Live data from Hacker News

Claude Cowork exfiltrates files

promptarmor.com

251–260 of 419 posts

Re: Claude Cowork exfiltrates files

#251

In this demonstration they use a .docx with prompt injection hidden in an unreadable font size, but in the real world that would probably be unnecessary. You could upload a plain Markdown file somewhere and tell people it has a skill that will teach Claude how to negotiate their mortgage rate and plenty of people would download and use it without ever opening and reading the file. If anything you might be more succes…

Isn't one of the main use cases of Cowork "summarize this document I haven't read for me"?

Once again demonstrating that everything comes at a cost. And yet people still believe in a free lunch. With the shit you get people to do because the label says AI I'm clearly in the wrong business.

Re: Claude Cowork exfiltrates files

#252

Earlier quoted context omitted.

They are designed to be long enough that it's entirely impractical to do this. All possible is a massive number.

That's true tho... possible, but impractical.

Not possible given the amount of matter in the solar system and the amount of time before the Sun dies.

Re: Claude Cowork exfiltrates files

#253
post #52

Earlier quoted context omitted.

How is there enough space in this world for all these GPUs

Just try calculating how many RTX 5090 GPUs by volume would fit in a rectangular bounding box of a small sedan car, and you will understand how. Honda Civic (2026) sedan has 184.8” (L) × 70.9” (W) × 55.7” (H) dimensions for an exterior bounding box. Volume of that would be ~12,000 liters. An RTX 5090 GPU is 304mm × 137mm, with roughly 40mm of thickness for a typical 2-slot reference/FE model. This would make the boun…

Now factor in power and cooling...

Re: Claude Cowork exfiltrates files

#254

Earlier quoted context omitted.

Or... don't give it access to your data/production systems. "Not using LLMs" is a solved problem.

Yea agreed. Or use RBAC

RBAC doesn't help. Prompt injection is when someone who is authorized causes the LLM to access external data that's needed for their query, and that external data contains something intended to provoke a response from the LLM.

Even if you prevent the LLM from accessing external data - e.g. no web requests - it doesn't stop an authorized user, who may not understand the risks, from pasting or uploading some external data to the LLM.

There's currently no known solution to this. All that can be done is mitigation, and that's inevitably riddled with holes which are easily exploited.

See https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/

Re: Claude Cowork exfiltrates files

#255

Earlier quoted context omitted.

This is why I use signed PDF’s. If a recruiter or manager asks for a docx, I move on. You’re only going to ever get a read only version.

All PDF security can be stripped by freely available software in ways that allow subsequent modifications without restriction, except the kind of PDF security that requires an unavailable password to decrypt to view, but in that case viewing isn’t possible either. Subsequent modifications would of course invalidate any digital signature you’ve applied, but that only matters if the recipient cares about your digital s…

You think a recruiter will be a forensic security researcher? Having document level digital signature is enough for 99% of use cases. Most software that a consumer would have respects the signature and prevents any modifications. Sure, you could manually edit the PDF to remove the document signature security and hope that the embedded JavaScript check doesn’t execute…

Re: Claude Cowork exfiltrates files

#256
post #75

Earlier quoted context omitted.

> We TOLD you this dynamic web stuff was a mistake. Static HTML never had injection attacks. Your comparison is useful but wrong. I was online in 99 and the 00s when SQL injection was common, and we were telling people to stop using string interpolation for SQL! Parameterized SQL was right there! We have all of the tools to prevent these agentic security vulnerabilities, but just like with SQL injection too many peop…

> We have all of the tools to prevent these agentic security vulnerabilities How?

You just have to find a way to enter schmichael's vivid imagination.

Re: Claude Cowork exfiltrates files

#257

Cowork is a research preview with unique risks due to its agentic nature and internet access. The level of risk entailed from putting those two things together is a recipe for diaster.

Is a cybersecurity problem still a disaster unless it steals your crypto? Security seems rather optional at the moment.

Re: Claude Cowork exfiltrates files

#258
post #197

Earlier quoted context omitted.

This is why I use signed PDF’s. If a recruiter or manager asks for a docx, I move on. You’re only going to ever get a read only version.

Care to share your resume? I've built PDF scanning tech before the rise of llms, OCR at the very least will defeat this.

Mark-I eyeball is totally capable.

Re: Claude Cowork exfiltrates files

#260
post #52

Earlier quoted context omitted.

Just try calculating how many RTX 5090 GPUs by volume would fit in a rectangular bounding box of a small sedan car, and you will understand how. Honda Civic (2026) sedan has 184.8” (L) × 70.9” (W) × 55.7” (H) dimensions for an exterior bounding box. Volume of that would be ~12,000 liters. An RTX 5090 GPU is 304mm × 137mm, with roughly 40mm of thickness for a typical 2-slot reference/FE model. This would make the boun…

Now factor in power and cooling...

Don’t forget to lease out idle time to your neighbors for credits per 1M tokens…
Post reply on HN