‹ BackHN Continuity

Thread

What Meta got right with Muse

138 points · 189 comments · young_mete

  1. satvikpendem · · focus · HN ↗
    I don't understand Muse, couldn't agents already do all this? I have ChatGPT for example and I can have it book tickets and other things for me, it even pulls up a cloud browser if it can't access APIs. It can check for details from my email and use those for the ticket. Now OpenAI has Dots too which is a 24/7 version of the same thing.
    1. nradov · · focus · HN ↗
      Sure, it's nothing super unique but the way that Meta has put all the pieces together including security works really well in practice. Muse seems to be the best of the AI personal assistants for regular people right now.
      1. hedora · · focus · HN ↗
        Does anyone believe the security works though? This is the company that brought us facebook, pervert glasses, and got sued by its E2EE content monitoring team (which apparently exists!) for emotional trauma because they had to read so much stuff from private WhatsApp messages.
        1. nradov · · focus · HN ↗
          I believe that Muse security is about as good as any other large cloud environment. In the long run maybe all of them will eventually be hacked but so far my other Meta accounts have been 100% secure. So I'll take my chances with Muse because it saves me time and allows me to get more done.

          Those other issues, while perhaps examples of bad corporate behavior, aren't really security lapses per se.

          1. ninth_ant · · focus · HN ↗
            Meta has a long history of treating their user’s data recklessly. Cambridge Analytica being a prominent example.

            They’ve also had a long history of using shady/deceptive practices to gather data, such as Onavo.

            Is their internal security up to par with other cloud providers? Maybe. Security from them? Definitely not to be trusted.

            (Former employee)

          2. jasongi · · focus · HN ↗
            It's not about cloud environments. Basically every ToS ever forbids you from disclosing your password to someone else or another entity. Even when you use a cloud-synced password manager, the whole security posture relies on that data being encrypted the entire time and never read in the cloud.

            The worst security faux pas of companies is storing user passwords - because the most common source of account breaches is via credential stuffing, where they get hacked, have their user base's passwords stolen and tried on other websites. The remedy being... not to store passwords, only salted, secure hashes.

            Muse sounds like a disaster - your credentials for other sites are floating around on their servers, with the capability of being decrypted. Maybe if sites decided to offer a form of auth tied to the agent that could be revoked in bulk in the event of a breach it might be a ok, but this is crazy.

          3. onedognight · · focus · HN ↗
            > my other Meta accounts have been 100% secure.

            The word “my” is doing some work here. Maybe you personally have been lucky, but Meta has had quite a few data breaches.

            <a href="https:&#x2F;&#x2F;breachhistory.com&#x2F;blog&#x2F;facebook-data-breaches-full-timeline-through-2026" rel="nofollow">https:&#x2F;&#x2F;breachhistory.com&#x2F;blog&#x2F;facebook-data-breaches-full-t...

            1. Anon1096 · · focus · HN ↗
              Linking to a straight LLM generated article where the first couple entries (the only ones I bothered to read) are about keystealers on users&#x27; computers doesn&#x27;t help your case.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.