Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions
Unofficial Hacker News client; not affiliated with Y Combinator.
jkingsman · · focus · HN ↗
Permissionless action is about to skyrocket as an issue, but this particular scenario strikes me as incredibly unlikely. Would be interested to know if Muse can provide more meaningful data provenance/logs.
Scanning iMessage dbs as a passive part of full disk access (and not a messages grant), if true, is a little sketchy, regardless.
skohan · · focus · HN ↗
Even as a technical person, it's not trivial to sandbox agents correctly. The fact that an mis-clicked permission popup could give an agent unrestricted access to a user's disk is a massive risk vector in the hands of lay people who barely understand how any of this works.
So much of current security depends on the model of tying access control to a user account. A lot has to be re-thought in terms of how to grant access to an agent working on the user's behalf, in a way that doesn't make it completely useless, and also doesn't require every user to become a sysadmin managing fine-grained agent permissions manually.
robby_w_g · · focus · HN ↗
I think the problem is that LLM providers are dis-incentivized from pursuing it because their ethos is gobbling up any and all data they can get.
> Oops, we accidentally yoinked your personal documents, photos, and videos and they’re now swimming in our model’s data ocean! We’re sorrrry, oh well let’s move on.
It’s up to the users to use tools that enforce security/privacy. Open source harnesses like pi.dev seem like a good path forward to me
dragonwriter · · focus · HN ↗
The problem is that, for most potential users to whom personal (not software dev) agents are being marketed, security & privacy for AI agents is a higher load domain to manage than the things they would want to delegate to agents to relieve load, so taking up the required security & privacy management to avoid problems using the agents creates disutility that exceeds the utility of the agent.
Which is why anyone selling them is going to distract from the issue rather than try to inform their customers.
EDIT:
Another problem is that in many cases, BECAUSE of the assumptions about how people use computers, web services, etc., the required tools DO NOT EXIST. Most account based web services DO NOT have ways to create, say, access tokens with a subset of full account permissions that you could give to an agent rather than full control of the account, because that kind of delegation to limited authority actors was never part of the usage model the vendor designed for.