<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I need people to understand that stuff like this will keep happening, for two reasons:]]></title><description><![CDATA[<p class="quote-inline">RE: <a href="https://cyberplace.social/@GossiTheDog/116676826944489315" rel="nofollow noopener"><span>https://</span><span>cyberplace.social/@GossiTheDog</span><span>/116676826944489315</span></a></p><p>I need people to understand that stuff like this will keep happening, for two reasons:</p><p>1. To be useful these chatbots need to have full access to everything they are supposed to "manage"; otherwise they are pointless.</p><p>2. Trying to stop prompt injection is basically trying to semantically filter natural language.</p><p>These tools have no model of the world, no ontology to anchor any "safety instructions" in. There will always be a way to talk one's way around them.</p><p><a href="https://mstdn.social/tags/InfoSec" rel="tag">#<span>InfoSec</span></a></p>]]></description><link>https://forum.fedi.dk/topic/bbe0313d-9377-417e-b0e2-7dbbd79de363/i-need-people-to-understand-that-stuff-like-this-will-keep-happening-for-two-reasons</link><generator>RSS for Node</generator><lastBuildDate>Sun, 14 Jun 2026 15:48:09 GMT</lastBuildDate><atom:link href="https://forum.fedi.dk/topic/bbe0313d-9377-417e-b0e2-7dbbd79de363.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 02 Jun 2026 01:50:14 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I need people to understand that stuff like this will keep happening, for two reasons: on Tue, 02 Jun 2026 04:10:37 GMT]]></title><description><![CDATA[<p><span><a href="/user/rysiek%40mstdn.social">@<span>rysiek</span></a></span> I would assume that anything a chatbot has permission to do, will get done, given enough time. Instructions to an LLM are just text which can and will get ignored. Also the chatbot can say that they did something even though no action has taken place. </p><p>It's all just meaningless text to the LLM.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.gamedev.place/users/dominikg/statuses/116678553584890189</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.gamedev.place/users/dominikg/statuses/116678553584890189</guid><dc:creator><![CDATA[dominikg@mastodon.gamedev.place]]></dc:creator><pubDate>Tue, 02 Jun 2026 04:10:37 GMT</pubDate></item><item><title><![CDATA[Reply to I need people to understand that stuff like this will keep happening, for two reasons: on Tue, 02 Jun 2026 03:00:37 GMT]]></title><description><![CDATA[<p><span><a href="/user/rysiek%40mstdn.social">@<span>rysiek</span></a></span> <span><a href="/user/paco%40infosec.exchange">@<span>paco</span></a></span> so you’re telling me they treat security as seriously as Meta treats privacy?</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.online/users/dgodon/statuses/116678278334254862</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.online/users/dgodon/statuses/116678278334254862</guid><dc:creator><![CDATA[dgodon@mastodon.online]]></dc:creator><pubDate>Tue, 02 Jun 2026 03:00:37 GMT</pubDate></item><item><title><![CDATA[Reply to I need people to understand that stuff like this will keep happening, for two reasons: on Tue, 02 Jun 2026 02:55:34 GMT]]></title><description><![CDATA[<p><span><a href="/user/rysiek%40mstdn.social">@<span>rysiek</span></a></span> </p><p>wait. so giving 4 year olds in the playground assault rifles can't ever be made safe? say it isn't so...</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/paul_ipv6/statuses/116678258515907416</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/paul_ipv6/statuses/116678258515907416</guid><dc:creator><![CDATA[paul_ipv6@infosec.exchange]]></dc:creator><pubDate>Tue, 02 Jun 2026 02:55:34 GMT</pubDate></item><item><title><![CDATA[Reply to I need people to understand that stuff like this will keep happening, for two reasons: on Tue, 02 Jun 2026 02:45:14 GMT]]></title><description><![CDATA[<p><span><a href="/user/paco%40infosec.exchange">@<span>paco</span></a></span> <span><a href="/user/rysiek%40mstdn.social">@<span>rysiek</span></a></span> "putting security above all else" = "instructing the code bots to only write secure code." Then telling them again because they *really* mean it this time!</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/EdCates/statuses/116678217869009389</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/EdCates/statuses/116678217869009389</guid><dc:creator><![CDATA[edcates@mastodon.social]]></dc:creator><pubDate>Tue, 02 Jun 2026 02:45:14 GMT</pubDate></item><item><title><![CDATA[Reply to I need people to understand that stuff like this will keep happening, for two reasons: on Tue, 02 Jun 2026 02:34:20 GMT]]></title><description><![CDATA[<p><span><a href="/user/rysiek%40mstdn.social" rel="nofollow noopener">@<span>rysiek</span></a></span> “We are doubling down on this very important work, putting security above all else — before all other features and investments,” Nadella said before adding “at least for the rest of this week. Maybe even a whole month.” <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f61c.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--stuck_out_tongue_winking_eye" style="height:23px;width:auto;vertical-align:middle" title="😜" alt="😜" /></p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/paco/statuses/116678175024246176</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/paco/statuses/116678175024246176</guid><dc:creator><![CDATA[paco@infosec.exchange]]></dc:creator><pubDate>Tue, 02 Jun 2026 02:34:20 GMT</pubDate></item><item><title><![CDATA[Reply to I need people to understand that stuff like this will keep happening, for two reasons: on Tue, 02 Jun 2026 02:30:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/paco%40infosec.exchange">@<span>paco</span></a></span> Satya Nadella made sure Microsoft focused on security over 2 years ago, after all!<br /><a href="https://www.geekwire.com/2024/haunted-by-repeated-breaches-microsoft-is-putting-security-above-all-else-vows-ceo-satya-nadella/" rel="nofollow noopener"><span>https://www.</span><span>geekwire.com/2024/haunted-by-r</span><span>epeated-breaches-microsoft-is-putting-security-above-all-else-vows-ceo-satya-nadella/</span></a></p>]]></description><link>https://forum.fedi.dk/post/https://mstdn.social/users/rysiek/statuses/116678158040365874</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mstdn.social/users/rysiek/statuses/116678158040365874</guid><dc:creator><![CDATA[rysiek@mstdn.social]]></dc:creator><pubDate>Tue, 02 Jun 2026 02:30:01 GMT</pubDate></item><item><title><![CDATA[Reply to I need people to understand that stuff like this will keep happening, for two reasons: on Tue, 02 Jun 2026 02:27:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/rysiek%40mstdn.social" rel="nofollow noopener">@<span>rysiek</span></a></span> At the bottom of that article is a headline for suggested next article:<br />“Also read: Microsoft is making Teams secure by default, automatically enabling new protections to reduce AI-driven threats.”</p><p>It wasn’t secure by default? But they’re gonna change that?</p><p>And I love how it flip flops from rock solid certainty “secure by default” to corporate weasel-speak “reduce AI-driven threats” in the span of a single sentence.</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/paco/statuses/116678149025087121</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/paco/statuses/116678149025087121</guid><dc:creator><![CDATA[paco@infosec.exchange]]></dc:creator><pubDate>Tue, 02 Jun 2026 02:27:44 GMT</pubDate></item><item><title><![CDATA[Reply to I need people to understand that stuff like this will keep happening, for two reasons: on Tue, 02 Jun 2026 02:11:26 GMT]]></title><description><![CDATA[<p><span><a href="/user/dancast%40wandering.shop">@<span>dancast</span></a></span> oh yeah, they probably got generated by it, and in a way they always pass. <img class="not-responsive emoji" src="https://media.mstdn.social/custom_emojis/images/000/001/975/original/26d4d98effc18187.png" title=":blobcatcoffee:" /></p>]]></description><link>https://forum.fedi.dk/post/https://mstdn.social/users/rysiek/statuses/116678084969695067</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mstdn.social/users/rysiek/statuses/116678084969695067</guid><dc:creator><![CDATA[rysiek@mstdn.social]]></dc:creator><pubDate>Tue, 02 Jun 2026 02:11:26 GMT</pubDate></item><item><title><![CDATA[Reply to I need people to understand that stuff like this will keep happening, for two reasons: on Tue, 02 Jun 2026 02:10:40 GMT]]></title><description><![CDATA[<p><span><a href="/user/rysiek%40mstdn.social">@<span>rysiek</span></a></span> I am sure it passed its unit tests.</p>]]></description><link>https://forum.fedi.dk/post/https://wandering.shop/users/dancast/statuses/116678081925855557</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://wandering.shop/users/dancast/statuses/116678081925855557</guid><dc:creator><![CDATA[dancast@wandering.shop]]></dc:creator><pubDate>Tue, 02 Jun 2026 02:10:40 GMT</pubDate></item><item><title><![CDATA[Reply to I need people to understand that stuff like this will keep happening, for two reasons: on Tue, 02 Jun 2026 02:10:26 GMT]]></title><description><![CDATA[<p><span><a href="https://eigenmagic.net/@arichtman">@<span>arichtman</span></a></span> because surely there will be no way to prompt-inject a request to write a malicious python script and run it. <img class="not-responsive emoji" src="https://media.mstdn.social/custom_emojis/images/000/276/008/original/1ebf90442c55f393.gif" title=":blobcatroll:" /></p>]]></description><link>https://forum.fedi.dk/post/https://mstdn.social/users/rysiek/statuses/116678080995906716</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mstdn.social/users/rysiek/statuses/116678080995906716</guid><dc:creator><![CDATA[rysiek@mstdn.social]]></dc:creator><pubDate>Tue, 02 Jun 2026 02:10:26 GMT</pubDate></item><item><title><![CDATA[Reply to I need people to understand that stuff like this will keep happening, for two reasons: on Tue, 02 Jun 2026 02:08:52 GMT]]></title><description><![CDATA[<p>We are several years into this and the biggest companies peddling these tools still cannot figure out how to make their products not fall for advanced cyberattack techniques like *checks notes* asking nicely again.</p><p>Microslop Slopilot had (has?) a similar issue – Reprompt attack simply repeated the malicious prompt in a query parameter: <br /><a href="https://www.techrepublic.com/article/news-reprompt-attack-microsoft-copilot/" rel="nofollow noopener"><span>https://www.</span><span>techrepublic.com/article/news-</span><span>reprompt-attack-microsoft-copilot/</span></a></p><p>These are not going away.</p>]]></description><link>https://forum.fedi.dk/post/https://mstdn.social/users/rysiek/statuses/116678074862477010</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mstdn.social/users/rysiek/statuses/116678074862477010</guid><dc:creator><![CDATA[rysiek@mstdn.social]]></dc:creator><pubDate>Tue, 02 Jun 2026 02:08:52 GMT</pubDate></item><item><title><![CDATA[Reply to I need people to understand that stuff like this will keep happening, for two reasons: on Tue, 02 Jun 2026 02:00:10 GMT]]></title><description><![CDATA[<p>One way out of this is compartmentalization, hard-limiting chatbot's access to certain resources. But that defeats the purpose of the chatbot – you can't have a chatbot that manages your mail without giving that chatbot access to your mail...</p><p>Another is to move towards more formalized instructions, which can then be properly constrained by permissions etc. But then you're re-inventing programming languages and access control, again defeating the purpose of a natural-language-processing chatbot.</p>]]></description><link>https://forum.fedi.dk/post/https://mstdn.social/users/rysiek/statuses/116678040636647436</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mstdn.social/users/rysiek/statuses/116678040636647436</guid><dc:creator><![CDATA[rysiek@mstdn.social]]></dc:creator><pubDate>Tue, 02 Jun 2026 02:00:10 GMT</pubDate></item><item><title><![CDATA[Reply to I need people to understand that stuff like this will keep happening, for two reasons: on Tue, 02 Jun 2026 01:55:53 GMT]]></title><description><![CDATA[<p><span><a href="/user/rysiek%40mstdn.social">@<span>rysiek</span></a></span>  Big sorry <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f605.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--sweat_smile" style="height:23px;width:auto;vertical-align:middle" title="😅" alt="😅" /> — you are totally correct. I hadn't thought about that <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f64f.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--pray" style="height:23px;width:auto;vertical-align:middle" title="🙏" alt="🙏" /> <a href="https://mas.to/tags/MeaCulpa" rel="tag">#<span>MeaCulpa</span></a> xD <a href="https://mas.to/tags/sorry" rel="tag">#<span>sorry</span></a></p><p>And yeah, their system is absolutely garbage from a security standpoint; they know it and still leave it like that… They could have disabled number visibility a long time ago and also could have made their AI garbage opt-in instead of enforced… And they still use the old double ratchet…  And many, many, many more things.</p>]]></description><link>https://forum.fedi.dk/post/https://mas.to/users/nemo/statuses/116678023825299035</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mas.to/users/nemo/statuses/116678023825299035</guid><dc:creator><![CDATA[nemo@mas.to]]></dc:creator><pubDate>Tue, 02 Jun 2026 01:55:53 GMT</pubDate></item><item><title><![CDATA[Reply to I need people to understand that stuff like this will keep happening, for two reasons: on Tue, 02 Jun 2026 01:54:32 GMT]]></title><description><![CDATA[<p><span><a href="/user/nemo%40mas.to">@<span>nemo</span></a></span> I don't think blaming the victim here is the way to go. Meta created a hilariously insecure system, this is on them.</p>]]></description><link>https://forum.fedi.dk/post/https://mstdn.social/users/rysiek/statuses/116678018467228131</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mstdn.social/users/rysiek/statuses/116678018467228131</guid><dc:creator><![CDATA[rysiek@mstdn.social]]></dc:creator><pubDate>Tue, 02 Jun 2026 01:54:32 GMT</pubDate></item><item><title><![CDATA[Reply to I need people to understand that stuff like this will keep happening, for two reasons: on Tue, 02 Jun 2026 01:53:49 GMT]]></title><description><![CDATA[<p><span><a href="/user/rysiek%40mstdn.social">@<span>rysiek</span></a></span> Apparently it could have been prevented with a WhatsApp PIN. Why isn't Obama using a WhatsApp PIN or the strict account settings, which also enable a PIN by default? <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f937.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--shrug" style="height:23px;width:auto;vertical-align:middle" title="🤷" alt="🤷" /> Btw I don't use WhatsApp; still trying to learn about it because many people use it.</p>]]></description><link>https://forum.fedi.dk/post/https://mas.to/users/nemo/statuses/116678015696965592</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mas.to/users/nemo/statuses/116678015696965592</guid><dc:creator><![CDATA[nemo@mas.to]]></dc:creator><pubDate>Tue, 02 Jun 2026 01:53:49 GMT</pubDate></item></channel></rss>