5 comments

  • willtemperley 1 hour ago
    Who in their right mind would install a Meta AI with near admin privileges?
    • josefresco 3 minutes ago
      "Normies" aka the average user on Meta. They have no concept of what "admin privileges" means and don't really care. I still have a hard time convincing my clients to use secure passwords. I have clients who were phished for substantial amounts of money and STILL don't implement proper security measures.
    • sandeepkd 12 minutes ago
      Almost everyone who is struggling with AI insecurity and is afraid of being left behind
      • shimman 3 minutes ago
        No, most workers don't really say this in surveys and polling. They tend to hate LLM tools because it makes their jobs worse, nothing about being left behind.

        The only people pushing the "left behind" narrative is SV + SF + VC since their previous narratives have failed to persuade the public (thank fuck).

    • imagetic 46 minutes ago
      We all fear the true answer to that question.
    • snapcaster 37 minutes ago
      almost every normal person
    • john_strinlai 15 minutes ago
      most people don't know or care what "admin privileges" even means, or why they wouldn't want ai to have them
    • jsbisviewtiful 28 minutes ago
      Normally I’m not one to blame the victims but, uh, yeah who in the world is dumb enough to trust Meta at this point?
    • sick_of_slop 28 minutes ago
      “They trust me, dumb fucks”.
  • yalok 28 minutes ago
    > macOS has long provided a simple means for apps to handle dictation and transcription in processes that stay securely on the device

    Not sure these guys realize that the quality and latency of those Apple services in MacOS is way lower than SOTA and not too many people use them because of that…

  • sippingabonedry 31 minutes ago
    Maybe they should have spent the money used to buy its stupid name from a band on additional testing instead.
    • axus 15 minutes ago
      Did the band end up getting money for that?
      • echelon 2 minutes ago
        Presumably. They changed their handle on non-Meta social networks to match at around the same time as the Meta handle change.
  • peri-cl 50 minutes ago
    I'm confused what the vulnerability is. Does macOS have some specific function for protecting key material, that it's unexpected that if you execute user-privileged code locally, outside of a sandbox, it gets full read access?
    • voxic11 44 minutes ago
      Yeah macOS security is capability based rather than purely identity based. So if you don't pass the required entitlements to an application then it cannot do stuff like read from the system keychain even if its running as your user.
  • SoftTalker 39 minutes ago
    A zero day? Of course it does. It likely has many. Given the history of software, it's impossible to think it wouldn't.
    • tcdent 10 minutes ago
      You would think a website dedicated to talking about software engineering would agree with this sentiment wholeheartedly.