Remix.run Logo
▲ alistairSH 8 hours ago

Are all of these just flavors of "the agent has the same permissions as the user"? Not that I want to trust Meta with anything, but I'm guessing it asked for "root" access and the users granted it...?

▲dcss_gardener 7 hours ago | parent | next [-]

Yes, it is clearly designed to give you access to all of this intentionally. Its system prompt (which you can just read in the interface without asking) explicitly instructs it to act on behalf of the user, not meta. All of its memory files, skills, db schema, memory integration system etc are likewise visible because they went out of their way to add an interface for viewing them!

I don't like or trust meta any more than I always did but I don't see how they could have done a "better" job with this. These kinds of agents are inherently pretty risky IMO but I don't see how this one is particularly more than any others.

Playing around with it I really don't get the sense there's any hidden prompt contradicting what's visible. It's nearly gleeful at using the VM in ways that were not intended and likely against meta's interests. I feel like someone must have won a really interesting internal power struggle to get this thing out in this form.

▲jkingsman 6 hours ago | parent [-]

> I really don't get the sense there's any hidden prompt contradicting what's visible

It will happily disclose its entire system prompt (which is interesting in its own right, and worth a read) or pop a reverse shell for you

> I don't see how they could have done a "better" job with this

I generally agree -- the openness is great. However, from experiences both inside and outside of Meta, good execution, a hacker ethic, and transparency ultimately has very little propping it up when money is on the line. In fact, it could be argued that Meta has a shareholder obligation to do profitable things such that even the best intentions can (and usually will) fall in the face of corporate hierarchy and sales numbers.

I think they did a pretty bang up job with Muse (the lack of communication with first-time agent users around how powerfully and confidently they can make horrifying mistakes, and how careful you need to be with prompting, and how even that sometimes isn't enough, notwithstanding).

I also think it will inevitably be used to squeeze profit, and given Meta's history, I think it's almost comical to not assume that will involve violations of the spirit of privacy. (and that's assuming that a proliferation of "it deleted all my files" "it messaged my ex" "it leaked private info" doesn't poison consumer sentiment before it even gets off the ground)

▲dcss_gardener 6 hours ago | parent [-]

I agree with all of that 100% as well. As it is now is probably not how it will stay for exactly those reasons.

▲oofbey 6 hours ago | parent | prev [-]

Probably. But also the agents are finding flaws in the security model.

Also Meta is actively encouraging users to grant them full permission, insisting with all their marketing might that it’s safe, which they know is a complete lie. Hard to blame the user when they’re being actively deceived like this. Other agent companies are more reserved and say things like “be careful” but Meta is the opposite.

▲judge2020 2 hours ago | parent | next [-]

I mean, it's not that the data isn't safe (they at least have modern user-level data protection similar to the other tech giants), nor will the agent generally do stuff you don't tell it to do. But I'm sure their stance was less "let's ask for granular per-category access whenever the user actually needs it" and more product-driven "we want the agent to have all the data and context it needs to become a successful product that gets people hooked, so let's ask for full disk access".

▲alistairSH 6 hours ago | parent | prev [-]

I definitely didn't intend to blame the victims here, beyond trusting Meta in the first place.

As for security models, it's probably long since time to sandbox all data and apps. More like mobile devices. Allow users to toggle that all off so they can use their computers for development etc, but the default state should force apps/tools to explicitly ask for permission to any folder, other app, API, CLI, etc. And ask for that permission regularly (or rather, reset the permission after some period of time). Or something like that (I haven't given it a great amount of thought).

▲luka2233 3 hours ago | parent [-]

there are patterns like task-scoped authorization solutions that could help here but the integration would be tricky since Muse is not open source