Live data from Hacker News

Document-borne AI worms can self-propagate through Copilot for Word

enklypesalt.com

41–50 of 317 posts

Re: Document-borne AI worms can self-propagate through Copilot for Word

#43

I mean all your data is already exfiltrated to Copilot, so a little extra worm cannot hurt. It is fun to see how all AI narratives are collapsing.

I think the damage/risk here isn't explicitly about exfiltration, but could also just be damage/harm to the organization through re-writing content in documents.

Re: Document-borne AI worms can self-propagate through Copilot for Word

#44
post #34

Earlier quoted context omitted.

No it’s not an example of that. Do you store components in your component state?

He probably means JSX mixing HTML with Javascript... function Greeting({ name }) { return Hello, {name} ; }

You just did that in a HN comment, yet nothing happened :).

Could it be that the whole idea is silly misunderstanding of fundamental tenets of reality in the first place?

Re: Document-borne AI worms can self-propagate through Copilot for Word

#46
post #17

Earlier quoted context omitted.

Mixing instructions and data is never a good idea. And I thought people understood that.

Separation of instructions and data is artificial. Reality has no such separation. A general purpose system needs not to have them either; it's a design feature, not a bug. People get too hung up on this fundamentally wrong idea, and the space of security, instead of progressing, is just running in circles like a headless chicken, making a mess of everything.

Only in systems that need to be themselves super generalist. Which is almost never the case.

Re: Document-borne AI worms can self-propagate through Copilot for Word

#47
post #6
post #5

> Malicious instructions hidden in an externally shared document could make Copilot alter drafted or edited documents in Word and propagate the attack to new documents. Oh no.

something something lethal trifecta

[flagged]

Re: Document-borne AI worms can self-propagate through Copilot for Word

#48
post #46

Earlier quoted context omitted.

Separation of instructions and data is artificial. Reality has no such separation. A general purpose system needs not to have them either; it's a design feature, not a bug. People get too hung up on this fundamentally wrong idea, and the space of security, instead of progressing, is just running in circles like a headless chicken, making a mess of everything.

Only in systems that need to be themselves super generalist. Which is almost never the case.

LLMs are.

Re: Document-borne AI worms can self-propagate through Copilot for Word

#50
post #17

Earlier quoted context omitted.

Mixing instructions and data is never a good idea. And I thought people understood that.

Separation of instructions and data is artificial. Reality has no such separation. A general purpose system needs not to have them either; it's a design feature, not a bug. People get too hung up on this fundamentally wrong idea, and the space of security, instead of progressing, is just running in circles like a headless chicken, making a mess of everything.

Literally all of software is artificial? Being explicit and reasoned about how you choose to allow or deny a particular computation is, surely, at the heart of a lot of computer security?
Post reply on HN