Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Ian Campbell
@neurovagrant@masto.deoan.org  ·  activity timestamp 4 months ago

This is fun. Google Gemini’s “Summarize email” function is vulnerable to invisible prompt injection utilized to deceive users, including with fake security alerts.

#infosec #cybersecurity #blueteam

https://0din.ai/blog/phishing-for-gemini

  • Copy link
  • Flag this post
  • Block
Ian Campbell
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 4 months ago

I continue to maintain that Apple’s slower march to AI puts them in a better place than the rest of the platforms rushing to create new user exposure for bad actors to exploit.

  • Copy link
  • Flag this comment
  • Block
Ian Campbell
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 4 months ago

SANITIZE YOUR INPUTS.

Everyone rushing to LLM-ify everything forgot every lesson about input sanitization.

smdh.

  • Copy link
  • Flag this comment
  • Block
Lauren Weinstein
@lauren@mastodon.laurenweinstein.org replied  ·  activity timestamp 4 months ago
@neurovagrant And of course, "sanitize your inputs" is going to fall on deaf ears among the public at large. Hell, you can't even get most people to wash their hands after using the restroom, it seems.

Seriously though, if the system depends on users taking specific actions to ensure their safety, the system is flawed in my opinion. Basically, "whenever you blame the users as a group, you're on the wrong side of the issue" has long been my philosophy.

  • Copy link
  • Flag this comment
  • Block
Scott Francis
@darkuncle@infosec.exchange replied  ·  activity timestamp 4 months ago
@lauren @neurovagrant if your system depends on somebody DTRT, you are going to have a bad time
  • Copy link
  • Flag this comment
  • Block
Lauren Weinstein
@lauren@mastodon.laurenweinstein.org replied  ·  activity timestamp 4 months ago
@darkuncle @neurovagrant Don't let the quest for perfect get in the way of the good, as the saying goes.
  • Copy link
  • Flag this comment
  • Block
Pete
@pete@mas.to replied  ·  activity timestamp 4 months ago
@lauren @neurovagrant

Interfaces should be designed to be easy to use safely and difficult to use un-safely.

  • Copy link
  • Flag this comment
  • Block
Ian Campbell
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 4 months ago

Aw jesus christ, sales types are gonna start using this now too aren’t they

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.3.21 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login