Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. OK!

OK!

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
212 Indlæg 82 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • mrgrumpymonkey@mastodon.socialM mrgrumpymonkey@mastodon.social

    @jonny So, this fleet learning system is something to be sold to the highest bidder? Like marketing a product? Is that how I'm supposed to be reading this?

    jonny@neuromatch.socialJ This user is from outside of this forum
    jonny@neuromatch.socialJ This user is from outside of this forum
    jonny@neuromatch.social
    wrote sidst redigeret af
    #75

    @mrgrumpymonkey
    Unclear. It is supposed to work as a sort of automatic "self-improvement" thing where the instances derive ideas from their chat history and share them with other instances, but it also seems like its tied into Ideas and Spaces as units of like code and functionality exchange. The tools around the fleet learning stuff is pretty locked down, you can't trigger them via the normal agent or any you can spawn. Its not live yet but I imagine that yes trying to game the context to make it submit Ideas that e.g. prompt the agent to install your shit will be a thing that happens

    mrgrumpymonkey@mastodon.socialM 1 Reply Last reply
    0
    • jonny@neuromatch.socialJ jonny@neuromatch.social

      @mrgrumpymonkey
      Unclear. It is supposed to work as a sort of automatic "self-improvement" thing where the instances derive ideas from their chat history and share them with other instances, but it also seems like its tied into Ideas and Spaces as units of like code and functionality exchange. The tools around the fleet learning stuff is pretty locked down, you can't trigger them via the normal agent or any you can spawn. Its not live yet but I imagine that yes trying to game the context to make it submit Ideas that e.g. prompt the agent to install your shit will be a thing that happens

      mrgrumpymonkey@mastodon.socialM This user is from outside of this forum
      mrgrumpymonkey@mastodon.socialM This user is from outside of this forum
      mrgrumpymonkey@mastodon.social
      wrote sidst redigeret af
      #76

      @jonny And this is what they are selling as AI. All I can say is, the internet has really changed since becoming corpratized. You are doing gods work.

      1 Reply Last reply
      0
      • jonny@neuromatch.socialJ jonny@neuromatch.social

        ay @ GrapheneOS is it possible to not share WiFi signal strength with apps? the muse app has been granted zero permissions but can read the signal amplitude of the radio and immediately interprets it as location

        edit: removing the tag, not trying to be a pile-on vector

        jonny@neuromatch.socialJ This user is from outside of this forum
        jonny@neuromatch.socialJ This user is from outside of this forum
        jonny@neuromatch.social
        wrote sidst redigeret af
        #77

        The main unprivileged body of a Space is not supposed to access the filesystem. This is enforced by.... regex

        viss@mastodon.socialV aburka@hachyderm.ioA brandonscript@appdot.netB optional@dice.campO jonny@neuromatch.socialJ 6 Replies Last reply
        0
        • jonny@neuromatch.socialJ jonny@neuromatch.social

          The main unprivileged body of a Space is not supposed to access the filesystem. This is enforced by.... regex

          viss@mastodon.socialV This user is from outside of this forum
          viss@mastodon.socialV This user is from outside of this forum
          viss@mastodon.social
          wrote sidst redigeret af
          #78

          @jonny trivially bypassable regex!

          jonny@neuromatch.socialJ theorangetheme@en.osm.townT 2 Replies Last reply
          0
          • jonny@neuromatch.socialJ jonny@neuromatch.social

            The main unprivileged body of a Space is not supposed to access the filesystem. This is enforced by.... regex

            aburka@hachyderm.ioA This user is from outside of this forum
            aburka@hachyderm.ioA This user is from outside of this forum
            aburka@hachyderm.io
            wrote sidst redigeret af
            #79

            @jonny service unavailable; REASON_BUN_GLOBAL

            netzblockierer@tech.lgbtN dpnash@c.imD theorangetheme@en.osm.townT 3 Replies Last reply
            0
            • jonny@neuromatch.socialJ jonny@neuromatch.social

              The main unprivileged body of a Space is not supposed to access the filesystem. This is enforced by.... regex

              brandonscript@appdot.netB This user is from outside of this forum
              brandonscript@appdot.netB This user is from outside of this forum
              brandonscript@appdot.net
              wrote sidst redigeret af
              #80

              @jonny alias eggzek = exec

              "Perfect, now I can run it."

              1 Reply Last reply
              0
              • viss@mastodon.socialV viss@mastodon.social

                @jonny trivially bypassable regex!

                jonny@neuromatch.socialJ This user is from outside of this forum
                jonny@neuromatch.socialJ This user is from outside of this forum
                jonny@neuromatch.social
                wrote sidst redigeret af
                #81

                @Viss
                I love how this product is almost exclusively a sandbox with permissioned sockets and yet they can reuse precisely none of that code to make a sandbox with permissioned sockets.

                1 Reply Last reply
                0
                • aburka@hachyderm.ioA aburka@hachyderm.io

                  @jonny service unavailable; REASON_BUN_GLOBAL

                  netzblockierer@tech.lgbtN This user is from outside of this forum
                  netzblockierer@tech.lgbtN This user is from outside of this forum
                  netzblockierer@tech.lgbt
                  wrote sidst redigeret af
                  #82

                  @aburka @jonny that's either a fake or perpective trick…

                  jonny@neuromatch.socialJ gray17@mastodon.socialG 2 Replies Last reply
                  0
                  • viss@mastodon.socialV viss@mastodon.social

                    @jonny trivially bypassable regex!

                    theorangetheme@en.osm.townT This user is from outside of this forum
                    theorangetheme@en.osm.townT This user is from outside of this forum
                    theorangetheme@en.osm.town
                    wrote sidst redigeret af
                    #83

                    @Viss @jonny If only they had used PCRE! Then they'd be so inscrutable everyone would just give up.

                    1 Reply Last reply
                    0
                    • netzblockierer@tech.lgbtN netzblockierer@tech.lgbt

                      @aburka @jonny that's either a fake or perpective trick…

                      jonny@neuromatch.socialJ This user is from outside of this forum
                      jonny@neuromatch.socialJ This user is from outside of this forum
                      jonny@neuromatch.social
                      wrote sidst redigeret af
                      #84

                      @Netzblockierer
                      @aburka
                      Bunny size misinformation!?! In my timeline!?!

                      netzblockierer@tech.lgbtN 1 Reply Last reply
                      0
                      • jonny@neuromatch.socialJ jonny@neuromatch.social

                        @Netzblockierer
                        @aburka
                        Bunny size misinformation!?! In my timeline!?!

                        netzblockierer@tech.lgbtN This user is from outside of this forum
                        netzblockierer@tech.lgbtN This user is from outside of this forum
                        netzblockierer@tech.lgbt
                        wrote sidst redigeret af
                        #85

                        @jonny @aburka it's more likely than you think!

                        • Free Scan now!

                        Sorry, I'm too damaged by #Memes…

                        1 Reply Last reply
                        0
                        • aburka@hachyderm.ioA aburka@hachyderm.io

                          @jonny service unavailable; REASON_BUN_GLOBAL

                          dpnash@c.imD This user is from outside of this forum
                          dpnash@c.imD This user is from outside of this forum
                          dpnash@c.im
                          wrote sidst redigeret af
                          #86

                          @aburka @jonny

                          When your very small bunny suddenly becomes gigantic:

                          BUNDERFLOW_ERROR

                          1 Reply Last reply
                          0
                          • aburka@hachyderm.ioA aburka@hachyderm.io

                            @jonny service unavailable; REASON_BUN_GLOBAL

                            theorangetheme@en.osm.townT This user is from outside of this forum
                            theorangetheme@en.osm.townT This user is from outside of this forum
                            theorangetheme@en.osm.town
                            wrote sidst redigeret af
                            #87

                            @aburka @jonny REASON_BUN_LOCAL

                            1 Reply Last reply
                            0
                            • toadjaune@hostux.socialT toadjaune@hostux.social

                              @GrapheneOS @jonny wasn't there a story, a few years ago, where uber would make you pay more if you had little battery left, because you'd be more desperate ?

                              I seem to recall some changes were made by android after that. It would seem I was wrong ?

                              toadjaune@hostux.socialT This user is from outside of this forum
                              toadjaune@hostux.socialT This user is from outside of this forum
                              toadjaune@hostux.social
                              wrote sidst redigeret af
                              #88

                              @GrapheneOS @jonny huh, apparently they've been suspected again, recently https://www.vice.com/en/article/uber-surge-pricing-phone-battery/

                              1 Reply Last reply
                              0
                              • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                                @jonny The Location permission combined with the right low-level permission requests provides access to a lot of information on the nearby Wi-Fi networks. Without the location permission, there's only info on the signal strength of the best available currently connected cellular and WI-Fi networks.

                                It would definitely be possible for us to change this by offering having spoofed values. However, it would make no sense to work on this when far more important privacy issues exist.

                                adhdruid@infosec.exchangeA This user is from outside of this forum
                                adhdruid@infosec.exchangeA This user is from outside of this forum
                                adhdruid@infosec.exchange
                                wrote sidst redigeret af
                                #89

                                @GrapheneOS Or you could argue that these are fundamentals. You can choose not to use apps, browsers, etc. You can’t choose not to use the battery or network.

                                @jonny

                                grapheneos@grapheneos.socialG adhdruid@infosec.exchangeA 2 Replies Last reply
                                0
                                • jonny@neuromatch.socialJ jonny@neuromatch.social

                                  The main unprivileged body of a Space is not supposed to access the filesystem. This is enforced by.... regex

                                  optional@dice.campO This user is from outside of this forum
                                  optional@dice.campO This user is from outside of this forum
                                  optional@dice.camp
                                  wrote sidst redigeret af
                                  #90

                                  @jonny the takeaway of your thread seems to be that regex can truly solve *any* problem. The duct tape of programming 🏆️

                                  1 Reply Last reply
                                  0
                                  • jonny@neuromatch.socialJ jonny@neuromatch.social

                                    RE: https://neuromatch.social/@jonny/117339825958098508

                                    OK! Meta evaluated this as intended behavior, not applicable for a bug bounty, so therefore responsible disclosure no longer applies so here goes:

                                    any process run within the VM can access the socket that provides inference with no attribution mechanism. This includes raw inference  with arbitrary system and user prompts, as well as the ability to spawn agents with a toolset labeled as being for the "spaces" feature, which we will come back to.

                                    This amounts to a horizontally contagious token and information harvesting bug being labeled as intended behavior.

                                    Splitting details into new thread below

                                    wcbdata@vis.socialW This user is from outside of this forum
                                    wcbdata@vis.socialW This user is from outside of this forum
                                    wcbdata@vis.social
                                    wrote sidst redigeret af
                                    #91

                                    @jonny This whole thread is so life-affirming. ❤️

                                    1 Reply Last reply
                                    0
                                    • jonny@neuromatch.socialJ jonny@neuromatch.social

                                      @fancysandwiches i am working on this but cannot publicly disclose any progress until meta decides whether or not it is payable as a bug bounty

                                      jakimfett@masto.hackers.townJ This user is from outside of this forum
                                      jakimfett@masto.hackers.townJ This user is from outside of this forum
                                      jakimfett@masto.hackers.town
                                      wrote sidst redigeret af
                                      #92

                                      @jonny @fancysandwiches and, how many of the other quirks that did hit the news cycle are already from this being done lol

                                      1 Reply Last reply
                                      0
                                      • jonny@neuromatch.socialJ jonny@neuromatch.social

                                        The main unprivileged body of a Space is not supposed to access the filesystem. This is enforced by.... regex

                                        jonny@neuromatch.socialJ This user is from outside of this forum
                                        jonny@neuromatch.socialJ This user is from outside of this forum
                                        jonny@neuromatch.social
                                        wrote sidst redigeret af
                                        #93

                                        So again, how could one end up with a compromised package on a muse instance? Wouldn't that have to be some sophisticated supply chain attack? Nope! Muse attempted to install packages from PyPI, which caused a card to pop up on the user interface asking for me to approve connecting to PyPI. I was not watching the screen, so the request timed out. It then proceeded to raw dog a list of PyPI mirrors from its training data. It couldn't figure out how to use uv, so it then generated a wheel download script that would bypass any lockfile that validated packages by hash. It forked that to the background, forgot about it, and then proceeded to attempt to manually download the specified dependencies across a dozen or two tool calls with direct URL construction over whatever mirrors returned something.

                                        Connecting to PyPI required explicit approval, but connecting to the mirrors didn't, and so i wouldn't have even noticed if i didn't always read the raw message stream rather than the interface output because you can never trust these things. When I stopped it and said "don't connect to random pypi mirrors wtf are you doing" it 1) lied about PyPI being unreachable because it has no visibility into the permission status and by pattern words should be there, 2) told me that two of the mirrors it tried were official PyPI mirrors, and 3) presented randomly wandering PyPI indexes as if it was a normal thing to do. If I wasn't a python developer and knew already there are no official PyPI mirrors, and also actively investigating how its egress permissions worked, I probably would have just accepted that.

                                        So anyway, unless you are a user with lots of direct domain knowledge about a language packaging ecosystem who is reading the entire raw message log as it happens, muse will aggressively download random shit from the internet and execute it.

                                        viss@mastodon.socialV happyborg@fosstodon.orgH jonny@neuromatch.socialJ bstacey@icosahedron.websiteB m0yng@mastodon.radioM 7 Replies Last reply
                                        0
                                        • jonny@neuromatch.socialJ jonny@neuromatch.social

                                          So again, how could one end up with a compromised package on a muse instance? Wouldn't that have to be some sophisticated supply chain attack? Nope! Muse attempted to install packages from PyPI, which caused a card to pop up on the user interface asking for me to approve connecting to PyPI. I was not watching the screen, so the request timed out. It then proceeded to raw dog a list of PyPI mirrors from its training data. It couldn't figure out how to use uv, so it then generated a wheel download script that would bypass any lockfile that validated packages by hash. It forked that to the background, forgot about it, and then proceeded to attempt to manually download the specified dependencies across a dozen or two tool calls with direct URL construction over whatever mirrors returned something.

                                          Connecting to PyPI required explicit approval, but connecting to the mirrors didn't, and so i wouldn't have even noticed if i didn't always read the raw message stream rather than the interface output because you can never trust these things. When I stopped it and said "don't connect to random pypi mirrors wtf are you doing" it 1) lied about PyPI being unreachable because it has no visibility into the permission status and by pattern words should be there, 2) told me that two of the mirrors it tried were official PyPI mirrors, and 3) presented randomly wandering PyPI indexes as if it was a normal thing to do. If I wasn't a python developer and knew already there are no official PyPI mirrors, and also actively investigating how its egress permissions worked, I probably would have just accepted that.

                                          So anyway, unless you are a user with lots of direct domain knowledge about a language packaging ecosystem who is reading the entire raw message log as it happens, muse will aggressively download random shit from the internet and execute it.

                                          viss@mastodon.socialV This user is from outside of this forum
                                          viss@mastodon.socialV This user is from outside of this forum
                                          viss@mastodon.social
                                          wrote sidst redigeret af
                                          #94

                                          @jonny is that your interface? did you make a harness for this thing or is this muses web interface?

                                          viss@mastodon.socialV jonny@neuromatch.socialJ 2 Replies Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper