[–] 2 points 2 years ago* (1 child)

Good example, I hope confirmation will be crucial and hopefully required before actions like this are taken by the device. Additionally I hope the prompt is phrased securely to make clear during parsing that the website text is not a user request. I imagine further research will highlight more robust prompting methods to combat this, though I suspect it will always be a consideration.

  • source
  • parent
  • context
  • [–] 15 points 2 years ago* (3 children)

    Given that personal sensitive data doesn’t leave a device except when authorised, a bad actor would need to access a target’s device or somehow identify and compromise the specific specially hardened Apple silicon server, which likely does not have any of the target’s data since it isn’t retained after computing a given request.

    Accessing someone’s device leads to greater threats than prompt injection. Identifying and accessing a hardened custom server at the exact time data is processed is exceptionally difficult as a request. Outside of novel exploits of a user’s device during remote server usage, I suspect this is a pretty secure system.

  • source
  • parent
  • context
  •  

    TransActual are today publishing an analysis of the flaws in the Cass Report’s approach and conclusions.

    I’m glad this is here. It’s reassuring to see people calling this report out for what it is. And with linked evidence to back up the criticism too.

    view more: next ›