‹ BackHN Continuity

Thread

Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions

163 points · 43 comments · dkobia

  1. jkingsman · · focus · HN ↗
    I'm no evangelist for LLM assistants, but this seems incredibly improbable and represents a failure of MacOS security if so. If full disk access isn't granted, Mac blocks it from the Downloads folder, to say nothing of actually sensitive paths. I would expect a far more likely case of an accidentally granted permission on another device or a permission that was on and then turned off.

    Permissionless action is about to skyrocket as an issue, but this particular scenario strikes me as incredibly unlikely. Would be interested to know if Muse can provide more meaningful data provenance/logs.

    Scanning iMessage dbs as a passive part of full disk access (and not a messages grant), if true, is a little sketchy, regardless.

    1. skohan · · focus · HN ↗
      Agent sandboxing/access control is one of the biggest problems to be solved before this technology really should go mainstream.

      Even as a technical person, it's not trivial to sandbox agents correctly. The fact that an mis-clicked permission popup could give an agent unrestricted access to a user's disk is a massive risk vector in the hands of lay people who barely understand how any of this works.

      So much of current security depends on the model of tying access control to a user account. A lot has to be re-thought in terms of how to grant access to an agent working on the user's behalf, in a way that doesn't make it completely useless, and also doesn't require every user to become a sysadmin managing fine-grained agent permissions manually.

      1. SamInTheShell · · focus · HN ↗
        It's already solved. I have two git repos proving these companies can fix the problems. The fact this continues just proves they don't care. In one project I literally containerize CLI coding tools, it works. You might say "sure, but network." I literally wrote a desktop app harness that you can toggle the network on/off too.

        This is all amateur hour shenanigans.

        1. skohan · · focus · HN ↗
          I sandbox my coding agents using bubblewrap, but I don't think it's as trivial a problem as you make it sound.

          For something like muse that's supposed to be a general-purpose assistant, how do you give it enough access to be useful, without giving it too much access, and creating unacceptable risks? And how do you do that in a way that's comprehensible the average Facebook user who's the target market of this product?

          1. SamInTheShell · · focus · HN ↗
            The problem is trivial to solve. Treat AIs like they are users. We have user space for a reason. We have linux namespaces for a reason. We have real airgap architectures where the data center can't even connect out.

            When you're a company running around with more than a few billion in the vault, you have no excuse for the level security negligence going on at every phase of rollout.

            I gawked at Cursor executing a python script one time and decided enough was enough, I don't raw dog these tools anymore because their developers are the dumbest people to task with security work. They just don't care.

            1. skohan · · focus · HN ↗
              So how would you go about sandboxing Muse in a way that it still functions as a general purpose assistant?
              1. SamInTheShell · · focus · HN ↗
                > that it still functions as a general purpose assistant

                What features you want it to have? The thing you're saying is super vague, I would just say that one belongs in cloud.

                If it must run things on the user's machine, it's gotta be in a rootless container and not be root inside the container. All tools belong in the container. Folder access explicitly configured by the user.

                Like I already did this for my local AI: <a href="https:&#x2F;&#x2F;github.com&#x2F;SamInTheShell&#x2F;loom" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;SamInTheShell&#x2F;loom

                It&#x27;s not perfect or even done, but it works and it shows the security model that should be standard for aligned models we&#x27;re running.

                Unaligned models, absolutely different story.

                Also VM is better than container for security, but containers are a bare minimum for me.

                1. skohan · · focus · HN ↗
                  Let&#x27;s say I have an aligned agent, and I want to give it access to my bank account to track my budget, and my email so it can automate responses to certain messages, and automatically unsubscribe from junk emails.

                  Nether service has a way to configure fine-grained access for a secondary user.

                  How do I go about giving the agent the ability to perform these tasks without exposing myself to the risk of unexpected destructive behavior from the agent?

                  1. SamInTheShell · · focus · HN ↗
                    Those are API things. Should be an API, build an MCP server for it. Doesn&#x27;t touch the PC. About the automated responses, that&#x27;s a write operation, therefore requires user consent.

                    If you want to design a system specifically to make sure you&#x27;re not going to get stonewalled for sending me an emdash, you build and maintain a set of permissive rules for sending&#x2F;reading to avoid my blacklist of people I&#x27;ll never work with.

                    Once you got API stuff sorted, just throw a cronjob at it or build a service for that stuff.

                    ^ There be prompts all over the place here, obviously. Realistically your MCP server will end up hacking on POP3.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.