lemmy.helios42.de
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Pro@programming.dev to Technology@programming.devEnglish ·
edit-2
3 months ago

Comet AI browser can get prompt injected from any site, drain your bank account

i.imgur.com

message-square
6
link
fedilink
42

Comet AI browser can get prompt injected from any site, drain your bank account

i.imgur.com

Pro@programming.dev to Technology@programming.devEnglish ·
edit-2
3 months ago
message-square
6
link
fedilink
Comments
  • Hackernews.

Source: zack_overflow on X/Twitter.

  • Brave Research;
  • Guardio Research.
  • Thekingoflorda@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    3 months ago

    How did they not think about this? This is a very basic prompt injection, and it still falls for it.

    • TonyTonyChopper@mander.xyz
      link
      fedilink
      English
      arrow-up
      15
      ·
      3 months ago

      They probably asked AI to write the browser. AI loves writing code with security vulnerabilities

    • Natanael@infosec.pub
      link
      fedilink
      English
      arrow-up
      7
      ·
      3 months ago

      The whole attack model has been known for years already and it isn’t even the first time that specifically an LLM browser plugin has been exploited by page contents

      https://bsky.app/profile/natanael.bsky.social/post/3kr2ud66y2x24

    • criss_cross@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      3 months ago

      Why think when there’s VC money to be had?

Technology@programming.dev

Technology@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !Technology@programming.dev

Share interesting Technology news and links.

Rules:

  1. No paywalled sites at all.
  2. News articles has to be recent, not older than 2 weeks (14 days).
  3. No external video links, only native(.mp4,…etc) links under 5 mins.
  4. Post only direct links.

To encourage more original sources and keep this space commercial free as much as I could, the following websites are Blacklisted:

  • Al Jazeera;
  • NBC;
  • CNBC;
  • Substack;
  • Tom’s Hardware;
  • ZDNet;
  • TechSpot;
  • Ars Technica;
  • Vox Media outlets(including Axios, due to new changes related to trackers on their website);
  • Engadget;
  • TechCrunch;
  • Gizmodo;
  • Futurism;
  • PCWorld;
  • ComputerWorld;
  • Mashable;
  • Hackaday;
  • WCCFTECH;
  • Neowin;
  • Jacobin;
  • Yahoo;
  • Freethink;
  • Big Think;
  • Newsweek.

More sites will be added to the blacklist as needed.

Encouraged:

  • Archive links in the body of the post.
  • Linking to the direct source, instead of linking to an article talking about the source.

Misc:

Relevant Lemmy Communities:

  • Beehaw Technology discussion.
  • Hard Tech news.
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 2 users / day
  • 78 users / week
  • 82 users / month
  • 8.27K users / 6 months
  • 1 local subscriber
  • 734 subscribers
  • 1.83K Posts
  • 4.5K Comments
  • Modlog
  • mods:
  • irelephant [he/him]@programming.dev
  • BE: 0.19.12
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org