Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Meta has confirmed this it intended behavior.

Ayyy! You're one of the folks I wrote my comment [0] for!

[0] <https://news.ycombinator.com/item?id=49953429>

 help



Totally fair if that's just a public stratch pad (which happens to make several specific, unsubstantiated claims). Not hating on that guy.

But if someone posts the thread with no other context than "check this out", then it seems appropriate explain this missing context.

And for the record, I did scroll back read through what he's saying as you suggested. The broader context is exactly what makes it clear he's just a bit confused about what he's "uncovered". (Obvious caveat: I haven't read through everything this guy has written, I could be missing something)


> I did scroll back read through what he's saying as you suggested. ... Obvious caveat: I haven't read through everything this guy has written...

Did you also scroll forward to read what he wrote after the stuff in the thread that was linked to? This tool is pretty obviously designed -whether intentionally or not- to enable the exfiltration of a ton of sensitive data to untrusted third parties while leaving its intended user none the wiser.


The things I see beneath that in the thread

a) More being surprised the muse will just provide internal details (which again, as intended) b) the bash scripts are ugly (okay? I don't think that's what we're arguing about) c) surprise that muse runs as root (then realizing this is explained by the VM-in-VM model and linking to the blog which explains this) d) surprise that muse can run as a seed box (idk is this supposed to be the security concern?)

Could you please be more specific about which part you're concerned about? I think that'd be more productive than linking to a long thread, me responding to what I see, then being told that it's just a scratch pad and I'm silly for taking it seriously but also if I look closer I'll see the deeper truth.


> ...then being told that it's just a scratch pad and I'm silly for taking it seriously...

Yeah, given how this has been going, I expected that sort of misrepresentation. A careful reader remembers that this is what I said:

  You should pop up to that -er- blog's top level, scroll back until you find the start of the investigation, and then start reading. Yeah, it's a huge pain in the ass, but this is -AFAICT- the guy's personal notepad, rather than some place where formal reports usually go. If someone walked over, picked up my personal notepad at $DAYJOB, and complained about how they couldn't make sense of it, I'd tell them to fuck right off, yanno?
Anyway. I'm certain that your answer to this is going to be some flavor of "no, of course it isn't", but are the combination of these things simply no problem?

<https://neuromatch.social/@jonny/117353184983766316>

<https://neuromatch.social/@jonny/117361988874888258>

<https://neuromatch.social/@jonny/117381101404641742>

<https://neuromatch.social/@jonny/117385767238251458>

<https://neuromatch.social/@jonny/117386670662407608>


I remembered what you said and I genuinely don't understand what I mischaracterized.

TBH I saw none of those comments by scrolling forward or backwards from the original link. Now it turns out I supposed to be checking quote tweets, not just scrolling like you said above? (tbf I'm not familiar with the neuromatch UI, could be user error on my part).

Again, I think this would've gone smoother if you actually articulated the problem you're concerned about, instead of linking to a "personal notepad" which you acknowledge has mistakes and isn't easily intelligible, and then blaming me for missing the actual point.

I'll look through these new comments later.

Edit: I see from your original comment what you meant by "top-level". I originally assumed you just meant top of the thread. I'll take the L here.


I've read through those comments and I see more interesting concerns being raised ("interesting" as in "not completely confused for trivial reasons", I'm not conceding anything).

Like I mentioned I don't work on Muse, and I suppose it'd wouldn't be appropriate for me (self-identified Meta employee) to publicly speculate on what defenses do and don't exist or what is intended. (sorry kinda a cop-out, I know).

Thanks for providing specific links to the specific concerns being raised.


> I originally assumed you just meant top of the thread. I'll take the L here.

I'd very much rather you commit to

* Slowing the hell down when you're reading things that other people write. If you don't have time to slow down and actually read, stay the hell out of the conversation.

* Upon receiving a notification that you've massively misunderstood something that someone has said in writing, immediately stop, carefully inspect what you know and what you assume, and then go back and carefully re-read the thing you've been told you massively misunderstood while keeping at the front of your mind the knowledge that your task is to find out what parts you totally misunderstood during your prior reads

This second point is a huge part of that whole "principle of charity" thing that's the fundamental part of good "netiquette". This principle should be abandoned when you have personal knowledge that your conversation partner is a fucking bozo or is otherwise intentionally fucking with you... but -as I'm sure you know- one cannot possibly possess that knowledge at the start of one's first conversation with a stranger.

> I suppose it'd wouldn't be appropriate for me ... to publicly speculate on what defenses do and don't exist or what is intended.

With all due respect, that's not what I asked for. What I asked was

  ...are the combination of these things simply no problem?
If it helps to focus your thinking, remember that "prompt injection" is a fancy phrase for "the tool is now blindly executing code handed to it by some random stranger on The Internet in the same way it would execute operator-issued or tool-manufacturer-embedded instructions".

I think at this point we're both just upset feeling like we've wasted each other's time. Sorry this wasn't more productive



Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: