• Soyweiser@awful.systems
    link
    fedilink
    English
    arrow-up
    5
    ·
    edit-2
    1 day ago

    He was particularly impressed at how it helped him cancel forgotten subscriptions.

    Not the only person I saw talking about how great that is. Which is saying more about the ai enthousiasts than the llm tbh. Esp with the addition that the phonecalls are done by a real person. And the addition that you need to upload your life to facebook for this to work. A privacy nightmare.

    Wonder how long we have till it takes out a lone in somebodies name to spend on facebook advertising tokens.

    E: Omg, it looks like it gave people root who were pretending to be another Muse instance. Imagine jokingly trying a ‘how do you do my fellow AI’ and then it works.

  • samvines@awful.systems
    link
    fedilink
    English
    arrow-up
    4
    ·
    2 days ago

    The best (worst) part of all is that Jonny keeps going to meta and being like “hey this is bad” and theyre like “nah that’s intended behaviour”

    This morning he confirmed that it’s possible to get unlimited arbitrary and untraceable access to their LLM infra through these containers and that meta said that’s “intended behaviour”

    From jonny:

    So, summary: There is arbitrary inference that is root accessible, everything runs as root, agents can be spawned, exfil is trivial, and a malicious binary can come onto the user’s system through casual prompting, explicit code-sharing through the yet-to-be-released Spaces feature, walked through by a Workflow-Backed Idea, or inspired by a Generated Idea. The also yet-to-be-activated fleet learning system is a system for sharing Ideas in the background between muse instances. coming into focus?