Live data from Hacker News

AI browser extensions are a security nightmare

kolide.com

101–110 of 129 posts

Re: AI browser extensions are a security nightmare

#101

Earlier quoted context omitted.

Already commented something similar in another thread: Why is the security policy for extensions still not architected like other web permissions? There has been a shift on mobile already from "take it or leave it"-style permissions on install towards more fine grained control not overidable by the app manifest. I think Browser extensions should behave similarly. Especially when it comes to which origins an extension…

you can make a warning as big and scary as you can, and people will just blindly hit accept/agree/ok. the look/design of the banner is not what will stop people from hitting ok, as at this point, i don't think anything will

While this is historically true, if the text is human readable - ‘may be able to read and transmit to a third party any data you input, including credit card numbers and passwords’ - is fairly likely to raise awareness. It’s not effect, but it’s better than nothing.

It’s worth contrasting clear communication such as the above to a EULA designed by scummy companies to not be read, browsers presumably have nothing to gain by exposing malicious plugins, so they’re a good candidate for the former.

If only we could get Mozilla executive to implement something actually useful instead of whatever meme tech they’ve lost their nut over this week, that’d be nice.

Re: AI browser extensions are a security nightmare

#102

Earlier quoted context omitted.

Already commented something similar in another thread: Why is the security policy for extensions still not architected like other web permissions? There has been a shift on mobile already from "take it or leave it"-style permissions on install towards more fine grained control not overidable by the app manifest. I think Browser extensions should behave similarly. Especially when it comes to which origins an extension…

you can make a warning as big and scary as you can, and people will just blindly hit accept/agree/ok. the look/design of the banner is not what will stop people from hitting ok, as at this point, i don't think anything will

Click 'agree' on the next 3 prompts within 15 seconds to see a monkey throwing an ice cream cone at King Charles

Re: AI browser extensions are a security nightmare

#103

Earlier quoted context omitted.

Privacy Badger, 1Password, HTTPS Everywhere, Dark Reader, to name a few.

> Add "Dark Reader"? > It can: Read and change all data on all your websites It already has the broadest permissions available. Dark Reader injects arbitary code into every page you visit. It's one silent update away from stealing all your sessions. This is a security nightmare. All browser extensions are a security nightmare.

Interesting!

Re: AI browser extensions are a security nightmare

#104
post #39
post #29

Earlier quoted context omitted.

How do we know that the brain is a statistical model of the world? It sounds like explaining an unknown phenomenon using the technology du jour - just 10/20 years ago, the brain was a computer.

This touches on a dichotomy that has fascinated me for decades, from the very beginning of my interest in AI. One side of the dichotomy asserts that "if it walks like a duck..." that is, if a computer appears to be intelligent to us, then it must be intelligent. This is basically the Turing Test crowd (even though Turing himself didn't approve of the Turing Test as an actual test of AI). On the other side, you have p…

The general notion is called "lumpers" and "splitters".

From the perspective of software, the lumpers are pretty much always wrong except for when they get a lucky guess. Think of a pointy-haired boss who weaponizes his wishful thinking with a brutal dismissal of all implementation details and imposes ignorantly firm deadlines, or an architecture astronaut who writes and forces upon everyone cruel interfaces and classes that are thoroughly out of touch with reality.

As they say: "it's more easy to lump splits than split lumps". The people who insist the statistical models have emergent behavior, or even worse, equate them with human brains are "lumpers" who lack imagination and have no desire to truly understand and model these things. They naively seek out oversimplifications and falsely believe they're applying Occam's Razor, but they're actually just morons. "Splitters" are by their very definition always technically correct, but create complex distinctions that either represent much deeper knowledge than necessary, or hallucination. Either way, both types are needed, and of course, society values the lumpers far more for essentially playing the lottery with their reputations by telling people what they want to hear.

https://en.m.wikipedia.org/wiki/Lumpers_and_splitters

Re: AI browser extensions are a security nightmare

#105
post #31

I wonder when we’ll start seeing computer viruses that communicate with a remote LLM in order to get help circumventing barriers. Alternatively, maybe anti-virus software can phone home to get on-the-fly advice.

> Alternatively, maybe anti-virus software can phone home to get on-the-fly advice.

Modern antivirus software already does this, more or less. It's usually called something like "cloud scanning."

Re: AI browser extensions are a security nightmare

#106

Earlier quoted context omitted.

Privacy Badger, 1Password, HTTPS Everywhere, Dark Reader, to name a few.

> Add "Dark Reader"? > It can: Read and change all data on all your websites It already has the broadest permissions available. Dark Reader injects arbitary code into every page you visit. It's one silent update away from stealing all your sessions. This is a security nightmare. All browser extensions are a security nightmare.

If you have the time, will, and ability, audit the latest release and turn off auto update. That’s counter productive when the extension has its own attack surface of course.

I also haven’t read anything concerning about Mozilla’s Recommended review system yet.

Re: AI browser extensions are a security nightmare

#107
post #2

> Yes, large language models (LLMs) are not actually AI in that they are not actually intelligent, but we’re going to use the common nomenclature here. I'm sorry for the off-topic comment, but why do I keep seeing this? What am I missing here – is it that some people define intelligence as >= human, or that LLM are not intelligence because they're *just* statistical models?

> is it that some people define intelligence as >= human

Just like some people define stupid as <= them. Aptitude is a multivariate spectra. It is already hard to come up with a cutoff on a single measure, way harder to do so for a bunch of different skills that for some reason happen to correlate in humans (and sometimes they diverge wildly as in the case of savant syndrome).

Re: AI browser extensions are a security nightmare

#108
post #87
post #29

Earlier quoted context omitted.

How do we know that the brain is a statistical model of the world? It sounds like explaining an unknown phenomenon using the technology du jour - just 10/20 years ago, the brain was a computer.

So conversely, is the brain magic? And if so, if we look at the evolutionary lineage of neural networks, at which point did it become so?

I wouldn't say the brain is magic, just that we still don't know what consciousness and intelligence is. Could the complex emergent behaviour we call intelligence emerge from a statistical model? Maybe. Can we gain more insights on what intelligence is by studying these models? Definitely. On the other hand — Are there limits to large language models' capabilities that we haven't reached yet?

Re: AI browser extensions are a security nightmare

#109
>Actually, the current AI situation may be even more perilous than Jurassic Park. In that film, the misguided science that brought dinosaurs back to life was at least confined to a single island and controlled by a single corporation. In our current reality, the dinosaurs are loose, and anyone who wants to can play with one.

I'm really tired of reading stuff like this above. Seriously, AI is a disruptive tech and some people will oppose any change, but this is too much. All of the "security issues" mentioned in the article are true for browser extensions,and perhaps even software in general.

Then the author talks about "copyright mess" just before describing how it is pretty much resolved in their company (copilot banned).

The only real "problem with AI" is really a "problem with cloud" or more precisely "problem with people's lack of understanding of it". Average people should be interested in finding software alternatives that don't undermine their privacy.

For example look at AI image up scaling. Every single android app other than mine sends user's images to a server somewhere. Are those images retained? Are they scanned for whatever "legal purposes" the maker deems adequate? No one knows. No one cares. Well specifically in the entire world about 90 people seem to care.

Why 90 people? Because that's how many users my android app has 6 months after release. (the app does all processing locally, free version is ad supported, paid version can be used 100% offline).

Re: AI browser extensions are a security nightmare

#110
post #21

Earlier quoted context omitted.

> LLM are not intelligence because they're just statistical models This is exactly it for me.

And if your brain is mostly a statistical model of the world, with action probabilities based on what parts of it happen to be excited at the moment?

The brain carries state and is self-modifying, which is something that can‘t be said about mere statistical models.
Post reply on HN