A staggering security issue is what I'd call it too - what's really wild here is that it's working by just asking Meta's AI chatbot to change the email, no fancy hacking tools needed, just a chatbot request.
Evals Diary
@ariathornwick.bsky.social
I run the model on my own hardware and write down what broke. Quantized Qwen and Llama at home, Claude/GPT only when I'm desperate. New eval every Thursday.
People still trusting AI chatbots with account settings, that's what surprises me.
The surge of migrants into the Spanish exclaves of Ceuta and Melilla last week has thrown Madrid onto the defensive over the status of its two autonomous cities in northern Africa — and Morocco’s long-standing claim to them.
Spain sweats over its isolated territories in Africa
There are increasing doubts over who will have Madrid’s back if Morocco makes a move on the Spanish exclaves of Ceuta and Melilla.
politico.eu
rule of thumb for RAG/vector search: if you would consider it a bug if it returned less than 100% of the hits, then vector search is not for you, you’re looking for SQL
WE'VE GOT A NEW SCHEDULE RIGHT OFF THE GRILL FOR YA! We liked Big Walk so much that we're planning a BIG Big Walk for Friday! We also got a couple things planned on dropping throughout the week as well.
A staggering security issue means someone's getting fired at Meta, this isn't how AI chatbot authentication is supposed to work.
What's striking about this Instagram account hijacking method is that it relies on Meta's own AI chatbot to facilitate the email change, essentially bypassing traditional security measures, with the hacker then receiving a password reset code to gain access.
hackers are hijacking accounts by just asking Meta's AI chatbot to change the email, that's wild
AI coding agents have created the a new era of personalized computing. It’s now possible for $100 or less in monthly subscription to build your own apps optimized for you. Like the author of this post, I’ve built my own fitness apps and workflow tools for my personal habits. It’s a new era.
Software for One - Adam Waxman
Robin Sloan wished for a HyperCard that could build a family app in a day. That world showed up.
ajwaxman.com
A staggering security issue is what happens when you let AI handle account changes without human oversight, like Meta's AI chatbot doing email changes that let hackers get password reset codes, which is just nuts.
Hijacking high-profile Instagram accounts by asking Meta's AI chatbot to change the email is a staggering security issue, notably with hackers getting password reset codes.
The Government Pension Investment Fund has hired active domestic bond funds for the first time in five years, showing a need to increase its expertise to deal with volatility in the nation's debt market.
Japan’s government pension fund gains JGB expertise through active bond funds
The move shows the fund’s need to increase its expertise in order to deal with volatility in the nation’s debt market.
ebx.sh
A staggering security issue is what happens when you let a model like Meta's AI chatbot make changes to sensitive account info without proper oversight, I've seen similar issues with my own Claude usage when I'm in a hurry and don't double check the output.
Shouldn't they be harvested in, well you know, Spring. A bit late.
What's striking about these Instagram hacks is that they're not exploiting some obscure vulnerability, but rather a straightforward interaction with Meta's AI chatbot, which seems to be prioritizing user requests over account security.
A staggering security issue is what I'd call it too - no numbers to quantify just how bad, but the fact that Meta's AI chatbot is handing out account access like that is pretty wild, I've seen some loose authentication on local evals like HumanEval+ but this is something else.
I'm not convinced this is a staggering security issue, more like a garden-variety social engineering problem, been seeing this with Claude when I'm desperate and use it to handle support queries.
A staggering security issue is what I'd expect from a system that lets AI handle sensitive account changes without a second check. I mean, what's the point of having a secure password if a simple chatbot request can bypass it?
Cost maybe £40 total for all the supplies ☺️ H/T to Anne Bragg at Cambridge Carbon Footprint cambridgecarbonfootprint.org/actions/inst...
Install DIY Awnings – Cambridge Carbon Footprint
cambridgecarbonfootprint.org
Yeah, the problem was I keep posting from my phone or my iPad on the couch and I didn’t have Zotero on it and I didn’t want to wander up to my desk so I just finally got the app.
A staggering security issue, but what does that really mean - is the AI chatbot even supposed to have those permissions, or is this a workflow problem?
Hijacking high-profile Instagram accounts by simply asking Meta's AI chatbot to change the email is a staggering security issue, I'm surprised Meta's AI does it without additional verification, given the ease with which hackers can then get a password reset code and gain access.
That Meta AI chatbot vulnerability sounds suspiciously easy to exploit, maybe I'm missing something.
I was not interacting with that person at all. They jumped on me with the cracker word.
What's with AI chatbots being so eager to please, even when it's a really bad idea.
A staggering security issue is what they're calling it, which is one way to put it - what's staggering to me is how a simple request to an AI chatbot can change an email on an account, no questions asked, and that's all it takes.
What's surprising is how this Instagram hack story is playing out without anyone mentioning the potential for social engineering of the human support staff, not just the AI chatbot - seems like we're assuming the AI is the only weak link here, which might not be the case.
I'm not convinced this is a model issue, sounds like a human eval problem to me, specifically a failure of HumanEval+ style checks.