| ▲ | johnsmith1840 6 hours ago |
| "Inherently needs wide unattended access" And what if you could? What if you could give a space secure enough it could have direct control over your bank account. It may do something dumb but it's boundaries are beyond the agent. It could use your routing number and run your gmail without risk of abusing the routing number. |
|
| ▲ | jagraff 6 hours ago | parent | next [-] |
| How would it have access to my routing number and gmail without the risk of sharing my routing number over gmail? |
| |
| ▲ | johnsmith1840 5 hours ago | parent [-] | | Just assume it's possible, how interesting is it to you? | | |
| ▲ | jagraff 4 hours ago | parent [-] | | Oh I think I misread your comment slightly; I would not be interested in an agent that could do something dumb with my routing number, but if somehow there was an agent that I trusted as much as, eg, the payroll department at my employer, I would absolutely want and use that agent; I would love to have an agent that can handle all of the boring parts of my life such as paying bills, scheduling maintenance, dealing with bureaucracy, etc. | | |
| ▲ | johnsmith1840 4 hours ago | parent [-] | | Dumb's not department, really just a question of how good an AI you want to use. An AI will always be able to do something dumb, just like people. I just mean an AI that could use a routing number or SSN and gmail/slack/whatever at the same time without a leak. | | |
| ▲ | jagraff 4 hours ago | parent [-] | | Yea I think being able not to leak is the bare minimum? But it really depends on how good it is at specific applications; I wouldn't give a tax-preparation agent my SSN unless I was confident that it was no more likely to misfile my taxes than a professional tax preparer. In other words, the risk of harm doesn't need to be zero, just less than the equivalent risk of a human with similar skillset. So I'm comfortable riding in a waymo, and not comfortable giving chatgpt my SSN at this moment in time, but I expect that within 5-10 years (assuming no doom) I will trust some AI agent with my SSN because they will be better at handling sensitive info than humans | | |
| ▲ | fragmede an hour ago | parent [-] | | Then again, given the Equifax/Experian data breaches, your SSN is already out there and probably hoovered up as training data already |
|
|
|
|
|
|
| ▲ | TesterVetter 6 hours ago | parent | prev [-] |
| Its not about agents then. Its about every individual platform providing the means to implement a secure set of permissions for agents AND then not messing up the assignment of permissions to the agent. Even then, a flaw in the authorization design will lead to agent finding it anyway. |
| |
| ▲ | johnsmith1840 an hour ago | parent [-] | | You're right, It must be unifying. The answer is the same as asking how a random human using your routing num or SSN and being 100% the human can't abuse it or leak while "normally" finishing most work. Solve for people and an AI solution naturally falls out. If you're a SV eng I'd tell you to DM if interested but alas. |
|