Live data from Hacker News

Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

this.weekinsecurity.com

231–240 of 287 posts

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#233

Earlier quoted context omitted.

No fan of Meta, but I think "staggering" is properly determined by the percent of users affected rather than the absolute number. It's staggering to an SMB with 100k customers; it's bad, but not "staggering" to an internet juggernaught with 3B MAU.

Twenty _thousand_ people had their personal data stolen, many of them relied on these accounts to run their business, many put at risk of hackers impersonating them. Meta in a fair world should be forced to financially compensate these people. They built a world where many people basically have to use their products for their jobs and then failed to look after the data because they wanted to replace customer support…

> Meta in a fair world should be forced to financially compensate these people.

In a fair world, Meta and companies like it wouldn’t exist.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#234
post #219

Earlier quoted context omitted.

way higher than other countries You must live in Monaco. Wikipedia has the United States #80. https://en.wikipedia.org/wiki/List_of_countries_by_traffic-r...

Wikipedia has the United States #80. Where do you see that? With 14.2/100K the US comes in at 111/190

Order by deaths per inhabitant and it is 80.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#235
Meta is clearly staying true to their ethos. “Move fast and break things”, “ask for forgiveness, not permission”, “have your security researcher delete their own email email by accident and then refuse to learn anything and use that same system to manage user accounts”.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#236
post #3

> "The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account," said Meta in its breach notice. I'm not sure "worked properly" and "as intended" accurately describe this situation.

They're saying: our AI worked perfectly, we just prompted it wrong.

As you do. All AI failures are caused by bad prompting because AIs are perfect.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#237

Earlier quoted context omitted.

“The strait of Hormuz is open so long as Iran does not fire missiles at ships.”

"The numbers will go down as soon as you quit testing"

The actual quote was "if you don't test, you won't have cases"

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#238
post #88

Earlier quoted context omitted.

You joke but this is almost literally what Chain-of-Thought does, at least in the early days. They basically just added "Wait," to the model's output and fed it back to the model iirc

This can't be a trillion dollar industry...

It's the ELIZA effect.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#239
post #99

Earlier quoted context omitted.

Read that as "worked as written" and "we disclaim any consequential or incidental damages and do not warrant this software." I continue to believe we could fix a lot of things in the US if we updated the UCC[1] to disallow 'disclaiming liability on software used in a product.' [1] Universal Commercial Code -- https://www.law.cornell.edu/ucc

I've always wanted to expose myself to unlimited legal liability by distributing open source software.

They did say a product. Is it a product if you're not selling it or even giving it away but you just made it available for download?

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#240

Earlier quoted context omitted.

This is not how liability works, anywhere. So I write a piece of code that "makes your screen do cool things" and it causes the power supply to fail on those screens. Someone reports that bug to me and I check it out and say "Oh, shit it does break power supplies." Then I immediately put a notice on and in the code that says "WARNING: This code will break the power supply of your montitor." And I put that warning in…

I broadly agree with you but TBF to the earlier comment consider what would happen if a FOSS author did something wrong and was found to be liable. How about curl for example? That sees use in car infotainment systems among other things and cars can be pretty expensive and there sure are an awful lot of them. The point is that we should be able to accommodate someone pushing a hobby project to github under a permissi…

The EU CRA handles this by putting liability on someone who integrates FOSS into a product instead of someone who wrote it. Because it doesn't make sense to put liability for unforeseen downstream uses on someone who gave away something they made in their spare time. Now, if it was a virus, you're still liable for distributing a virus.
Post reply on HN