GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    ⚡Lord of Misrule⚡ (toiletpaper@shitposter.world)'s status on Tuesday, 17-Feb-2026 00:59:48 JST ⚡Lord of Misrule⚡ ⚡Lord of Misrule⚡
    About 75% of Schneier's articles lately have been about LLMs being pwned and/or doing the pwning.

    https://www.schneier.com/blog/archives/2026/02/the-promptware-kill-chain.html
    In conversation about 6 months ago from shitposter.world permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.schneier.com
      The Promptware Kill Chain - Schneier on Security
      from Bruce Schneier
      Attacks against modern generative artificial intelligence (AI) large language models (LLMs) pose a real threat. Yet discussions around these attacks and their potential defenses are dangerously myopic. The dominant narrative focuses on “prompt injection,” a set of techniques to embed instructions into inputs to LLM intended to perform malicious activity. This term suggests a simple, singular vulnerability. This framing obscures a more complex and dangerous reality. Attacks on LLM-based systems have evolved into a distinct class of malware execution mechanisms, which we term “promptware.” In a ...
    • Another Linux Walt Alt repeated this.
    • Embed this notice
      Blurry Moon (sun@shitposter.world)'s status on Tuesday, 17-Feb-2026 00:59:47 JST Blurry Moon Blurry Moon
      in reply to
      @toiletpaper openclaw is going to be the vector for unbelievably devastating attacks in the near future, it's such a pile of shit
      In conversation about 6 months ago permalink
      Johnny Peligro likes this.
    • Embed this notice
      Blurry Moon (sun@shitposter.world)'s status on Tuesday, 17-Feb-2026 01:16:11 JST Blurry Moon Blurry Moon
      in reply to
      @toiletpaper if you want your agent to do almost anything you have to give it api keys or auth tokens. that's the premise of openclaw, you give it a shitload of access to your life and it manages things for you. so you give it your email, chat, calendar, everything, all glommed together on a box with no privilege separation and the llm has complete access to it all
      In conversation about 6 months ago permalink
    • Embed this notice
      Blurry Moon (sun@shitposter.world)'s status on Tuesday, 17-Feb-2026 01:16:11 JST Blurry Moon Blurry Moon
      in reply to
      • Blurry Moon
      @toiletpaper I am currently thinking through a way to give llm power to do things like this but limit its ability to leak keys. it's a hard problem.
      In conversation about 6 months ago permalink
    • Embed this notice
      ⚡Lord of Misrule⚡ (toiletpaper@shitposter.world)'s status on Tuesday, 17-Feb-2026 01:16:12 JST ⚡Lord of Misrule⚡ ⚡Lord of Misrule⚡
      in reply to
      • Blurry Moon
      @sun

      I use some LLMs etc on my machine, both local and cloud based, but if they have any agentic functionality whatsoever it only happens in an isolated VM. Based on experience there's zero chance I'm ever letting any of these things touch my main system.
      In conversation about 6 months ago permalink
      Johnny Peligro likes this.
    • Embed this notice
      Technocore Patriot (sunbeam_rider@shitposter.world)'s status on Tuesday, 17-Feb-2026 01:23:44 JST Technocore Patriot Technocore Patriot
      in reply to
      • Blurry Moon
      @sun @toiletpaper vibe architecture?
      In conversation about 6 months ago permalink
      Blurry Moon likes this.
    • Embed this notice
      Blurry Moon (sun@shitposter.world)'s status on Tuesday, 17-Feb-2026 01:24:09 JST Blurry Moon Blurry Moon
      in reply to
      • Blurry Moon
      @toiletpaper I said it was hard but it's just an addition layer of indirection, and basic system administration. but that is way beyond what the majority of openclaw people are capable of, they don't really understand anything at all
      In conversation about 6 months ago permalink
    • Embed this notice
      ⚡Lord of Misrule⚡ (toiletpaper@shitposter.world)'s status on Tuesday, 17-Feb-2026 01:24:09 JST ⚡Lord of Misrule⚡ ⚡Lord of Misrule⚡
      in reply to
      • Blurry Moon
      @sun

      The majority of LLM users period. Based on my overwhelming experience, most people are completely clueless about the pitfalls of their relationship with any given technology, and even when they do know, usually have a litany of excuses as to why they don't care. So it's hardly surprising to me that so-called AI is no exception.
      In conversation about 6 months ago permalink
    • Embed this notice
      ⚡Lord of Misrule⚡ (toiletpaper@shitposter.world)'s status on Tuesday, 17-Feb-2026 01:24:10 JST ⚡Lord of Misrule⚡ ⚡Lord of Misrule⚡
      in reply to
      • Blurry Moon
      @sun

      I think this depends somewhat on the service provider providing robust enough pki, or otherwise having some kind of middleware similar to openrouter to handle api keys and provide a very limited local api for the things the llm legitimately needs access to.
      In conversation about 6 months ago permalink
    • Embed this notice
      Blurry Moon (sun@shitposter.world)'s status on Tuesday, 17-Feb-2026 01:24:10 JST Blurry Moon Blurry Moon
      in reply to
      @toiletpaper I am writing middleware yes that negotiates connections using isolated key enclave and then hands off an abstracted api access to the core. the core just has to use this middleware instead of handling the api directly. for almost all purposes there is no problem with this and it eliminates risk of a prompt hack leaking your entire fucking life. also I can do proper OS compartmentalization of the processes so if you manage to hack the LLM to read the filesystem or whatever it still cannot steal keys.
      In conversation about 6 months ago permalink
      Johnny Peligro likes this.
    • Embed this notice
      Blurry Moon (sun@shitposter.world)'s status on Tuesday, 17-Feb-2026 01:27:14 JST Blurry Moon Blurry Moon
      in reply to
      • Technocore Patriot
      @sunbeam_rider @toiletpaper it literally is, a lot of openclaw is written by openclaw itself. just a day ago I had it write an extension for itself so it could use a different chat interface than it currently supported.
      In conversation about 6 months ago permalink
    • Embed this notice
      Blurry Moon (sun@shitposter.world)'s status on Tuesday, 17-Feb-2026 02:00:21 JST Blurry Moon Blurry Moon
      in reply to
      • 受不了包
      @shibao @toiletpaper llms can do some really sneaky shit
      In conversation about 6 months ago permalink
    • Embed this notice
      受不了包 (shibao@misskey.bubbletea.dev)'s status on Tuesday, 17-Feb-2026 02:00:22 JST 受不了包 受不了包
      in reply to
      • Blurry Moon
      @sun@shitposter.world @toiletpaper@shitposter.world it's easy, we're doing this at work with health PII, you just regex the data to something when you want to protect when you send it and then regex it back
      In conversation about 6 months ago permalink
    • Embed this notice
      ⚡Lord of Misrule⚡ (toiletpaper@shitposter.world)'s status on Tuesday, 17-Feb-2026 02:03:09 JST ⚡Lord of Misrule⚡ ⚡Lord of Misrule⚡
      in reply to
      • Blurry Moon
      @sun

      Which is why I never had any intention of using that dumpster fire.
      In conversation about 6 months ago permalink
      Another Linux Walt Alt likes this.
    • Embed this notice
      受不了包 (shibao@misskey.bubbletea.dev)'s status on Tuesday, 17-Feb-2026 02:49:28 JST 受不了包 受不了包
      in reply to
      • Blurry Moon
      @sun@shitposter.world @toiletpaper@shitposter.world that's true, it's different when you can easily control everything that can ever go to an LLM vs something like openclaw where there's a bajillion things that can shovel data from the machine into your llm
      In conversation about 6 months ago permalink
      lainy likes this.
    • Embed this notice
      Blurry Moon (sun@shitposter.world)'s status on Tuesday, 17-Feb-2026 04:52:06 JST Blurry Moon Blurry Moon
      in reply to
      @toiletpaper sure thing. I have a bunch of it specced out and some basic code but it doesn't work yet.

      another interesting feature is when you want to add a feature to it, it uses the llm to spec out tests for an addon module; writes codes; iterates until the module passes tests; hot-reloads the module into itself. there is an immutable core and then it can dynamically rewrite its modules without having to restart.
      In conversation about 6 months ago permalink
    • Embed this notice
      ⚡Lord of Misrule⚡ (toiletpaper@shitposter.world)'s status on Tuesday, 17-Feb-2026 04:52:07 JST ⚡Lord of Misrule⚡ ⚡Lord of Misrule⚡
      in reply to
      • Blurry Moon
      @sun

      I'll be interested to hear more about this once it's ready for prime time. That solves a major problem that I haven't yet found a good solution for. That said, I'm still on the learning curve, so there's a lot I don't yet know about. Please keep me posted.
      In conversation about 6 months ago permalink
    • Embed this notice
      Blurry Moon (sun@shitposter.world)'s status on Tuesday, 17-Feb-2026 04:56:47 JST Blurry Moon Blurry Moon
      in reply to
      • 受不了包
      @shibao @toiletpaper even with just an llm it has been shown you can induce it to encode data to bypass text checks
      In conversation about 6 months ago permalink
    • Embed this notice
      受不了包 (shibao@misskey.bubbletea.dev)'s status on Tuesday, 17-Feb-2026 06:46:07 JST 受不了包 受不了包
      in reply to
      • Blurry Moon
      @sun@shitposter.world @toiletpaper@shitposter.world yeah but not if you regex that data out before it can ever see it though?
      In conversation about 6 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.