‹ BackHN Continuity

Thread

Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions

163 points · 43 comments · dkobia

  1. jkingsman · · focus · HN ↗
    I'm no evangelist for LLM assistants, but this seems incredibly improbable and represents a failure of MacOS security if so. If full disk access isn't granted, Mac blocks it from the Downloads folder, to say nothing of actually sensitive paths. I would expect a far more likely case of an accidentally granted permission on another device or a permission that was on and then turned off.

    Permissionless action is about to skyrocket as an issue, but this particular scenario strikes me as incredibly unlikely. Would be interested to know if Muse can provide more meaningful data provenance/logs.

    Scanning iMessage dbs as a passive part of full disk access (and not a messages grant), if true, is a little sketchy, regardless.

    1. skohan · · focus · HN ↗
      Agent sandboxing/access control is one of the biggest problems to be solved before this technology really should go mainstream.

      Even as a technical person, it's not trivial to sandbox agents correctly. The fact that an mis-clicked permission popup could give an agent unrestricted access to a user's disk is a massive risk vector in the hands of lay people who barely understand how any of this works.

      So much of current security depends on the model of tying access control to a user account. A lot has to be re-thought in terms of how to grant access to an agent working on the user's behalf, in a way that doesn't make it completely useless, and also doesn't require every user to become a sysadmin managing fine-grained agent permissions manually.

      1. thefounder · · focus · HN ↗
        something tell me that the vast majority of people will give all the permissions the agent ask but even more look for a bypass/yolo permission.

        I say that from coding experience. You don’t want to approve 100 windows to get a task done. In the end the only “sane” solution for my setup was a dedicated machine just for the agent with Bitwarden for secrets and full access/yolo mode.

        If you are concerned about the agent deleting everything make sure you have a process backing up the git repositories at least to a separate service/hosting and that’s it…for now.

        So the solution is to have backups and a way to restore data…

        1. skohan · · focus · HN ↗
          That helps you if the blast radius is on your machine, but it doesn't really help if the agent is using your credentials to cause some damage with some remote system you have access to.

          When I was kicking the tires on pi, one of the first things the agent did was push an update to one of my published Rust crates (not the project it was working on).

          That in itself wasn't harmful, but it did convince me it was worth the effort to figure out sandboxing after that.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.