logoalt Hacker News

singpolyma3yesterday at 8:24 PM2 repliesview on HN

This is true but it's not really a security scenario. The LLM isn't an attacker it's just an unreliable tool.


Replies

syntheticnatureyesterday at 8:58 PM

Unreliable/stupid is worse than malice, here.

show 1 reply
felixgalloyesterday at 8:34 PM

all unreliable tools are attackers. Even if you're using well-aligned LLMs like Opus, you should assume that any input you give it -- including all dependencies from npm, etc. -- are at risk of compromise, which could result in attempted exfiltration of data or system takeover. You can be absolutely sure that there are thousands of well-motivated hacker groups, both national and private, looking for ways in.