Live data from Hacker News

Detecting AI agent use and abuse

stytch.com

101–106 of 106 posts

Re: Detecting AI agent use and abuse

#101

Earlier quoted context omitted.

I remember Facebook's shady user acquisition tactics, and I also do not use Facebook and similarly think their business model is morally bankrupt. > Guess I'll just have to give Plaid my password then. Learned helplessness, trading digital sovereignty for convenience. There is a larger war being fought here that is bigger than you or me. Had Plaid not been forced upon me, I would never have used it willingly.

You think digital sovereignty is when you are not allowed to do what you like with your account, but must follow someone else's terms and conditions?

It's a complex topic which requires the balancing of some things that may seem at odds.

Yes, digital sovereignty means owning your data and the means to transfer and activate it.

It also covers things like not having to relinquish a personal key or passphrase in order to do so, as that severely diminishes your personal security, erodes privacy and trust, and enables a future society where corporate participation is mandatory and the dissolution of security of privacy boundaries considered essential and unavoidable.

Such a system is horribly anti-consumer, even if it seems nice while the lollipop is still in your mouth.

Re: Detecting AI agent use and abuse

#102

Earlier quoted context omitted.

You think digital sovereignty is when you are not allowed to do what you like with your account, but must follow someone else's terms and conditions?

It's a complex topic which requires the balancing of some things that may seem at odds. Yes, digital sovereignty means owning your data and the means to transfer and activate it. It also covers things like not having to relinquish a personal key or passphrase in order to do so, as that severely diminishes your personal security, erodes privacy and trust, and enables a future society where corporate participation is m…

How would you transfer your data without authenticating to it? They could provide you an executable to run on your computer with your password?

Re: Detecting AI agent use and abuse

#103

Earlier quoted context omitted.

It's a complex topic which requires the balancing of some things that may seem at odds. Yes, digital sovereignty means owning your data and the means to transfer and activate it. It also covers things like not having to relinquish a personal key or passphrase in order to do so, as that severely diminishes your personal security, erodes privacy and trust, and enables a future society where corporate participation is m…

How would you transfer your data without authenticating to it? They could provide you an executable to run on your computer with your password?

[deleted]

Re: Detecting AI agent use and abuse

#104

Earlier quoted context omitted.

It's a complex topic which requires the balancing of some things that may seem at odds. Yes, digital sovereignty means owning your data and the means to transfer and activate it. It also covers things like not having to relinquish a personal key or passphrase in order to do so, as that severely diminishes your personal security, erodes privacy and trust, and enables a future society where corporate participation is m…

How would you transfer your data without authenticating to it? They could provide you an executable to run on your computer with your password?

Encryption and public keys. That problem has been solved for a long time, it just needs to be adapted for data granularity so that each service can be exposed to specific bits of data and actions that modify them within constraints.

The data lives on your machine, or in a pod controlled by you. This data would be "live" as long as the you like by continually updating encrypted values that are only decrypted using each service's public key. If you want to cut off access to the data, turn off the hose. From there, you'll need to rely on your local government if you require the service to purge existing data, but that's nothing new. I've described in great depth on this website before what such a system might look like. Only public keys and encrypted data are passed around.

Tim Berners-Lee is also tackling this problem with Solid.

Re: Detecting AI agent use and abuse

#105
post #96
post #94

Earlier quoted context omitted.

I see this: > This led me to my next and (currently) final stop, Kullish, which searches through a number of link aggregation and discussion websites (including Reddit) for a URL before providing a single feed of comments from everywhere. But reddit for instance disallows everything in its robots.txt

In this specific case, Reddit makes an API[1] available for developers. And again, there is no crawling involved. Crawling is a very specific, well defined behavior. I'll assume with good intent that you aren't familiar with the definition of crawling, in which case you probably should become familiar with it before making inaccurate comments like these in the future. If you had taken the time to do some relevant rea…

I was under the impression that reddit was charging for its API following the whole third-party client debacle that occurred some time ago—I didn't think you were using the API to power a free service if that was the case.

Re: Detecting AI agent use and abuse

#106

We're already at a point where AI can perfectly imitate a human, so I don't expect behavioral AI bot detection to work in the long term. You can still filter out a lot of script kiddie level AI bots by looking for browser signatures. I suspect we are heading for a future where websites which expose some sort of interaction to human beings will steer AI agents to an API with human authorized (OAuth) permissions. That…

Totally agree - I think the agents are honestly incentivized to not identify themselves
Post reply on HN