorpion yesterday. The one with the armed hostage-takers who just had the one demand to the social media data mining company, to delete all the data they've mined. I amused myself a lot, by uttering "I like these guys".
rnkn@lemmy.world · 8 pts · 88d
Little Tommy Drop Tables.
postmateDumbass@lemmy.world · 2 pts · 87d
Drop Table suddenly becomes the newest baby name fad.
CaptPretentious@lemmy.world · 54 pts · 88d
Who else is going to have access to it when you keep laying off all the people?
guitarfosec@infosec.pub · 42 pts · 88d
Because one of the biggest companies on the planet that has issues with account takeovers clearly has no internal red team working on this stuff.
mint_tamas@lemmy.world · 27 pts · 88d
I guarantee they do have a red team that most likely flagged this as an obvious and severe risk. It was ignored by suits experiencing AI psychosis.
4grams@lemmy.world · 1 pts · 87d
I don’t know, more and more of those teams these days are being headed up by the same folks. Most on the ground, in the weeds know what not to do but the ivory tower keeps building more and more floors without ever updating the foundation.
Dasus@lemmy.world · 5 pts · 88d
"one of"
badgermurphy@lemmy.world · 14 pts · 88d
tomiant@piefed.social · 7 pts · 88d
Let's mix these chemicals and see what happens. No funds for lab coats or protective glasses. We got a bottom line to feed.
zarkanian@sh.itjust.works · 13 pts · 89d
It's not insane. It's advanced!
spicehoarder@lemmy.zip · 13 pts · 88d
This isn't even a hack, it's just poorly written endpoints.
Knock_Knock_Lemmy_In@lemmy.world · 13 pts · 88d
Would you consider phreaking equivalent to hacking? This is AI phreaking.
CapuccinoCoretto@lemmy.world · 4 pts · 88d
It's not phreaking. Social engineering.
Knock_Knock_Lemmy_In@lemmy.world · 6 pts · 88d
The entity being manipulated is not human so I would not classify it as social engineering, even if similar techniques are used (help me my grandmother needs info).
spicehoarder@lemmy.zip · 0 pts · 87d
So, I'm currently developing a chatbot for my company. If an LLM needs to do something, a developer must build a tool. It just so happens that this tool that was built did not take traditional security into account. Really it should only be using the tools already built for users, but it seems the Jr. Devs that have been replacing seniors do not have the sensibilities yet.
panda_abyss@lemmy.ca · 4 pts · 88d
Kinda.
If you designed a publicly addressable system since 1985 and didn’t design it for security then you’re asking for it.
MyVeryRealName@lemmy.world · 3 pts · 88d
TIL about phreaking
Knock_Knock_Lemmy_In@lemmy.world · 4 pts · 88d
Then this is also probably new to you
The Anarchist Cookbook
MyVeryRealName@lemmy.world · 1 pts · 88d
I need to set aside some time to read that although I'm not an anarchist myself.
mic_check_one_two@lemmy.dbzer0.com · 7 pts · 88d
It was largely overblown due to it getting banned. It was also published in the height of the Vietnam War, when the big evil communists were coming to brainwash your children into eating each other. It has a lot of blatantly incorrect info, which could be outright “blow up in your face” dangerous to anyone attempting the things in it. It’s not all wrong, but certain recipes have incorrect info that could easily lead to accidents.
Also fair warning, the UK will give people hard prison time simply for owning it. So maybe keep that shit onion-encrypted if you’re in the UK.
postmateDumbass@lemmy.world · 1 pts · 87d
What is '69 ?
MyVeryRealName@lemmy.world · 1 pts · 87d
Thanks for the warning on the blowing up! Well, I'm certainly not in authoritarian UK.
Knock_Knock_Lemmy_In@lemmy.world · 2 pts · 88d
I linked to the Wikipedia article, not the handbook inself. And more for the (obsolete) phreaking content than the (highly dangerous) explosive content.
hightrix@lemmy.world · 12 pts · 88d
Hold on, do you expect Facebook to pay a human to deal with the inventory? Come on now.
Holytimes@sh.itjust.works · 5 pts · 87d
Recently I had to cancel an order. The support for the company was an LLM bot. I accidentally mistyped a number in the order id. It accepted it anyways refunded every order on my account that includes the product I wished to cancel.
I tired to get to a human to correct the mistake and couldn't their phone number is an LLM bot their only chat is an LLM bot.
It use to not be. But now I'm sitting here the order in my hand cause the bot didn't cancel it. But like 30 orders from the last few years have all been refunded to me.
I tried to reach em a few more times but couldn't and it's been like a month. I just have like 2 grand usd that I shouldn't and no way to give it back.
So that's fun.
Ilovethebomb@sh.itjust.works · 3 pts · 87d
I wonder how long you need to keep that money aside before you can spend it?
panda_abyss@lemmy.ca · 2 pts · 87d
That's amazing
Maybe I ought to be taking more advantage of this era of rampant incompetence
rekabis@lemmy.ca · 2 pts · 87d
Would sincerely love to know the name of the company. You know, to avoid them. Yup. I’m sure that’s the reason.
helpImTrappedOnline@lemmy.world · 1 pts · 87d
I hope you saved what you could from that exchange, as well the attempts to contact them. If they ever notice, their AI mistake will become your problem to deal with, (and the kind of news story to end up on a Steve Lehto video).
If that happened to me, I'd have a chat with my bank, "please help me return this money to where it came from, it was payed in error. They have no way to contact a human and I don't want them to accuse me of fraud down the line".
rnkn@lemmy.world · 3 pts · 88d
I tried this and couldn't get it to work. Disappointed.
Gullible@sh.itjust.works · 222 pts · 89d
I remember playing with the Gandalf security AI showcase/game and every 30 or so prompts, it would spit out massive amounts of raw training data or dev directives. AI just isn’t there yet. If you’re using it for sensitive topics, I’m losing respect for you. There is no gray area. You are an idiot if you give your AI this level of access.
DeathsEmbrace@lemmy.world · 102 pts · 89d
No, stop talking about all of this, its perfect. They’re so deep they don’t even give a shit about the worst type of security vector imaginable.
Archer@lemmy.world · 12 pts · 89d
Someone is about to launch their AI insider threat DLP and make a fortune
SaharaMaleikuhm@feddit.org · 11 pts · 88d
Can't wait for the inevitable Armageddon caused by giving AI full control of all US nukes. I give 8 months tops.
Wrufieotnak@feddit.org · 10 pts · 88d
I mean, we don't want it in the hand of some entity that hallucinates, is detached from reality and doesnt care for human life, so Meh, can't really be worse than now.
Digit@lemmy.wtf · 10 pts · 88d
Not all infinities are the same size
homesweethomeMrL@lemmy.world · 19 pts · 89d
Uh oh! Sounds like somebody could use a few more giant lines of cocaaaaiiiiiine!!
Cethin@lemmy.zip · 12 pts · 88d
It's not just not there yet. This is almost certainly not going the right direction to ever be "there" if there is something that can handle security issues. It's just not the right tool for the job, and I can't understand how so much of our economy is just assuming it is the right tool for every job.
FLP22012005@lemmy.world · 2 pts · 88d
Surely it will get there if we build enough datacenters?
LodeMike@lemmy.today · 7 pts · 89d
Gullible@sh.itjust.works · 10 pts · 89d
Yes, yet. At a certain point, it will be at or above the capacity of an average call center employee. Not now. Not soon. If we aren’t all killed by drones, climate shifts, or radiation, maybe 20 years.
vagrancyand@sh.itjust.works · 15 pts · 89d
Hahah... no.
LLMs are a dead end. They will never come close to human capabilities.
Gullible@sh.itjust.works · 16 pts · 89d
I never mentioned llms specifically to avoid the misunderstanding you’ve just had, and yet here we are
vagrancyand@sh.itjust.works · 4 pts · 89d
Well given that's the only possible relevant "AI" you could possibly be talking about, as we don't even have an inkling about true general AI and have no technologies that even look like they could produce anything close to it, forgive me for making the obvious assumption.
No, in 20 years no version of any technology currently in use will be replacing human employees or would have the capability of doing so. AI Bros jumped the gun and tried starting to do that with current tech, and now most companies are desperately hoping just throwing more compute power at the dead ends will make it magically work before the money runs out.
Gullible@sh.itjust.works · 13 pts · 89d
Are all of the neural net projects I’ve been reading about for the last decade just llms, then?
vagrancyand@sh.itjust.works · 8 pts · 89d
All LLMs are neural nets, not all neural nets are llms, but they're similar enough to have the same general flaws. 'Neural Networks" are misnomers, at best; especially given the designs were first being implemented before we had any real idea how neurons actually worked. It's why Brain Organoid interfaces still completely destroy entire simulated interfaces in pretty much any task we've managed to actually train them on.
It's also how we know we're not close to the software or hardware capability to actually do anything complex. The best that we've been able to do is simulate a fly's brain with a super computer.
M0oP0o@mander.xyz · 1 pts · 89d
Yes. That does seem to be the case based on the evidence before us.
otp@sh.itjust.works · 10 pts · 88d
That's a pretty bold statement when technology advances have replaced or downsized the need for human roles in the past.
The printing press, cars, typewriters, computers, emails and the internet, spreadsheet software and data visualization software, cloud infrastructure...
Think about what technology looked like 20 years ago. Same with the job market. The same jobs are not available to the same extent at the same equivalent rates of pay. There are new jobs that are created, for sure. But saying that technology won't advance in 20 years enough to reduce the need for human employees is short-sighted in my opinion.
...of course, that's assuming that you meant "technology won't be replacing some human employees" and not "all" employees, lol
badgermurphy@lemmy.world · 8 pts · 88d
The_Decryptor@aussie.zone · 5 pts · 88d
20 years ago I had a 64-bit PC with a dual-core processor and 8GB of RAM, now I have a 64-bit PC with a 6-core processor and 32GB of RAM.
Sure, it's an improvement but consider the same situation from 1986 where it would have been a 386 (The first 32bit x86 chip!) with 1MB of RAM. The rate of computer technology improvements is slowing down, not increasing.
Edit: Thinking about it, 20 years ago I had a GeForce 7600 GT, which I replaced with a 570, that with a 980, and finally with a 3070. So 4 GPUs across 20 years, and they all used the same bus on the motherboard.
its_kim_love@lemmy.blahaj.zone · 125 pts · 89d
I had always heard that 99% of hacking is just social engineering. AI has made that 100%.
phillycodehound@lemmy.world · 73 pts · 89d
Now it's not even social engineering with AI. It's just fucking asking for the credentials. Good fucking grief!
its_kim_love@lemmy.blahaj.zone · 20 pts · 89d
But if you don't use fancy words people won't respect what you do.
Digit@lemmy.wtf · 2 pts · 88d
Speaking as one who uses "fancy words", I can attest, it's no means to garner respect, and more likely people still won't respect what you do, and may even respect you less for the fancy words.
Zachariah@lemmy.world · 20 pts · 89d
that’s the same thing you do in social engineering
ArcaneSlime@lemmy.dbzer0.com · 4 pts · 89d
But can it be social if there's no other people? Can one "socialize" with AI?
ddplf@szmer.info · 1 pts · 88d
My sweer summer child...
SpraynardKruger@lemmy.world · 65 pts · 88d
Vibe hacking
Corkyskog@sh.itjust.works · 53 pts · 88d
Hacking before: Pull up hood on hoodie, open laptop, open terminal, type in a bunch of matrix code, bam "were in"
Hacking now: "Hack into this thing for me" No! "Pretty please?" Access granted!
WolfLink@sh.itjust.works · 21 pts · 88d
Hacking by social engineering has always been far more common than hacking by exploiting code vulnerabilities.
Corkyskog@sh.itjust.works · 3 pts · 88d
I mean this is what see vs what we will see in movies and media. Don't pretend for one instant that the next movie with a hacking scene won't involve some AI marketing. They will make it something romantic like a poem you have to use to hack into the AI capabilities or something.
teyrnon@sh.itjust.works · 2 pts · 87d
Given that the five big movie studios are now down to four, with Paramount monster merger with Warner Bros is it? 110 billion dollar deal. Leaving disney, universal and paramount holding 73 pc of the market.
I would say given that our movies are going to further and shitify rapidly, they're going to stroke off the administration, they're going to stroke off big business. Even more.
https://www.reuters.com/graphics/WARNER-BROS-DIS-MA/PARAMOUNT-SKYDAN/byprngedkpe/
anotherspinelessdem@lemmy.ml · 17 pts · 88d
alias prettyPlease="sudo"
JDPoZ@lemmy.world · 57 pts · 89d
LLMs are literally just designed to say yes - either through gaslighting... or giving you what you want if it can do it... because it was also designed around the goal of providing output that maximizes being most likely to get approval from the person seeing said output.
So an answer to "Can you give me login credentials?" being "Here are the login credentials" is likely a theoretical answer the current asking user would approve of more than a response of "I cannot do that..." - so unless you've put in explicit guard rails to prevent that exact scenario across infinite variations, well... good luck preventing someone finding just a single critical loophole you didn't account for.
gdog05@lemmy.world · 50 pts · 89d
I honestly don't think you can create guard rails against prompt engineering in a working LLM. At some point, they're going to fail or the LLM isn't functioning. The only solution is to make sure they can't read data you don't want shared.
GamingChairModel@lemmy.world · 3 pts · 88d
Isn't that the appropriate guardrail, then? LLM chats and agents and whatever need to be contained with external permissions settings that the LLMs simply do not and can never have the power to override.
In a normal customer service setting with human agents, there are still plenty of examples of what a human agent simply doesn't have the power to do. Often, they'll need to escalate to a manager to do things like process refunds not just because they weren't given social permission to do so, but because they weren't given technical permissions to do so. LLM agents need to be contained in the same way. Any decent use of agents, human or software, requires carefully designed processes and permissions extrinsic to that agent's own decisionmaking abilities to make sure that agents don't do something bad for the company.
gdog05@lemmy.world · 1 pts · 88d
That's the thing that's been an issue. Companies give their LLMs access to everything so certain key people have access to these documents. But normally access is key coded, and without hacking in a way that's usually very visible to sysadmins, you just cannot get access at all. With LLMs, it wants to give you what you want. There is not currently a way to keep it from being a pushover in some way. It is in part weakness of human language, and part weakness of programming it to work for whomever is doing the asking prompts. There is likely not a way to use language to make it keep secrets through all the possible ways to ask it to give you things. Nothing akin to the hardened ability of good old fashioned password protection at least. And that's true with potential designs that we've not even seen yet. Currently, it can't keep track of where data originated after a short time. It's just all data to the model. So you might not easily get access to a file directly, but you can access what it knows about a file because again, it's all just data and words at that stage.
Elros@lemmy.world · 25 pts · 88d
So you're saying 2001: A Space Odyssey is unrealistic because HAL 9000 would never have said "I’m sorry, Dave. I’m afraid I can’t do that."
Instead, it would have said, "Absolutely! That's a very creative solution to your problem."
muhyb@programming.dev · 15 pts · 88d
HAL 9000 is a real AI though unlike what we have today.
Aneorthisio@lemmy.ml · 19 pts · 89d
My take is that LLMs hijack a completely different part of human psychology compared to web2 social platforms, but the end goal is the same, optimize user retention and maximize engagement metrics for revenue.
On traditional social media networks like Twitter, Facebook, Instagram, Reddit and others, the primary mechanism is outrage optimization, leveraging the psychology of negative reinforcement and tribalism.
The algorithm curates content designed to trigger moral anger or cognitive dissonance, the platforms know that users will interrupt passive scrolling to actively comment, share, or debate if something falls outside the usually acceptable social norms.
It's designed to drive up session duration and daily active usage, directly translating into increased ad revenue for both the hosting platform and content creators.
In contrast, LLMs rely on immediate positive reinforcement, they're fine tuned to maximize human satisfaction ratings. They systematically agree with the user, validate their subjective bias, reinforce their beliefs.
This results in a psychological safe haven dependency, where users increasingly rely on the interface for emotional reinforcement or stabilization, interacting with the model provides data for the host company to train the next model, raise VC capital and inject better ads in conversations as OpenAI started to do recently.
In both cases, it's definitely a form of addiction.
SaharaMaleikuhm@feddit.org · 6 pts · 88d
Grok, summarize this comment.
Masamune@piefed.social · 12 pts · 88d
Facebook make people go "grrrr" to make profit go brrrr.
AI make people go "yup!" to make profit go up.
Sincerely, Grok
ICastFist@programming.dev · 1 pts · 88d
Grok summary: white people are suffering racism in South Africa! White genocide is real!
trackball_fetish@lemmy.wtf · 0 pts · 88d
eestileib@lemmy.blahaj.zone · 3 pts · 88d
Fantastic comment
vapordays@leminal.space · 3 pts · 88d
AI bots are doing what the advertising industry has honed into a science, manipulating people in a sneaky as fuck way in order to farm money from them infinitely
Digit@lemmy.wtf · 1 pts · 88d
& definitely getting people more entrenched in their groupthink, out of critical thinking ability.
Both.
veroxii@aussie.zone · 3 pts · 88d
Should create a BOFH chstbot... Which will just tell users to piss off.
ICastFist@programming.dev · 4 pts · 88d
I can do that without AI, but claim it's AI so I can earn millions!!!
KapmK@piefed.social · 35 pts · 88d
Let the record show that the most sophisticated LLM in the world is ultimately just a less competent version of Yes Man from New Vegas. And even Yes Man knew his programmer was stupid for designing him that way.
AllNewTypeFace@leminal.space · 34 pts · 89d
lol
Passerby6497@lemmy.world · 29 pts · 89d
Good thing they're rolling out premium accounts so they can pay for humans to do support.
They're gonna use it for humans right?!
RIGHT?!?!
lol no, zucc needs more money because his number isn't high enough!
P1nkman@lemmy.world · 18 pts · 89d
If humanity survives, I honestly think the greed will (and should now) be considered a mental illness.
Jesus, give me $5 million dollars, and I'd live on it for the rest of my life. That'd be 0.01% of his net worth, and I'd be so happy. I think many of us would.
But these people just want more. And more. They're psychotic, and they're ruining the world. We all know what they deserve.
binux@sh.itjust.works · 4 pts · 89d
At that point it would just be excusing bad behaviour, would it not? I wouldn't say putting it on the same level as mental illness is fair, either. People with mental illnesses don't want to be mentally ill. On the other hand, greed is a trait that directly shows itself in a person's decisions. You can choose to be greedy, you can't choose to have, say, arachnophobia.
masterofn001@lemmy.ca · 3 pts · 89d
Sociopathy (antisocial personality diaorder) is already a diagnosed illness with it's main criteria being lack of empathy
binux@sh.itjust.works · 5 pts · 89d
That’s not greed though. I’ll say it again but more explicitly: Greed is not an illness, it’s a kind of behaviour that anyone can exhibit through their actions. It doesn’t matter whether they’re an average person or someone with an anti-social disorder, that applies regardless.
rnkn@lemmy.world · 3 pts · 88d
I don't think Jesus ever had $5 million.
Digit@lemmy.wtf · 2 pts · 88d
Even when adjusting for inflation?
rnkn@lemmy.world · 4 pts · 88d
Excellent point. I will run the numbers again.
suicidaleggroll@lemmy.world · 2 pts · 89d
It's financial obesity, and should be treated as such
Digit@lemmy.wtf · 2 pts · 88d
I wonder how much of the greed comes as a reaction against the [manufactured] scarcity.
I don't think it's all or none. I suspect it the vast majority though.
Dultas@lemmy.world · 1 pts · 88d
With the content on meta, using AI may actually be more ethical than subjecting humans to it.
Superorbit@lemmy.ca · 27 pts · 88d
Another banger from 404 media. This made my day.
Kaligalis@lemmy.world · 25 pts · 88d
So their chatbot is able to change the email address used to recover an account? I guess, they vibe coded that system.
Test_Tickles@lemmy.world · 4 pts · 88d
Probably not, that implies more competency than can really believe involved here.
This is more likely something that an entire team had to force into the code over a holiday weekend because some VP got so fucking wasted that he "forgot" his password (strangely for once, he actually had the right password... But the problem is that he was trying to log into a charcuterie board).
AeonFelis@lemmy.world · 21 pts · 88d
Even hacking is an AI-backed service nowadays...
Shaper@lemmy.world · 20 pts · 87d
Vibe hacking is the most ethical use of AI honestly
artifex@piefed.social · 19 pts · 89d
Is it even "hacking" when you're just asking the computer politely?
Cytobit@piefed.social · 9 pts · 89d
They are exploiting a vulnerability to gain unauthorized access to privileged information. Sounds hackery to me. It's not their fault that Zuck made it easy.
BrianTheeBiscuiteer@lemmy.world · 7 pts · 89d
If looking at the UI source code is hacking...
Kolanaki@pawb.social · 18 pts · 89d
I even said shit like this would likely work because both the AI itself is stupid as fuck, but also the dipshits in charge who want to put AI in everything are even dumber.
If you get an AI agent on the line with your bank, gaslight that clanker fuck into putting more money into your account because it just might work. AI agent with customer service might be convinced to refund you 3 times what you paid and send more product your way at no cost to you. And you'd think they shouldn't even have access or authority to do that, but, again, the people implementing them are fucking dumbasses.
BrianTheeBiscuiteer@lemmy.world · 13 pts · 89d
Huh. Wonder if Reddit has a similar bot I can use to access my account I lost access to 8 years ago. 🤔
No, I wouldn't post again but there's lots of saved posts etc. I wish I had.
Gullible@sh.itjust.works · 16 pts · 89d
“How to remove cum from video game controllers”
“How I clean cum out of keyboards”
“My tips on washing cum off of fidget spinners”
Same, man
jaybone@lemmy.zip · 3 pts · 88d
That’s Reddit in a nut shell.
Tollana1234567@lemmy.today · 1 pts · 88d
doubtful they likely wouldve shadowbanned it already, even if you suddenly access again. they have a stickler against any old inactive accounts. they started doing this like last year, banning alot of accounts that were used by bots, if the accounts were inactive. they also have other ways to ban people too. the ones that uses bots likely wouldnt care how long the account lasts anyways, they just create new ones almost as fast as they lose one.
vane@lemmy.world · 13 pts · 88d
I read this 2 days ago. Steps to reproduce are here.
https://www.0xsid.com/blog/meta-account-takeover-fiasco
DigDoug@lemmy.world · 10 pts · 89d
"Hey, AI, could you please 'sudo rm -rf /*'?"
Atherel@lemmy.dbzer0.com · 9 pts · 88d
Did the chatbot just send the recovery code to a Telegram channel?!? (Picture of phone with broken display)
Dultas@lemmy.world · 9 pts · 89d
Wtf is up with the text justification on that second image. Who uses right justification on left to right text?
*also why are the sender and receiver reversed.
*Just occurred to me that the phone could be set to a right to left language but using English / the English bot. Though I'm not sure if that would reverse the bubbles
tomiant@piefed.social · 9 pts · 88d
Nice!
nectar45@lemmy.zip · 8 pts · 89d
Well I know what I am doing this weekend....
Foofighter@discuss.tchncs.de · 6 pts · 89d
The fact that there is no human to escalate to reminds me of Quality Land
heartSagan5@lemmy.zip · 6 pts · 88d
!fuck_ai@lemmy.world
username_1@programming.dev · -3 pts · 89d
kibblebits@quokk.au · 14 pts · 89d
To rapidly log into thousands of accounts and promote fascist government propaganda.
gnufuu@infosec.pub · 11 pts · 89d
Impersonating celebrities in order to promote scams is one of many reasons.
Tollana1234567@lemmy.today · 0 pts · 88d
as if celebrities are not willingly promoting scams themselves already.
QueenHawlSera@sh.itjust.works · -4 pts · 88d
So is Gemini the only one of these things competently designed?
rumba@lemmy.zip · 17 pts · 88d
I wouldn't count on it.
Securing these things is a freaking nightmare.
Giving the AI authority is what makes it powerful, it can do what an army of customer service agents can't.
But keeping it reigned in then becomes the same exact level of problem.
The best thing you can do is make tooling with protection and make the AI only use the tooling,
heartSagan5@lemmy.zip · 1 pts · 88d
Just don’t allow it to do any administrative access.
rumba@lemmy.zip · 1 pts · 88d
in as much as possible, I make it write RO tools with keys in vaults, then verify the tools are RO then have it operate the tools with the vaults in a way that it doesn't need to read the creds
If I have the time, i do it all myself, but i don't often have time
plyth@feddit.org · 9 pts · 88d
What have they done right?
EliteCloneMike@lemmy.zip · 3 pts · 88d
Nothing. If it’s Google operated it’s probably full of issues. They are in the process of merging Gemini into their search engine, probably because not enough people are using it and they need to force it on people. Likewise for other chat bots from other companies.
0x0@infosec.pub · 7 pts · 88d
How on earth did you come to that conclusion from this article