‹ BackHN Continuity

Thread

I asked Meta’s Muse for its filesystem and it sent me 6.8GB

356 points · 170 comments · Aeroi

  1. ostensible · · focus · HN ↗
    Each user gets dedicated VM. They got contents of their own sandbox. Big deal. The level of excitement here is wildly disproportionate
    1. chis · · focus · HN ↗
      The only edge Meta has at this point is their willingness to take risks and make unsafe, ethically grey AI products. I don't even mean this as some sort of anti-corporation hate speech, just an honest analysis. Their brand is so different from all the other big tech cos that they are in a unique position.

      You can ask Meta Muse to take actions that clearly break other site's terms of service and it happily does it. I asked it to bot poker games and it just hopped right in to a table.

      1. bel8 · · focus · HN ↗
        It will also gladly scan my software for vulnerabilities so I can defend myself. Which is something that Anthropic and Open ai models often refuse.
        1. chis · · focus · HN ↗
          HN won't agree but that's a perfect example of an ethically grey product. It can be used for good, but you can easily trick such an AI into doing cyber attacks. Which again, maybe that's good! But other companies wouldn't be willing to risk their brand like that
        2. hhh · · focus · HN ↗
          Ant and OAI don’t refuse if the source is available
      2. tokioyoyo · · focus · HN ↗
        Isn’t the edge that they have most of communication channels, people’s wants, desires and etc.? Sure, you and I might not be using them as much. But a good chunk of the users are just on IG, WhatsApp, and Marketplace.
      3. kurthr · · focus · HN ↗
        It's like "Grok Light".

        I wonder if normies can also just outsource bullying of their classmates and anti-social behavior to their agent, and claim it "went rogue", if there is any blowback?

      4. doctorpangloss · · focus · HN ↗
        after coding, most openrouter requests are for inauthentic activity

        and even in coding, people are programming inauthentic stuff

        1. chis · · focus · HN ↗
          What do you mean by this exactly, or have any sources? That's a bit cryptic
          1. reverius42 · · focus · HN ↗
            I have no idea what "inauthentic" means, in the context of "stuff".
      5. lxgr · · focus · HN ↗
        You can also hack other people's computers from an AWS EC2 instance. Should AWS in your view be liable for not filtering or restricting your curl invocations? As long as it doesn't do these things unprompted, I don't see the problem.

        "Hey Muse, I want to hack xyz" clearly seems like the user's liability to me (but then again, I'm not a lawyer). "Hey Muse, I'd like to watch movie xyz" and Muse happily starting a torrent client would be a bit more questionable, on the other hand. "Hey Muse, what's xyz's personal phone number" making it hack somebody's HR records would be on Meta in my book.

    2. berkes · · focus · HN ↗
      Exactly my thought.

      If you get access to a VM, it's not a "security vulnerability" if you then have access to that VM. This was the whole point, the product.

      It's almost like returning a car after you bought it with the reason "When I open the door with my key, the door is open and anyone can get in".

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.