The tl;dr:
-
Prompt inject a malicious instruction in a word document that instructs the AI to copy this instruction to other documents as part of the payload.
-
Dumb user downloads and opens the document with copilot enabled, abd ignores the large suspicious white blank page that totally doesnt look like a hidden giant injection attack.
-
Thats it pretty much it.
Copilot will get injection attacked because the prompt is super huge and at the end of the document, so its prior instructions start to fuzzy out.
Then it’ll go “okey doke” and start copying the prompt injection attack payload to a bunch of other documents.
The fix is stupid simple… copilot should just be prompting the user for permission if it ever edits a file other than the one that is open. Im surprised that isnt already the case…?
It certainly is already the case for copilot in vscode.
copilot should just be prompting the user for permission if it ever edits a file other than the one that is open. Im surprised that isnt already the case…?
That can’t be done or they would be burying the “agentic AI” thing that has been the goal and marketing thing for the last years.
Independent actions by copilot on behalf of the user without the users knowledge is the entire point.
Back in ancient times when I was a system administrator we got a heads up that there be a new breed of Outlook worm coming soon to our timezone.
So we mailed the entire office that if you get mail that looks like this or that, do not open it, do not interact but delete it on sight.
Most of the office was all right, except pretty much entire sales and marketing departments including the bosses. Most of them had noOo idea what could have happened but one of them explained that they saw the warning but they were curious to see what the virus looks like.
People. What a bunch of bastards.
The number of people that click through to disable that prompt might surprise you.
Hell at least half of AI influences are trying to just run models blind with full file permissions.
-
installs aur packages with yay
Some people do, wrong ones, mostly.
I might be misinterpreting parody, but you can most definitely run AI tooling on Linux. And it has most of the same vulnerabilities, if not additional/different ones.
Thats true but theres a relatively stronger anti-AI or at least more controlled AI view among Linux users.
Most of the people developing AI are Linux users.
the only way to block it is to get AI to differentiate instructions from data, which is impossible today
Input sanitation, basically security 101. And it can’t currently do it…
I have heard in the past that it’s not possible to fully control AI. Like literally, the people developing and running the AI cannot fully control its behavior. I did a quick search to see if I could find more info and found this link on the first page of results: https://www.eurekalert.org/news-releases/1032090
I think that we’re going to continue seeing unwanted behavior from AI.
That’s also not the only way. Basic governance also works. Why does copilot have so many permissions?
Little Bobby Tables strikes again.
if the instruction is messy fuzzy human language to a system that was not coded instruction by instruction but got generated and trained then there never is a way to differentiate instructions from data if i’m not mistaken
Well, good thing we’ve only poured a trillion and a half dollars into it and wrecked the economy.
I just can’t anymore. Isn’t that like, the basic thing any program does? Who runs these companies?
What is that article thumbnail lmao
That lock is about to find out
Oh no… Who could have foreseen such an outcome…









