Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. I need people to understand that stuff like this will keep happening, for two reasons:

I need people to understand that stuff like this will keep happening, for two reasons:

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
infosec
16 Indlæg 8 Posters 30 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • rysiek@mstdn.socialR This user is from outside of this forum
    rysiek@mstdn.socialR This user is from outside of this forum
    rysiek@mstdn.social
    wrote sidst redigeret af
    #1

    RE: https://cyberplace.social/@GossiTheDog/116676826944489315

    I need people to understand that stuff like this will keep happening, for two reasons:

    1. To be useful these chatbots need to have full access to everything they are supposed to "manage"; otherwise they are pointless.

    2. Trying to stop prompt injection is basically trying to semantically filter natural language.

    These tools have no model of the world, no ontology to anchor any "safety instructions" in. There will always be a way to talk one's way around them.

    #InfoSec

    nemo@mas.toN rysiek@mstdn.socialR dancast@wandering.shopD paul_ipv6@infosec.exchangeP 4 Replies Last reply
    1
    0
    • rysiek@mstdn.socialR rysiek@mstdn.social

      RE: https://cyberplace.social/@GossiTheDog/116676826944489315

      I need people to understand that stuff like this will keep happening, for two reasons:

      1. To be useful these chatbots need to have full access to everything they are supposed to "manage"; otherwise they are pointless.

      2. Trying to stop prompt injection is basically trying to semantically filter natural language.

      These tools have no model of the world, no ontology to anchor any "safety instructions" in. There will always be a way to talk one's way around them.

      #InfoSec

      nemo@mas.toN This user is from outside of this forum
      nemo@mas.toN This user is from outside of this forum
      nemo@mas.to
      wrote sidst redigeret af
      #2

      @rysiek Apparently it could have been prevented with a WhatsApp PIN. Why isn't Obama using a WhatsApp PIN or the strict account settings, which also enable a PIN by default? 🤷 Btw I don't use WhatsApp; still trying to learn about it because many people use it.

      rysiek@mstdn.socialR 1 Reply Last reply
      0
      • nemo@mas.toN nemo@mas.to

        @rysiek Apparently it could have been prevented with a WhatsApp PIN. Why isn't Obama using a WhatsApp PIN or the strict account settings, which also enable a PIN by default? 🤷 Btw I don't use WhatsApp; still trying to learn about it because many people use it.

        rysiek@mstdn.socialR This user is from outside of this forum
        rysiek@mstdn.socialR This user is from outside of this forum
        rysiek@mstdn.social
        wrote sidst redigeret af
        #3

        @nemo I don't think blaming the victim here is the way to go. Meta created a hilariously insecure system, this is on them.

        nemo@mas.toN 1 Reply Last reply
        0
        • rysiek@mstdn.socialR rysiek@mstdn.social

          @nemo I don't think blaming the victim here is the way to go. Meta created a hilariously insecure system, this is on them.

          nemo@mas.toN This user is from outside of this forum
          nemo@mas.toN This user is from outside of this forum
          nemo@mas.to
          wrote sidst redigeret af
          #4

          @rysiek Big sorry 😅 — you are totally correct. I hadn't thought about that 🙏 #MeaCulpa xD #sorry

          And yeah, their system is absolutely garbage from a security standpoint; they know it and still leave it like that… They could have disabled number visibility a long time ago and also could have made their AI garbage opt-in instead of enforced… And they still use the old double ratchet… And many, many, many more things.

          1 Reply Last reply
          0
          • rysiek@mstdn.socialR rysiek@mstdn.social

            RE: https://cyberplace.social/@GossiTheDog/116676826944489315

            I need people to understand that stuff like this will keep happening, for two reasons:

            1. To be useful these chatbots need to have full access to everything they are supposed to "manage"; otherwise they are pointless.

            2. Trying to stop prompt injection is basically trying to semantically filter natural language.

            These tools have no model of the world, no ontology to anchor any "safety instructions" in. There will always be a way to talk one's way around them.

            #InfoSec

            rysiek@mstdn.socialR This user is from outside of this forum
            rysiek@mstdn.socialR This user is from outside of this forum
            rysiek@mstdn.social
            wrote sidst redigeret af
            #5

            One way out of this is compartmentalization, hard-limiting chatbot's access to certain resources. But that defeats the purpose of the chatbot – you can't have a chatbot that manages your mail without giving that chatbot access to your mail...

            Another is to move towards more formalized instructions, which can then be properly constrained by permissions etc. But then you're re-inventing programming languages and access control, again defeating the purpose of a natural-language-processing chatbot.

            rysiek@mstdn.socialR dominikg@mastodon.gamedev.placeD 2 Replies Last reply
            0
            • rysiek@mstdn.socialR rysiek@mstdn.social

              One way out of this is compartmentalization, hard-limiting chatbot's access to certain resources. But that defeats the purpose of the chatbot – you can't have a chatbot that manages your mail without giving that chatbot access to your mail...

              Another is to move towards more formalized instructions, which can then be properly constrained by permissions etc. But then you're re-inventing programming languages and access control, again defeating the purpose of a natural-language-processing chatbot.

              rysiek@mstdn.socialR This user is from outside of this forum
              rysiek@mstdn.socialR This user is from outside of this forum
              rysiek@mstdn.social
              wrote sidst redigeret af
              #6

              We are several years into this and the biggest companies peddling these tools still cannot figure out how to make their products not fall for advanced cyberattack techniques like *checks notes* asking nicely again.

              Microslop Slopilot had (has?) a similar issue – Reprompt attack simply repeated the malicious prompt in a query parameter:
              https://www.techrepublic.com/article/news-reprompt-attack-microsoft-copilot/

              These are not going away.

              paco@infosec.exchangeP 1 Reply Last reply
              0
              • rysiek@mstdn.socialR This user is from outside of this forum
                rysiek@mstdn.socialR This user is from outside of this forum
                rysiek@mstdn.social
                wrote sidst redigeret af
                #7

                @arichtman because surely there will be no way to prompt-inject a request to write a malicious python script and run it.

                1 Reply Last reply
                0
                • rysiek@mstdn.socialR rysiek@mstdn.social

                  RE: https://cyberplace.social/@GossiTheDog/116676826944489315

                  I need people to understand that stuff like this will keep happening, for two reasons:

                  1. To be useful these chatbots need to have full access to everything they are supposed to "manage"; otherwise they are pointless.

                  2. Trying to stop prompt injection is basically trying to semantically filter natural language.

                  These tools have no model of the world, no ontology to anchor any "safety instructions" in. There will always be a way to talk one's way around them.

                  #InfoSec

                  dancast@wandering.shopD This user is from outside of this forum
                  dancast@wandering.shopD This user is from outside of this forum
                  dancast@wandering.shop
                  wrote sidst redigeret af
                  #8

                  @rysiek I am sure it passed its unit tests.

                  rysiek@mstdn.socialR 1 Reply Last reply
                  0
                  • dancast@wandering.shopD dancast@wandering.shop

                    @rysiek I am sure it passed its unit tests.

                    rysiek@mstdn.socialR This user is from outside of this forum
                    rysiek@mstdn.socialR This user is from outside of this forum
                    rysiek@mstdn.social
                    wrote sidst redigeret af
                    #9

                    @dancast oh yeah, they probably got generated by it, and in a way they always pass.

                    1 Reply Last reply
                    0
                    • rysiek@mstdn.socialR rysiek@mstdn.social

                      We are several years into this and the biggest companies peddling these tools still cannot figure out how to make their products not fall for advanced cyberattack techniques like *checks notes* asking nicely again.

                      Microslop Slopilot had (has?) a similar issue – Reprompt attack simply repeated the malicious prompt in a query parameter:
                      https://www.techrepublic.com/article/news-reprompt-attack-microsoft-copilot/

                      These are not going away.

                      paco@infosec.exchangeP This user is from outside of this forum
                      paco@infosec.exchangeP This user is from outside of this forum
                      paco@infosec.exchange
                      wrote sidst redigeret af
                      #10

                      @rysiek At the bottom of that article is a headline for suggested next article:
                      “Also read: Microsoft is making Teams secure by default, automatically enabling new protections to reduce AI-driven threats.”

                      It wasn’t secure by default? But they’re gonna change that?

                      And I love how it flip flops from rock solid certainty “secure by default” to corporate weasel-speak “reduce AI-driven threats” in the span of a single sentence.

                      rysiek@mstdn.socialR 1 Reply Last reply
                      0
                      • paco@infosec.exchangeP paco@infosec.exchange

                        @rysiek At the bottom of that article is a headline for suggested next article:
                        “Also read: Microsoft is making Teams secure by default, automatically enabling new protections to reduce AI-driven threats.”

                        It wasn’t secure by default? But they’re gonna change that?

                        And I love how it flip flops from rock solid certainty “secure by default” to corporate weasel-speak “reduce AI-driven threats” in the span of a single sentence.

                        rysiek@mstdn.socialR This user is from outside of this forum
                        rysiek@mstdn.socialR This user is from outside of this forum
                        rysiek@mstdn.social
                        wrote sidst redigeret af
                        #11

                        @paco Satya Nadella made sure Microsoft focused on security over 2 years ago, after all!
                        https://www.geekwire.com/2024/haunted-by-repeated-breaches-microsoft-is-putting-security-above-all-else-vows-ceo-satya-nadella/

                        paco@infosec.exchangeP dgodon@mastodon.onlineD 2 Replies Last reply
                        0
                        • rysiek@mstdn.socialR rysiek@mstdn.social

                          @paco Satya Nadella made sure Microsoft focused on security over 2 years ago, after all!
                          https://www.geekwire.com/2024/haunted-by-repeated-breaches-microsoft-is-putting-security-above-all-else-vows-ceo-satya-nadella/

                          paco@infosec.exchangeP This user is from outside of this forum
                          paco@infosec.exchangeP This user is from outside of this forum
                          paco@infosec.exchange
                          wrote sidst redigeret af
                          #12

                          @rysiek “We are doubling down on this very important work, putting security above all else — before all other features and investments,” Nadella said before adding “at least for the rest of this week. Maybe even a whole month.” 😜

                          edcates@mastodon.socialE 1 Reply Last reply
                          0
                          • paco@infosec.exchangeP paco@infosec.exchange

                            @rysiek “We are doubling down on this very important work, putting security above all else — before all other features and investments,” Nadella said before adding “at least for the rest of this week. Maybe even a whole month.” 😜

                            edcates@mastodon.socialE This user is from outside of this forum
                            edcates@mastodon.socialE This user is from outside of this forum
                            edcates@mastodon.social
                            wrote sidst redigeret af
                            #13

                            @paco @rysiek "putting security above all else" = "instructing the code bots to only write secure code." Then telling them again because they *really* mean it this time!

                            1 Reply Last reply
                            0
                            • rysiek@mstdn.socialR rysiek@mstdn.social

                              RE: https://cyberplace.social/@GossiTheDog/116676826944489315

                              I need people to understand that stuff like this will keep happening, for two reasons:

                              1. To be useful these chatbots need to have full access to everything they are supposed to "manage"; otherwise they are pointless.

                              2. Trying to stop prompt injection is basically trying to semantically filter natural language.

                              These tools have no model of the world, no ontology to anchor any "safety instructions" in. There will always be a way to talk one's way around them.

                              #InfoSec

                              paul_ipv6@infosec.exchangeP This user is from outside of this forum
                              paul_ipv6@infosec.exchangeP This user is from outside of this forum
                              paul_ipv6@infosec.exchange
                              wrote sidst redigeret af
                              #14

                              @rysiek

                              wait. so giving 4 year olds in the playground assault rifles can't ever be made safe? say it isn't so...

                              1 Reply Last reply
                              0
                              • rysiek@mstdn.socialR rysiek@mstdn.social

                                @paco Satya Nadella made sure Microsoft focused on security over 2 years ago, after all!
                                https://www.geekwire.com/2024/haunted-by-repeated-breaches-microsoft-is-putting-security-above-all-else-vows-ceo-satya-nadella/

                                dgodon@mastodon.onlineD This user is from outside of this forum
                                dgodon@mastodon.onlineD This user is from outside of this forum
                                dgodon@mastodon.online
                                wrote sidst redigeret af
                                #15

                                @rysiek @paco so you’re telling me they treat security as seriously as Meta treats privacy?

                                1 Reply Last reply
                                0
                                • rysiek@mstdn.socialR rysiek@mstdn.social

                                  One way out of this is compartmentalization, hard-limiting chatbot's access to certain resources. But that defeats the purpose of the chatbot – you can't have a chatbot that manages your mail without giving that chatbot access to your mail...

                                  Another is to move towards more formalized instructions, which can then be properly constrained by permissions etc. But then you're re-inventing programming languages and access control, again defeating the purpose of a natural-language-processing chatbot.

                                  dominikg@mastodon.gamedev.placeD This user is from outside of this forum
                                  dominikg@mastodon.gamedev.placeD This user is from outside of this forum
                                  dominikg@mastodon.gamedev.place
                                  wrote sidst redigeret af
                                  #16

                                  @rysiek I would assume that anything a chatbot has permission to do, will get done, given enough time. Instructions to an LLM are just text which can and will get ignored. Also the chatbot can say that they did something even though no action has taken place.

                                  It's all just meaningless text to the LLM.

                                  1 Reply Last reply
                                  0
                                  • jwcph@helvede.netJ jwcph@helvede.net shared this topic
                                  Svar
                                  • Svar som emne
                                  Login for at svare
                                  • Ældste til nyeste
                                  • Nyeste til ældste
                                  • Most Votes


                                  • Log ind

                                  • Har du ikke en konto? Tilmeld

                                  • Login or register to search.
                                  Powered by NodeBB Contributors
                                  Graciously hosted by data.coop
                                  • First post
                                    Last post
                                  0
                                  • Hjem
                                  • Seneste
                                  • Etiketter
                                  • Populære
                                  • Verden
                                  • Bruger
                                  • Grupper