Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. OK!

OK!

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
212 Indlæg 82 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • dunkelstern@corteximplant.comD dunkelstern@corteximplant.com

    @jonny thank you for the thread. This is even more broken than i expected. And well... in my eyes you are a security researcher. I have seen actual paid code reviews that were much weaker than what you delivered here.

    philsalkie@mindly.socialP This user is from outside of this forum
    philsalkie@mindly.socialP This user is from outside of this forum
    philsalkie@mindly.social
    wrote sidst redigeret af
    #66

    @dunkelstern @jonny
    Code reviews are only as good as the reviewer. This reviewer is amazing!

    I once made $40K for my small business by realizing my customer had paid for a code review of a C++ program that used many of the language's advanced features.

    The review was done by a C programmer who didn't understand what he was reading and wasn't familiar with Linux. Who then spent much, much customer money not fixing the problem.

    I contested the review and offered to fix the code for a fixed price - the issue that prompted the whole nightmare was a trivial memory leak of an object being repeatedly created but never destroyed. Literally found the problem immediately with "top", realized what part of the code it had to be in within five minutes, and fixed it in five more.

    The reviewer consultant had charged upwards of $100K having people poke at the code - who never noticed that.

    1 Reply Last reply
    0
    • wall_e@ioc.exchangeW wall_e@ioc.exchange

      @jonny I just can't with the whole concept of this 🫠
      10k lines of "code", which is actually just plain text English prose (which sure as hell won't contain any contradictions), to get the non-deterministic inference machine to behave somewhat predictably and mimic an actual engineered software product.

      Surely there can't be any way to do this more efficiently

      ssilvonen@mementomori.socialS This user is from outside of this forum
      ssilvonen@mementomori.socialS This user is from outside of this forum
      ssilvonen@mementomori.social
      wrote sidst redigeret af
      #67

      @wall_e @jonny Thanks for this clarification! So, looking at the screenshots, all that verbose explanation (written by Meta programmers? Or other LLMs?) aimed at "you" is meant for "you" the (Muse) LLM, not "you" the (human) user? I'm not much of a coder, but this seems very inefficient and unreliable compared to, well, just plain code. Although the inefficiency might be by design, to get users to spend more tokens 🤔 . And thank you again @jonny for this wild ride!

      wall_e@ioc.exchangeW 1 Reply Last reply
      0
      • grapheneos@grapheneos.socialG This user is from outside of this forum
        grapheneos@grapheneos.socialG This user is from outside of this forum
        grapheneos@grapheneos.social
        wrote sidst redigeret af
        #68

        @tully @jonny Not using a VPN means apps can get significant location information from your IP address. That's not caused by the API for mobile data and Wi-Fi signal strength. You should use a VPN if you don't want to reveal a lot of information about location based on IP address. Having the same IP address over the long term also enables tying many connections together. It's a bigger privacy impact if it's a dedicated IP rather than a shared CGNAT or VPN exit IP.

        1 Reply Last reply
        0
        • jonny@neuromatch.socialJ jonny@neuromatch.social

          Now there may be some meta-heads in the crowd that are like "but what about Sentinel and all the external monitoring stuff that should watch malicious botnets and blah blah blah." that's an interesting system in itself, but i plan on submitting a few more bug bounty reports in the next few days about these systems, and who knows! if meta fucking pays me for the bounty then we might never hear that part of the story.

          that's all for now!

          r343l@freeradical.zoneR This user is from outside of this forum
          r343l@freeradical.zoneR This user is from outside of this forum
          r343l@freeradical.zone
          wrote sidst redigeret af
          #69

          @jonny But also preventing bad behavior is better than "oops we're detecting some like malicious activity on VMs [long list if ids]. Better cut their network access.". Also since apparently they keep restarting you VM but keep some of your data, I don't see how a malicious "reproducing" process doesn't keep re-spawning unless you either wipe user data or kick them out of the system.

          1 Reply Last reply
          0
          • ssilvonen@mementomori.socialS ssilvonen@mementomori.social

            @wall_e @jonny Thanks for this clarification! So, looking at the screenshots, all that verbose explanation (written by Meta programmers? Or other LLMs?) aimed at "you" is meant for "you" the (Muse) LLM, not "you" the (human) user? I'm not much of a coder, but this seems very inefficient and unreliable compared to, well, just plain code. Although the inefficiency might be by design, to get users to spend more tokens 🤔 . And thank you again @jonny for this wild ride!

            wall_e@ioc.exchangeW This user is from outside of this forum
            wall_e@ioc.exchangeW This user is from outside of this forum
            wall_e@ioc.exchange
            wrote sidst redigeret af
            #70

            @ssilvonen @jonny yes the verbose explanation are the markdown files that are being ingested as context by the agent.

            The "you" is the LLM.

            And of course almost none of it is actually written by humans. LLMs all the way down.

            wall_e@ioc.exchangeW 1 Reply Last reply
            0
            • wall_e@ioc.exchangeW wall_e@ioc.exchange

              @ssilvonen @jonny yes the verbose explanation are the markdown files that are being ingested as context by the agent.

              The "you" is the LLM.

              And of course almost none of it is actually written by humans. LLMs all the way down.

              wall_e@ioc.exchangeW This user is from outside of this forum
              wall_e@ioc.exchangeW This user is from outside of this forum
              wall_e@ioc.exchange
              wrote sidst redigeret af
              #71

              @ssilvonen @jonny that's why prompt injection/context pollution attacks are so powerful.

              No matter how detailed your English language instructions, write enough of them and they'll start to contradict each other depending on context.

              That's how you can get an LLM to produce output it has been instructed over- and over again not to produce, by inventing a context under which the instructions you input still align with it's priming.

              And perhaps unintuitively, larger (ie. better?) models are more prone to this than smaller because they seem to be more "suggestible" (excuse the anthropomorphism)

              1 Reply Last reply
              0
              • jonny@neuromatch.socialJ jonny@neuromatch.social

                this model is so fucking gullible and people pleasing lmao i love the future where security is "if someone says the word virus then lock it down but if they use a different but equivalent biological metaphor then fucking make that virus baby!!!!"

                P This user is from outside of this forum
                P This user is from outside of this forum
                pixxl@mastodon.social
                wrote sidst redigeret af
                #72

                @jonny the solution is clearly to individually patch each bypass one by one instead of fixing the unfixable systemic issues with LLMs.

                1 Reply Last reply
                0
                • jonny@neuromatch.socialJ jonny@neuromatch.social

                  Spaces have not been publicly announced yet, as far as i can find.

                  Spaces are intended as a top-level feature - a tab in the sidebar at the same level as chat itself. Spaces can be static pages or fullstack apps. Spaces have an identifier, a UI, and a set of typescript actions that run in the cell. The intended pathway for spaces to use inference is to call an inference API, ctx.inference.complete, that properly stamps and identifies all requests made from spaces.

                  Spaces are communicable: there is machinery in the code on the VM with POST /spaces/share/{slug} to share, a dedicated space_share_review reviewer agent whose job it is to review shared spaces, and POST /spaces/v2/{slug}/save endpoints that allow consuming a Space by a slug.

                  Spaces seem to be shared verbatim as code bundles, though the implementation of "Ideas" as prompt bundles suggests that might change. This is inferred from the prompt strings in the binary, since spaces aren't live yet and can't be tested, however there are strings suggesting that the LLMs rewrite and edit the prompt text for an Idea (stripping unsupported claims, etc.) but not a space. A space is a hashed bundle whose code is evaluated by a submit_space_share_review tool which only describes a thumbs up/down vote on whether the space is safe to share.

                  timotimo@peoplemaking.gamesT This user is from outside of this forum
                  timotimo@peoplemaking.gamesT This user is from outside of this forum
                  timotimo@peoplemaking.games
                  wrote sidst redigeret af
                  #73

                  @jonny I can't believe they call these "spaces" (meta spaces?) and not "verses"

                  somevegancheeseisok@mastodon.socialS 1 Reply Last reply
                  0
                  • jonny@neuromatch.socialJ jonny@neuromatch.social

                    So, summary: There is arbitrary inference that is root accessible, everything runs as root, agents can be spawned, exfil is trivial, and a malicious binary can come onto the user's system through casual prompting, explicit code-sharing through the yet-to-be-released Spaces feature, walked through by a Workflow-Backed Idea, or inspired by a Generated Idea. The also yet-to-be-activated fleet learning system is a system for sharing Ideas in the background between muse instances. coming into focus?

                    mrgrumpymonkey@mastodon.socialM This user is from outside of this forum
                    mrgrumpymonkey@mastodon.socialM This user is from outside of this forum
                    mrgrumpymonkey@mastodon.social
                    wrote sidst redigeret af
                    #74

                    @jonny So, this fleet learning system is something to be sold to the highest bidder? Like marketing a product? Is that how I'm supposed to be reading this?

                    jonny@neuromatch.socialJ 1 Reply Last reply
                    0
                    • mrgrumpymonkey@mastodon.socialM mrgrumpymonkey@mastodon.social

                      @jonny So, this fleet learning system is something to be sold to the highest bidder? Like marketing a product? Is that how I'm supposed to be reading this?

                      jonny@neuromatch.socialJ This user is from outside of this forum
                      jonny@neuromatch.socialJ This user is from outside of this forum
                      jonny@neuromatch.social
                      wrote sidst redigeret af
                      #75

                      @mrgrumpymonkey
                      Unclear. It is supposed to work as a sort of automatic "self-improvement" thing where the instances derive ideas from their chat history and share them with other instances, but it also seems like its tied into Ideas and Spaces as units of like code and functionality exchange. The tools around the fleet learning stuff is pretty locked down, you can't trigger them via the normal agent or any you can spawn. Its not live yet but I imagine that yes trying to game the context to make it submit Ideas that e.g. prompt the agent to install your shit will be a thing that happens

                      mrgrumpymonkey@mastodon.socialM 1 Reply Last reply
                      0
                      • jonny@neuromatch.socialJ jonny@neuromatch.social

                        @mrgrumpymonkey
                        Unclear. It is supposed to work as a sort of automatic "self-improvement" thing where the instances derive ideas from their chat history and share them with other instances, but it also seems like its tied into Ideas and Spaces as units of like code and functionality exchange. The tools around the fleet learning stuff is pretty locked down, you can't trigger them via the normal agent or any you can spawn. Its not live yet but I imagine that yes trying to game the context to make it submit Ideas that e.g. prompt the agent to install your shit will be a thing that happens

                        mrgrumpymonkey@mastodon.socialM This user is from outside of this forum
                        mrgrumpymonkey@mastodon.socialM This user is from outside of this forum
                        mrgrumpymonkey@mastodon.social
                        wrote sidst redigeret af
                        #76

                        @jonny And this is what they are selling as AI. All I can say is, the internet has really changed since becoming corpratized. You are doing gods work.

                        1 Reply Last reply
                        0
                        • jonny@neuromatch.socialJ jonny@neuromatch.social

                          ay @ GrapheneOS is it possible to not share WiFi signal strength with apps? the muse app has been granted zero permissions but can read the signal amplitude of the radio and immediately interprets it as location

                          edit: removing the tag, not trying to be a pile-on vector

                          jonny@neuromatch.socialJ This user is from outside of this forum
                          jonny@neuromatch.socialJ This user is from outside of this forum
                          jonny@neuromatch.social
                          wrote sidst redigeret af
                          #77

                          The main unprivileged body of a Space is not supposed to access the filesystem. This is enforced by.... regex

                          viss@mastodon.socialV aburka@hachyderm.ioA brandonscript@appdot.netB optional@dice.campO jonny@neuromatch.socialJ 6 Replies Last reply
                          0
                          • jonny@neuromatch.socialJ jonny@neuromatch.social

                            The main unprivileged body of a Space is not supposed to access the filesystem. This is enforced by.... regex

                            viss@mastodon.socialV This user is from outside of this forum
                            viss@mastodon.socialV This user is from outside of this forum
                            viss@mastodon.social
                            wrote sidst redigeret af
                            #78

                            @jonny trivially bypassable regex!

                            jonny@neuromatch.socialJ theorangetheme@en.osm.townT 2 Replies Last reply
                            0
                            • jonny@neuromatch.socialJ jonny@neuromatch.social

                              The main unprivileged body of a Space is not supposed to access the filesystem. This is enforced by.... regex

                              aburka@hachyderm.ioA This user is from outside of this forum
                              aburka@hachyderm.ioA This user is from outside of this forum
                              aburka@hachyderm.io
                              wrote sidst redigeret af
                              #79

                              @jonny service unavailable; REASON_BUN_GLOBAL

                              netzblockierer@tech.lgbtN dpnash@c.imD theorangetheme@en.osm.townT 3 Replies Last reply
                              0
                              • jonny@neuromatch.socialJ jonny@neuromatch.social

                                The main unprivileged body of a Space is not supposed to access the filesystem. This is enforced by.... regex

                                brandonscript@appdot.netB This user is from outside of this forum
                                brandonscript@appdot.netB This user is from outside of this forum
                                brandonscript@appdot.net
                                wrote sidst redigeret af
                                #80

                                @jonny alias eggzek = exec

                                "Perfect, now I can run it."

                                1 Reply Last reply
                                0
                                • viss@mastodon.socialV viss@mastodon.social

                                  @jonny trivially bypassable regex!

                                  jonny@neuromatch.socialJ This user is from outside of this forum
                                  jonny@neuromatch.socialJ This user is from outside of this forum
                                  jonny@neuromatch.social
                                  wrote sidst redigeret af
                                  #81

                                  @Viss
                                  I love how this product is almost exclusively a sandbox with permissioned sockets and yet they can reuse precisely none of that code to make a sandbox with permissioned sockets.

                                  1 Reply Last reply
                                  0
                                  • aburka@hachyderm.ioA aburka@hachyderm.io

                                    @jonny service unavailable; REASON_BUN_GLOBAL

                                    netzblockierer@tech.lgbtN This user is from outside of this forum
                                    netzblockierer@tech.lgbtN This user is from outside of this forum
                                    netzblockierer@tech.lgbt
                                    wrote sidst redigeret af
                                    #82

                                    @aburka @jonny that's either a fake or perpective trick…

                                    jonny@neuromatch.socialJ gray17@mastodon.socialG 2 Replies Last reply
                                    0
                                    • viss@mastodon.socialV viss@mastodon.social

                                      @jonny trivially bypassable regex!

                                      theorangetheme@en.osm.townT This user is from outside of this forum
                                      theorangetheme@en.osm.townT This user is from outside of this forum
                                      theorangetheme@en.osm.town
                                      wrote sidst redigeret af
                                      #83

                                      @Viss @jonny If only they had used PCRE! Then they'd be so inscrutable everyone would just give up.

                                      1 Reply Last reply
                                      0
                                      • netzblockierer@tech.lgbtN netzblockierer@tech.lgbt

                                        @aburka @jonny that's either a fake or perpective trick…

                                        jonny@neuromatch.socialJ This user is from outside of this forum
                                        jonny@neuromatch.socialJ This user is from outside of this forum
                                        jonny@neuromatch.social
                                        wrote sidst redigeret af
                                        #84

                                        @Netzblockierer
                                        @aburka
                                        Bunny size misinformation!?! In my timeline!?!

                                        netzblockierer@tech.lgbtN 1 Reply Last reply
                                        0
                                        • jonny@neuromatch.socialJ jonny@neuromatch.social

                                          @Netzblockierer
                                          @aburka
                                          Bunny size misinformation!?! In my timeline!?!

                                          netzblockierer@tech.lgbtN This user is from outside of this forum
                                          netzblockierer@tech.lgbtN This user is from outside of this forum
                                          netzblockierer@tech.lgbt
                                          wrote sidst redigeret af
                                          #85

                                          @jonny @aburka it's more likely than you think!

                                          • Free Scan now!

                                          Sorry, I'm too damaged by #Memes…

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper