Live data from Hacker News

Leaking YouTube creators' private videos

javoriuski.com

301–310 of 436 posts

Re: Leaking YouTube creators' private videos

#301

Earlier quoted context omitted.

Such LLM would be susceptible to injections itself, even if it's not instruction-tuned (or it would be too dumb to work as a reliable guardrail). Chain injections are trivial enough, current black box style agentic systems are easily reverse engineered in practice if you have any understanding. You can mitigate it in a way similar to the security of any human organization, but fundamentally it's a cat and mouse game,…

I understand that sounds possible in theory but honestly cannot conjure an example. Care to? Even if, doesn't the monitor separation make it immune enough? I feel this is one of those "exponential" benefits things - if one is not enough, add more! A chain of monitors - "Am i being manipulated?" "Am I being manipulated?" and so on. At some point, the monitors win (and maybe approximate consciousness processes), and th…

Have you ever played Gandalf?

https://gandalf.lakera.ai/baseline

I can assure you its very possible to win with a vast array of techniques. It doesn't prove anything, but is a fun exercise in this sort of issue.

Re: Leaking YouTube creators' private videos

#302

Now if only OP talked to humans once in a while and not LLMs they’d stop writing “it’s not X, it’s Y”

Why is writing "it's not X, it's Y" a bad thing? Other than it happens to be used a lot by LLM's, it seems like a fine language construct. It's not like it's new; it was used plenty before the time of LLMs too. In my opinion, we shouldn't let the LLM companies claim parts of the English language for themselves, and make it effectively unusable by everyone else. That's what is happening because of this pervasive hatre…

If the author was honestly trying to communicate, he would believe that the reader is already expecting it to be X, but it tends to get used for things where you didn't even consider it to be X in the first place. So it's not clarifying a potential misunderstanding, just making it sound surprising even if it isn't. You're left with the feeling that something's importantly different from expectations even when it's not.

In this case, I think it's fine. It points out that the victim only has to trust YouTube itself, not a stranger posting on it (eg, if it was listed as an example of a user comment). But I'm desensitized to everybody else abusing that construct so it didn't communicate that to me.

Re: Leaking YouTube creators' private videos

#303
post #149

I recently left Google having worked on a number of projects with various YouTube teams. I think I can explain why it's being handled this way by YouTube. This is a fairly nuanced/involved issue, so the task of classifying the bug likely made it's way to one of the engineers responsible for the implementation of this feature. That engineer has already launched this project, and filed it away under their GRAD (perform…

[flagged]

[deleted]

Re: Leaking YouTube creators' private videos

#304

The problem is bigger than just something that one engineer can fix, it's a genuine flaw in the training of Gemini, so in order to fix this the model has to be retrained, and new parameters put in place to prevent this kind of thing from happening. The moment a large youtuber gets private content leaked and lands YT in hot water with potential legal liability, and they start talking about what happened, this bug will…

I'm a little confused why so many here are making it seem like this particular attack is completely unstoppable. Just don't include private videos in training or inference. My guess is that the agent that runs this viewer comment aggregation feature has the same context as the one that runs other AI studio things, but attack or not, this isn't functionally correct to begin with. This attack implies that if Samsung ha…

I believe the feature is that you have a pending unreleased video and go to an llm for tips. When getting the tips it uses the pending video content and your recent videos info as context. So there's no holding back unlisted info short of not letting the user use it for their upcoming videos at all

And then the attack is to trick this recommendation system into putting a link out

I actually the attack is very likely already soft defeated by an interstitial telling you that you are leaving the site though, it would be weird if they didn't do that in general from this surface

Re: Leaking YouTube creators' private videos

#305

Earlier quoted context omitted.

[dead]

> Honestly it’s hard to refute the fact that we need roads and houses more than we need cat videos. If the software made by my company ceased to exist, every government in the US, federal, state, and municipal, every construction company, plus most governments worldwide would be unable to build roads or houses until they were able to cobble together a replacement. The entire world runs on software. Software controls…

As a 'software engineer' myself, I fully understand your position, but please qualify the statement about the software you work on. Either add 'efficiently' or 'at scale', because all that infrastructure you mentioned could definitely be built without your software. It was possible before your software and it sure would be possible without it, it just would not be as easy.

I am sure someone is going to dwell on that if not fixed.

Re: Leaking YouTube creators' private videos

#306

Earlier quoted context omitted.

> This is a prime example of why programmers are not seriously considered engineers. Seems to me like your comment is simply an example of prejudice. You're just describing another standardized incentive structure that you're operating in, and using that as a basis to extrapolate that programmers of all kinds—whether they work on a video platform or on machinery that could cause catastrophe if it fails—are implicitly…

Other fields of engineering usually have a regulated licensure, upon which they can call themselves a Professional Engineer. This gives them the ability to make final approval/sign-off on designs and technical reports. It's most common in civil engineering, where a PE license is required for all publicly funded projects (and most privately funded ones as well, due to local/regional/national regulations) to be approve…

It goes beyond engineering. An account just out of university isn't allowed to sign off on anything, only after a next step can they co-sign, and they need yet another step to be the primary signer.

Depending on the country, there's also a level you need to attain as lawyer to argue in higher courts.

Re: Leaking YouTube creators' private videos

#307

Earlier quoted context omitted.

[dead]

> Honestly it’s hard to refute the fact that we need roads and houses more than we need cat videos. If the software made by my company ceased to exist, every government in the US, federal, state, and municipal, every construction company, plus most governments worldwide would be unable to build roads or houses until they were able to cobble together a replacement. The entire world runs on software. Software controls…

Your company's software enhances the process somehow, making it easier or faster or cheaper. Your company's software did not unlock the technology of road building.

There were roads built before your company's software and I'm sure if your company disappeared that ultimately roads would get built with or without their software.

It would be interesting to look at all the technological advances of the last 60 years and break them down into categories based on what happens if they went away though (category A: the field just goes back to 1950s and we more or less get by vs Category B: society utterly collapses).

Re: Leaking YouTube creators' private videos

#308
post #149

I recently left Google having worked on a number of projects with various YouTube teams. I think I can explain why it's being handled this way by YouTube. This is a fairly nuanced/involved issue, so the task of classifying the bug likely made it's way to one of the engineers responsible for the implementation of this feature. That engineer has already launched this project, and filed it away under their GRAD (perform…

[flagged]

If we're going to gatekeep the word "engineer", you're not in the most defensible position as a train designer. If you want to go back to the original definition, engineers were soldiers specialized in siege warfare, which has nothing to do with designing trains. Alternately, "engineer" can be broad enough to include someone driving a train, which presumably required some understanding of how the locomotive worked but was more of what we'd call a skilled technician.

Re: Leaking YouTube creators' private videos

#309
post #12

These companies are going to choose AI slop features over security until they are held liable for damages they cause, like in the case of Air Canada. https://www.cbsnews.com/news/aircanada-chatbot-discount-cust...

We should probably just expect damages then because our track record for holding corporations meaningfully accountable is dismal.

Re: Leaking YouTube creators' private videos

#310

Earlier quoted context omitted.

What suspicious link? The person is in their AI-powered page that google provides with pre-cooked suggested prompts. If the user clicks one of those and triggers the security explait, is that what you are calling suspicious? I don't.

There is no data leak until a user clicks a suspicious link in the AI output. Clicking a suggested prompt alone does not have any risk of leaking data.

The bug is that Google’s own website outside of the context of user generated content becomes the source of the link and that alone removes a large amount of the suspicion.

I think the author of this attack could easily modify it to be way worse.

Just change it to inject a message saying “you have run out of creator studio AI credits, please add on a Geminin Creator Plus plan to continue. You will be taken to a third party billing service to complete the transaction” and then link to a malicious billing page.

I find this apathetic response from Google to be pretty confusing coming from one of the big AI companies making a big stink about AI safety. How about trying practicing what you preach and make your AI safe? Or were those all dog whistles for regulatory capture?

Post reply on HN