Aquarium Security and Other Organisational Priors

·LessWrong··

TL;DR a few model providers are learning from private conversations across many organisations, giving their models better representations of how those organisations secure their systems and plausibly making semi-autonomous attacks easier. Private credentials are given directly to LLMs at scale. Beyond the same WiFi password being reused across office-wifis or stored in a Google doc, people post API keys straight into prompts, hardcode them in files, copy them into chats on personal accounts, etc...

Read full article →

Related Articles

Omarchy: Any User Process Can Escalate to Root
trap0xcc · Hacker News · 1d ago
Run macOS Software on Linux
Bluestein · Hacker News · 4h ago
METR and Redwood Offer Holy %^ Postmortem of the HuggingFace Hack
catbird · Hacker News · 1d ago
Bug Blindness
davidmckenna · Hacker News · 2d ago
Hy4 preview
shenli3514 · Hacker News · 2d ago