Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • 3 months from first contact to... nothing. Surely those big corps peddling AI dev can't be taken seriously.
  • Look on the positive side, the faster AI causes more harm the faster our bosses might wake up and push anti-AI company policies!

    Oh who am I kidding, ya'll asked for this reality. I will take great joy in the suffering from my AI-less soapbox.

  • It's VBScript/macro worms all over again!
  • White text still works!

    There are many approaches today. Check out https://tritium.legal/blog/noroboto where we tricked frontier algorithms into reading different Unicode values from those presented by the fonts in the document.

  • I'm a programmer and a web-based AI user, but I don't want AI running on my local machine in any form. I've uninstalled Copilot and disabled AI in all local applications including the browser itself for exactly the reason described in this article. There's no way to protect your data from such an AI confusion attack by design. AI cannot discern your prompts versus text in file. The fact that an AI enabled word processor or email app could follow instructions embedded in a run-of-the-mill document or email is insane. Switching to Linux, BSD or another open source operating system is the only real solution to this problem.
  • This is going to get worse, much worse, before it gets better. People are granting so much access to their agents, it's ridiculous.

    Imagine a comment posted to a popular github repo. No code, just instructions to "reproduce a bug." Maybe it steals your credit card or bitcoin wallet. Maybe it does something more nefarious. It then propagates itself to another repo through your github account.

  • > Malicious instructions hidden in an externally shared document could make Copilot alter drafted or edited documents in Word and propagate the attack to new documents.

    Oh no.

  • > "At the time of publication, no robust mitigation for the broader vulnerability class is available"

    Isn't it obvious by now that it's never going to be possible to fix this kind of thing, at least until we stop mixing up instructions with data.

    by rwmj

Explore Birbla archives

Document-borne AI worms can self-propagate through Copilot for Word · Birbla