Earlier quoted context omitted.
I don't think "works well enough" is good enough. We are currently starting to wire LLMs up as AI-enhanced personal assistants - with the goal of giving them access to our email, and the ability to take actions on our behalf. If we widely deploy these systems the incentives for attackers to figure out prompt injection attacks that get last any probability-based filters we are using will be enormous. An attacker only…
How do we determine how vulnerable a system is without seeing how it is implemented? That is, can you generalize LLM usage to all apps and determine that the entire field is exposed? Obviously it is a problem for end users, but that’s more of an optics and trust angle, just as browser extensions are a privacy nightmare. I am as worried as you are on this front, given that people appear to be using browser extensions…
Shortcut for macOS and iOS has disabled-by-default advanced options Allow Running Scripts, Allow Sharing Large Amounts of Data, Allow Deleting without Confirmation, Allow Deleting Large Amounts of Data. [0]
[0] https://support.apple.com/guide/shortcuts-mac/adjust-privacy...