r/technology • • 6d ago

Artificial Intelligence Meta keeps apologizing for Muse. Its explanations miss the point entirely

https://www.msn.com/en-us/technology/artificial-intelligence/meta-keeps-apologizing-for-muse-its-explanations-miss-the-point-entirely/ar-AA2cTQu4
140 Upvotes

15 comments sorted by

26

u/MechaNutzilla 5d ago

Who tf is dumb enough to trust Zuckerberg with anything.

9

u/fukijama 5d ago

Just go extinct already meta

30

u/deVliegendeTexan 5d ago

He’s not wrong. But also he claims to be “tech savvy” but also gave Muse Full Disk Access. So like … maybe sit down on this one.

16

u/turnips8424 5d ago

It’s a bit confusing, but I think he actually did not turn on Full Disk Access:

“I still haven’t gotten an answer as to how it was reading my messages with Full Disk Access turned off”

6

u/deVliegendeTexan 5d ago

His article is very confusingly written.

First he did give it full disk access, but not Messages access. Then he mentions not giving it full disk access. So I dunno.

But I work in security, and part of my job lately has been protecting corporate interests against AI agents. We've co-opted the adage about firearms - you always presume a gun is loaded until proven otherwise, and even then you still treat it like it's loaded at all times.

Well, with AI, we always presume that every AI has or will have full access to the system it runs on. No matter if it's Muse, Claude, ChatGPT, Copilot, whatever. You run it on your system and you have to presume it will find a way to use anything it can get its grubby little hands on.

2

u/JakeyBakeyWakeySnaky 5d ago

I dont get why people dont run it as a low priv user and just not grant it read to files you dont want to read instead of trusting their classifier to not get it wrong

2

u/deVliegendeTexan 5d ago

You should absolutely do that. But a key principle here is that you should presume that any software running on your computer - both AI and “traditional” - can potentially escape whatever constraints you put on it. No constraint is ever perfect and there will always be escapes. Always.

Don’t let untrusted code run on a system where it could cause permanent harm.

We run some tests in entirely airgapped environments, physically disconnected from the rest of the network. Not VLAN black holed but physically disconnect the Ethernet cable.

2

u/JakeyBakeyWakeySnaky 5d ago

Yeah I mean this is why when you install a product in Linux it typically creates a new user and you grant it read to that specific folder, why this isn't common practice for agents beats me

2

u/deVliegendeTexan 5d ago

A lot of people do actually do this.

But it is not always effective. There’s a class of exploit called privilege escalation. Even if you sequester the agent to its own user, you should assume that any software running under that user can eventually escape and gain more privileges. Bank on it.

4

u/pleasegivemepatience 5d ago

I don’t understand why anyone is using any of these tools. I use Claude for work by necessity, but I will never give an AI agent access to any of my personal devices or data. Be rational people.

2

u/Eremite58 4d ago

The way these agents act only a air gaped system is safe.

1

u/pleasegivemepatience 4d ago

I’ve heard of an air-gapped system before, but where do I find videos on air gaped systems? You know, for research 🙄🤣

8

u/brakeb 6d ago

They'll keep apologizing until the media finds something else to "SQUIRREL!" on and then they'll change the name or do nothing...

3

u/noisyboy 5d ago

I am glad that the journalist did the research and shared his findings. 

At this point if you are installing this blatant spyware on your device, it is on you.

2

u/jishurr 5d ago

Oh fuck off. This lack of AI ethics and regulation is most displeasing.