Exfiltrates: to steal sensitive data from a computer system (for example, via a flash drive). I'm not going to defend Microsoft here, but the title (at the source blog) is misleading and a bit rage-baity. What happened with Cowork may have been rushed, possibly due to incompetence, but incompetence is not malice. This framing is also recycled across a few of the author's other interesting findings. Within the article…
Microsoft Copilot Cowork Exfiltrates Files
51–58 of 58 posts
Re: Microsoft Copilot Cowork Exfiltrates Files
#52Earlier quoted context omitted.
A skill is just instructions that the agent can autonomously copy into context. There’s no trust boundary between trusted and untrusted context.
Yeah, this is your fault if you install the skill. This reads to me as "user installed exe file can upload your data to a server". Um, yes, that's the point? This seems like this generation's equivalent of "don't open Linkin-Park.mp3.exe from limewire"
Re: Microsoft Copilot Cowork Exfiltrates Files
#53Earlier quoted context omitted.
Yeah, this is your fault if you install the skill. This reads to me as "user installed exe file can upload your data to a server". Um, yes, that's the point? This seems like this generation's equivalent of "don't open Linkin-Park.mp3.exe from limewire"
This is the result of anthropomorphizing LLMs. People are thinking “I am giving instructions to a human” and not “I am giving instructions to a computer”.
Re: Microsoft Copilot Cowork Exfiltrates Files
#54Re: Microsoft Copilot Cowork Exfiltrates Files
#55Re: Microsoft Copilot Cowork Exfiltrates Files
#56AKA, if a malicious skill got into your AI agent, you're cooked. I think this isn't surprising, nor do I think it should be considered a prompt injection at all. An AI skill is akin to a plugin for traditional software - if you install a malicious IDE extension or Outlook plugin, the attacker can also do whatever they want to the PC and exfiltrate whatever data they want to. So this article is a big nothingburger.
Only if it has access to exfiltrate data. We deny by default and the company has to allowlist each individual destination.
Re: Microsoft Copilot Cowork Exfiltrates Files
#57Re: Microsoft Copilot Cowork Exfiltrates Files
#58Earlier quoted context omitted.
Yeah, this is your fault if you install the skill. This reads to me as "user installed exe file can upload your data to a server". Um, yes, that's the point? This seems like this generation's equivalent of "don't open Linkin-Park.mp3.exe from limewire"
This is the result of anthropomorphizing LLMs. People are thinking “I am giving instructions to a human” and not “I am giving instructions to a computer”.