This is fun. Google Gemini’s “Summarize email” function is vulnerable to invisible prompt injection utilized to deceive users, including with fake security alerts.
This is fun. Google Gemini’s “Summarize email” function is vulnerable to invisible prompt injection utilized to deceive users, including with fake security alerts.
I continue to maintain that Apple’s slower march to AI puts them in a better place than the rest of the platforms rushing to create new user exposure for bad actors to exploit.
SANITIZE YOUR INPUTS.
Everyone rushing to LLM-ify everything forgot every lesson about input sanitization.
smdh.
Seriously though, if the system depends on users taking specific actions to ensure their safety, the system is flawed in my opinion. Basically, "whenever you blame the users as a group, you're on the wrong side of the issue" has long been my philosophy.
Interfaces should be designed to be easy to use safely and difficult to use un-safely.
Aw jesus christ, sales types are gonna start using this now too aren’t they
A space for Bonfire maintainers and contributors to communicate