Live data from Hacker News

Document-borne AI worms can self-propagate through Copilot for Word

enklypesalt.com

251–260 of 317 posts

Re: Document-borne AI worms can self-propagate through Copilot for Word

#251
post #149

Earlier quoted context omitted.

You're saying that people fall for phishing because scammers invent completely unrealistic scenarios that would never happen outside TV shows?

I am saying it is unbelievable scenario and yes, I want the person dealing with it ignore it as such.

They could go to the server room and check if there's smoke pouring out of it before dialing 911.

Re: Document-borne AI worms can self-propagate through Copilot for Word

#252

Earlier quoted context omitted.

Even engineers like doing it sometimes. The old telephone system was so hackable because of in band signaling.

The “new” phone system (SS7) still relies on implicit trust and a lack of security.

that is not new. It is newer than the phreakable one but it is many decades old from before there were things like encryption, and Linux.

Re: Document-borne AI worms can self-propagate through Copilot for Word

#253
post #180

Has anyone pointed out yet that in a world full of AIs, these worms are just memes? Memetic idea propagation, same as what happens with us apes.

Those are parasitic memes, that bring no value to the host. There are many such memes in apes world too.

I just lost the game.

Re: Document-borne AI worms can self-propagate through Copilot for Word

#254
post #165

Earlier quoted context omitted.

If there is a fire and a risk to life, you don't want any delay.

Then don't send an email? Emails are async in the first place.

You're not the sender in this scenario, you're the receiver.

Noting that the sender is being weird during what appears to be an emergency is a choice that some people do make, but as per my other list of examples, people in actual emergency situations do sometimes act weird, and dismissing the sender or delaying response on the basis the sender is being weird, has led to actual deaths: https://news.ycombinator.com/item?id=49098781

(The converse: "people can act weird in emergencies" is exploited by scammers so cover suspicious phone numbers and mediocre deepfakes of voices).

Re: Document-borne AI worms can self-propagate through Copilot for Word

#255

I am wondering when the whole Excel/Word universe is going to die. One can only hope.

It seems to me it's more about Outlook, OneDrive, SharePoint, Project and Teams now. With Entra and Intune, of course. All kinds of 'control and monitor your employees' stuff has been going on there for a while. I think that's more of the moat than a spreadsheet and a word processor. Unless it's a shared document, no one cares if you use LibreOffice or whatever else, as long as you can provide requested formats when…

I think most people use Google Docs now anyway.

Re: Document-borne AI worms can self-propagate through Copilot for Word

#256
post #230

Earlier quoted context omitted.

> People ... are trying very hard to argue that humans are subject to this via social engineering but it is not the same Thank you, I always hear the "but humans fall for social engineering too!" line used reflexively whenever yet another prompt injection attack gets reported and it drives me crazy. While it's true certain strings of text exist that both an LLM and a human could plausibly fall victim to, they are a t…

> Base64, Unicode substitution, emojis, output of obfuscated but "harmless" code run in a sandbox, image steganography, etc that could be endlessly disguised without a human even being able to see it, yet alone fall for it Like a whisper or a morse code pattern or a post-it stuck in the middle of a stack of fresh printouts saying "${employee} is threatening to kill me please call 911" or... Yes, LLMs and humans have…

Agreed. I do not understand why so many others cannot understand that independent non deterministic models cannot be constrained the same way as deterministic code can.

It’s just fundamentally different. They are both software in the same way liquids and solids are both matter but they have fundamentally different properties due to their nature.

Re: Document-borne AI worms can self-propagate through Copilot for Word

#257
post #70
post #64

> "At the time of publication, no robust mitigation for the broader vulnerability class is available" Isn't it obvious by now that it's never going to be possible to fix this kind of thing, at least until we stop mixing up instructions with data.

> until we stop mixing up instructions with data Is such a thing even possible with a generally intelligent system processing content with unlimited diversity?

Yes, basically we just need really good, strong parentheses.

E.g. see Yoshua Bengio "Scientist AI". Or multi-stream LLMs

Re: Document-borne AI worms can self-propagate through Copilot for Word

#258

Earlier quoted context omitted.

We've already seen that it's possible to trick models into seeing user input as their own "thinking" if you make it sound like what the model writes. While it may appear that it's looking at the tags on the input, in practice that's not as strong a guarantee as you'd hope.

Do you have the reference for this, I remember seeing it recently but can't dig it up

I think GP is referring to "Prompt Injection as Role Confusion" (https://role-confusion.github.io/). It was discussed on HN several weeks ago (https://news.ycombinator.com/item?id=48631888)

Re: Document-borne AI worms can self-propagate through Copilot for Word

#259

Earlier quoted context omitted.

The “new” phone system (SS7) still relies on implicit trust and a lack of security.

that is not new. It is newer than the phreakable one but it is many decades old from before there were things like encryption, and Linux.

Current system, unfortunately.

Re: Document-borne AI worms can self-propagate through Copilot for Word

#260

Earlier quoted context omitted.

that is not new. It is newer than the phreakable one but it is many decades old from before there were things like encryption, and Linux.

Current system, unfortunately.

No, that's not true, there is no single current system. There is no telephony equivalent to BGP. Each separate interconnection uses whichever protocol it wants to.
Post reply on HN