all 40 comments

sorted by: hot top controversial new old
[–] 41 points 3 days ago* (1 child)

Article title

Copilot worm can spread through Microsoft Word docs

Post title

Microsoft confirms an AI worm is propagating through Copilot and other MS apps

The article talks about a document-born self propagating virus demonstration a group of security researchers made because LLMs/Copilot doesn't distinguish between data and instructions. The article does not imply this was seen in the wild.

  • source
  • hideshow 2 child comments
  • [–] 14 points 3 days ago (1 child)

    True, itś a bad headline.

    But since cloaking instructions inside data has been a thing since little Bobby Tables, and I've been hearing about this vector for months, it's safe to assume someone somewhere has done this with CoPilot and Word by now.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 50 points 3 days ago

    You promise?

  • source
  • [–] 46 points 3 days ago

    Consequences of actions and all that.

    Bit of schadenfreude watching these bloated, monopolistic tech companies screw themselves over in hubristic pursuit of more power and profit.

  • source
  • [–] 45 points 3 days ago (2 children)

    Anyone using AI for a financial report deserves exactly what they asked for.

  • source
  • hideshow 4 child comments
  • [–] 15 points 3 days ago (4 children)

    Not knowing anything outside of tax filing software how much more automated can financial work get

  • source
  • parent
  • hideshow 8 child comments
  • [–] 5 points 3 days ago

    Financial software is one of those things that companies just don’t update for decades. It wouldn’t surprise me at all if somebody had started handing off a bunch of their payroll or accounting reporting to an AI instead of just updating to a newer software with more features.

  • source
  • parent
  • [–] 2 points 3 days ago

    I have worked in regulated industries for a long time. I guess it cannot be properly automated because laws change all the time (like every other month because some politician got a stupid idea and you have to start from scratch once again). That would be why we have companies dedicated to handling finances, taxes, and laws.

  • source
  • parent
  • [–] 1 point 2 days ago

    I don't use ms stuff, but how sure are users that the ai that's pervasive throughout the system isn't peeking at the data even if you didn't invoke it explicitly?

    Maybe it doesn't and I'm just being overly paranoid, otoh, this is ms, so...

  • source
  • parent
  • [–] 38 points 3 days ago (1 child)

    “To my knowledge, this is among the first public demonstrations of document-borne AI-worm self-propagation through normal workflows in a mainstream commercial productivity suite.”

    What a fucking sentence my god. Every scientist in cyberpunk shit should talk exactly like this.

  • source
  • hideshow 2 child comments
  • [–] 16 points 3 days ago (1 child)

    All this could boil down to:

    "To my knowledge, this is among the first document-borne AI-worm propagations through a productivity suite"

    self-propagation

    it's useless, "worm" already implies that

    normal workflows

    this implies there is an abnormal workflow that already had this problem- which, as far as i know, didn't

    mainstream commercial productivity suite

    oh my fucking god, just say productivity suite, it never happened with non-mainstream or non-commercial suites either because guess what, NO ONE ADDED AIs IN TO THEM BEFORE, unless we consider shit like Notion or whatever "productivity suite" too but i doubt

  • source
  • parent
  • hideshow 2 child comments
  • [–] 27 points 3 days ago (1 child)

    This is what happens when you don't separate instructions from data. It's boot sector viruses all over again

  • source
  • hideshow 2 child comments
  • [–] 3 points 3 days ago (1 child)

    Johnny drop tables strikes again

  • source
  • parent
  • hideshow 2 child comments
  • [–] 8 points 3 days ago (1 child)
  • [–] 2 points 3 days ago (1 child)

    "Common short male nickname with repeated letters and ending in -y" drop tables

    Is how my brain stored that info. And always does. Been corrected before, never remember the correction. Might remember that there IS a correction, still wrong. Like in this case.

    Another satisfying ADHD moment

  • source
  • parent
  • hideshow 2 child comments
  • [–] 8 points 2 days ago (1 child)

    the only way to block it is to get AI to differentiate instructions from data, which is impossible today.

    Heh, it's like a buffer overflow

  • source
  • hideshow 2 child comments
  • [–] 14 points 3 days ago (2 children)

    JUST MORE MARKETING FOR AI. Don’t fall for it!

    The worm is just trying to juice the IPO.

  • source
  • hideshow 4 child comments
  • [–] 3 points 3 days ago

    Idk all those “its a sUpEr HaXoR” articles act as it AI is too powerful or something, and in so doing act as marketing.

    This is more “AI is too stupid and overly trusted, and could easily wreck your data and operations”. If anything, this news should be pushing every major corporation to immediately restrict usage and eliminate any level of trust that they have in AI being used in their company to automate anything. Its definitely not positive news for any IPO

  • source
  • parent
  • [–] 11 points 3 days ago* (2 children)

    This stock photo is wild with those fishing bait rubber "worms"

  • source
  • hideshow 4 child comments
  • [–] 4 points 3 days ago (1 child)

    Oh, cool. Just when my job mandated a training that requires installation of a local LLM that reads your emails and documents. Maybe we’ll get fucked by someone getting an email.

  • source
  • hideshow 2 child comments
  • [–] 4 points 3 days ago

    That’s an interesting twist on the Tower of Babel

  • source
  • [–] 1 point 3 days ago

    Claims it's only Copilot, but what about any other LLM connected to document workflow?

  • source
  • [–] 1 point 3 days ago (1 child)

    Fantastic news. Sort of like AI convincing the people who use AI to off themselves, it's the problem slowly taking care of itself.

  • source
  • hideshow 2 child comments
  • [–] -3 points 3 days ago (2 children)

    Yeah, fuck vulnerable people who've been made lonely by our system that makes us feel isolated and full of despair so it can sell us companionship and hope. If they're too weak to life in this fucked up world, they deserve to die

    /s

    Seriously, though, did you think through this shit before you hit send or just think "people who like ai bad, bad people should die"?

  • source
  • parent
  • hideshow 4 child comments
  • [–] 2 points 3 days ago (1 child)

    Ah yes, the problem looking for a solution is the answer to all our woes

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 3 days ago

    False dichotomy, dude. The positions aren't pro or anti ai. I'm pro-human, even if those humans made silly mistakes. I don't think anyone should be pushed to the point of suicide, regardless of what's doing the pushing.

    Fuck AI.

    Fuck treating your fellow man like they're less than

  • source
  • parent
  • [–] 1 point 3 days ago* (last edited 2 days ago)

    If you consider the massive focus on AI that will likely eventually put pretty much everyone out of work and could actually lead to a global dystopia to be a problem, then AI use wrecking the installations or files of devices it has access to and convincing all of it's users to kill themselves is certainly a solution. Maybe not the best solution, or the most like giving everyone a big warm hug and sticky kiss to make their booboos go away, but a solution.

    If the process sped up to the point where within the next few hours every single computer AI had CLI access to or some other way to wreck had that happen and every single human who interacts with AI was convinced to off themselves... well, AI could effectively stop being any issue at all by tomorrow morning.

    Sure, it's not altruistic or the kindest cuddliest thing to say. That doesn't mean it's not true. And there are other genuine benefits. It would likely bankrupt (or suicide) a lot of awful people; it would help quite a bit with global pollution/emissions both simply because there are an estimates 1-2 billion people who interact with AI regularly and because all of them offing themselves would impact the wealthier who tend to be the worst offenders far more than the poorest; with so many people gone it would help with overcrowding and homelessness; it would push the industries that have had job loss due to AI to rehire humans; and there would certainly be a boom in a lot of industries... less chipper examples being everything relating to coffins, funerals, cremations, etc.

    It would also pretty much completely stave off the worst of the potential future dystopias we could be quickly heading towards, at least for a few decades. Humans do tend to repeat awful mistakes thinking they'll do better this time, but at least it would end or push back the scenarios once firmly relegated to science fiction where AI takes over and wipes out all or most of humanity, or AI remains subservient to it's human masters but after automating human labor with robotics the people in charge become fully corrupt and cause most of humanity to die off so the world becomes their personal paradise.

    One could argue that given the chances for things to go wrong enough that the bulk of the species is wiped out, everyone who converses with AI painlessly offing themselves would be for the greater good.

    All: For the greater good.

  • source
  • parent