I’m pretty frustrated with Muse and the last thing I want to be doing with my free time is defending Meta, but this is such clickbait.
Point by point:
> “OMG you can jailbreak it and get it to spill its VM”
This is the whole point; any content on the VM is yours. It runs in an isolated sandboxed VM separate from stored credentials etc; this is effectively your own computer. You don’t have to trick it.
> It collects dossiers on your contacts
These are more text files that live on your private VM, alongside memory.md, etc. Do you want your secretary to forget every person you contact every day?
> It accessed Messages without full disk access
This whole story never made sense or was substantiated. Full disk access is an OS level security boundary; the user had to switch this on.
> It sold some guys stuff for too cheap and gave out his address
OK this one I basically believe, haha. Because this is the problem with Muse: the LLM is just too dumb to perform complex tasks effectively in many cases.
I get the appeal of agents, I do. This is the future stuff we always wanted. But I cannot get myself to give one of these things access to my bank account or allow it to do price comparsion and shopping without oversight. Or access to my email or chat history.
I just do not trust any of them, not with my money or with access to my conversations.
Speak for yourself. I hated the idea of agents ever since I first heard of it back in the 90s or 00s. For me, the most valuable feature of computers is predictability. I want tools, not agents. A computer should augment my own skills, not replace them.
What AI boosters don't realize is that we're not in the optimistic days of the 1990s anymore. We've seen that the prevailing tech business model is to offer convenience as a lure to lock in dependent users and extract value from them.
Unless these AI assistants are running on self-managed platforms independent of their developers, all I see is immense counterparty risk.
> What AI boosters don't realize is that we're not in the optimistic days of the 1990s anymore.
Comments like this are in a different reality than most consumers. Most consumers don’t care about things like avoiding lock in to a platform. If the platform solves their problem then they don’t have any reason to leave it anyway. They’re not worried if their data is used to show them more targeted ads.
Topics like this show a sharp divergence between what you read on Hacker News and how actual users operate. We already knew that people who don’t trust Facebook aren’t going to suddenly start using Muse. They were never going to consider it. For the people who do actually use Meta products, which is a customer base counted in the billions, many will not have any problem using these tools.
Imagine we were talking about soda (or pop, or coke, or soft drink, depending on your dialect). Personally, I find it absolute insanity to be regularly consuming so much dissolved sugar especially during our ongoing obesity and digestive health epidemic.
But, “most consumers” don’t care about that. The beverage industry is insanely profitable, especially with recent forays into “energy drinks”.
Do people who drink so much dissolved sugar live without consequences? Absolutely not. They have a significantly lower quality of life and die much sooner than people who do not drink dissolved sugar.
I don’t see your comment as a valid dismissal. Just one more way that individual outcomes in our society are increasingly K-shaped.
I asked my wife to not share any info with Muse and she said “Well they know everything already”. Well I was able to convince her not to with some stories about hallucinations of agents getting things horribly wrong as agents in the past, because the privacy concerns just didn’t phase her. Shes even more aware than most people since I’m very privacy aware. 100% it’s very echo chambery to claim that it’s not 1990 anymore. It’s like a historian saying that history won’t repeat itself because we all know what happened last time
My wife and I do not even allow Meta Apple and Google products or proprietary software in our home (unless owned by guests) because they are all predatory and endless alternatives exist.
I see a lot of validity in your reply, but I think there is still nuance in how these priorities are expressed. How would you compare this issue to the Flock backlash, for example?
I think most people draw a strong distinction between privacy violations that are done "to them" and privacy issues with things they've chosen to use, even if they're quite similar from a technological perspective. I'd bet a lot of anti-Flock people have location sharing enabled on their phone.
Most consumers absolutely care, why do you think the biggest bipartisan issue is a massive national backlash against tech companies and a clear majority of workers being against LLM tools in the workplace?
These types of comments just show what a massive bubble you're in.
That backlash is based on conspiracy theories about data centers using up all the water and the legitimate fear of AI taking their jobs, not anything to do with privacy.
Well they will start caring when their teen with image issues starts getting targetted beauty ads[1], or when they get pregnant, want to abort, and get directed to an anti-abortion center instead[2], and afterwards they get served "abortion reversal pills" ads[3].
Or when they are hit by any other privacy fuckup like that.
Big Tech's head is at "being evil is just being competent", "democracy is incompatible with freedom" (for me to do what I want). It is also at "humans are obsolete" point. And while Zuckenberg specifically does not have cool quotes, he was at the "who cares about genocide" and "let show weight loss ads to teenagers who we determined have low self-esteem" points in the past.
Notes: actual quote is "If you're evil, you're at least competent. And if you're evil, you're not bad. And therefore, maybe you're actually kind of good because you're at least getting something done"
AI seems to be an amplifier for other problems that we never fixed, more than an authentic source of problems on its own. In this case it's amplifying that we never really trusted the cloud to begin with.
We have a lot of deferred problems to go back and solve before all these dreams can come true.
I think WallE is the perfect reference for the world AI/oligarchy are running towards. Not whether it exists, but that' dependency+environmental destitution.
I see the value of the tool but I would never use it from Meta. Would need to be self hosted with a very structured framework and guardrails so that even my local model couldn't accidentally wire 50k to a Nigerian prince or whatever the latest email scam is.
Man, I wonder how many facebook marketplace sales will be something like "In order to make sure you're a real person, before we can meet up so I can hand over this brand new macbook for $500 I need you to send me $10 electronically. It's really just to verify your commitment". With the right prompting, I'd be entirely unsurprised if Muse will just send over the $10, and of course the seller ghosts the buyer -_-
I've sold a few things on marketplace and have got some strange requests from buyers that i think are AI. I was selling a piece of exercise equipment that has a screen attached to it (rowing machine) and got a request to take a picture with a tape measure to verify the screen dimensions. The product is only sold with one screen size and it was plainly visible in the listing pictures too.
I see everybody freaking out about unfettered payment access to one's bank accounts and I keep wondering why people don't jump to the obvious solution of simply only giving it a single purpose or limited fund credit card number from privacy.com or something.
Am I missing something with the concern about ability to constrain the blast radius?
I would call that kind of thing "a very structured framework and guardrails". You'd have to come up with entirely different solutions if you want the agent to receive payments or monitor your budget.
I trust mine considerable, but only because I can run it mostly offline on hardware I own that lives in my garage. It baffles me that I am the only technical person I know that exclusively uses AI this way.
I am a technical person and while I appreciate the challenge of buying the hardware, setting up the software stack and managing the system, I can't figure out any use cases that would justify the work. This is the main issue I have with Muse, Dots, etc. There just must be something about my routines that don't align with what these companies are expecting their users to do. I do take advantage of the investor subsidized coding agents, but it will take years of my usage of their services to come close to initial start up cost of my own system.
I am very curious as to what other people of using these agents for? Some of the use cases I hear; comparative shopping, travel planning, etc. don't appeal to me. Our people using them to manage family life issues like school schedules, meetings, etc? I feel like I am missing out, but I also am not seeing the greater appeal yet.
I’m in the same boat. After witnessing context rot and inference collapse, I do not trust any LLM with mission critical work. Not Jev, not grok, not fable, not Opus.
What extent does that happen for you? I have got very good results with self hosted qwen3.8 flash next at q4 and even with qwen3.635b on a laptop. I don't keep it running forever on every single repo, its ok to leave notes in agents.md and let it search that instead of the entire history staying in context.
The Qwen models, especially when quantized, can be really bad about just trying things and seeing what works. If you’re not watching all the tool calls you may not see it, but it’s kind of scary to watch them just bump into wrong decisions and backtrack.
They also have a bad habit of accidentally building URLs that hit Alibaba infrastructure, likely because their training environment had them use those URLs. If you haven’t watched the outgoing network requests you might be very surprised at what your Qwen agents do sometimes.
heh I got a completely stupid error from gemini about some apache configs, when I pointed it out, the llm apologised, said the line(s?) should look like this, then posted the same two lines uneditted haha
I made an agent to derive and iterate on a stock trading strategy for me. What I did was give it a virtual bank account that models your typical brokerage account. So my agent reads the news, financials, markets, all the information it can gather to decide what stocks to buy/sell and manage its portfolio. Then what I do is just follow along with real money.
I could see shopping being the same way, let the agent shop for you or identify good deals on things you want but then push them to you to make the actual purchase. Like you, I'm certainly not going to let an agent make a real purchase for me unattended and I doubt any merchant is going to have much sympathy for "my AI bought this by mistake".
The missing piece for connecting an agent to your credit card or other financials is financial liability.
If Meta/OpenAI/etc would guarantee they’d compensate you in full for anything that wasn’t supposed to happen —and had an established track record of doing so— it would make trusting agents to make financial choices easier
“ If Meta/OpenAI/etc would guarantee they’d compensate you in full for anything that wasn’t supposed to happen —and had an established track record of doing so— it would make trusting agents to make financial choices easier”
Sad to see such paranoia, agents can genuinely be an agent of good and positive change.
Last night I had ChatGPT go through an old email account and surface memories that I literally forgot. People who I have fond memories of. Yea I could have spent time querying gmail and digging but the agent did it in a way that really resonated. I don't care if Sama has my emails now. I do care about connecting with my past and enjoying the memories of a time long past.
Paranoid scolds of HN want the average person to be deprived of value like this for some reason.
My email is gigabytes of garbage and a few useful bits of information that are useful and have personal relevance to me. You personally, dear reader, could probably read all my emails and I wouldn’t give a shit. I just checked my sent mails for the last few years, it’s like 90% sending absence excuses to my kid’s school. Google already has it all, so I guess I could just wait for them to get off their ass and make a useful equivalent to Grok Bot and friends.
My wife has scheduled a visit with a physician and there was a younger person in there. They legit said “haha I don’t know what it is” and used ChatGPT for diagnosis.
I have no doubt they would have no problem outsourcing everything to agents.
Did they reach a good diagnosis by using tools to provide themselves additional information to process?
Or did they make a fatally wrong diagnosis that was only discovered because the old doctor whipped out their medical encyclopedias? You left us hanging without the relevant part of the story!
Personally to me this feels like another classic case of starting with the technology and figuring out where to sell it as opposed to the customer experience.
Sorry, no. This is not the future I wanted. I do not run any agents nor ever will.
I find all this is just the next-gen privacy violation, disguised obviously as: "Oh, WOW an agent in the computer is doing all this for me". Bullshit.
It seems that never is enough with these ever thirsty companies, they keep pushing the limits and surprinsingly a lot of people do not care at all nor value the implications of having an arbitrary process running and doing pretty much whatever the agenda of their creators are.
Don't worry, I'm sure eventually you'll simply be required to give one of these things access to your bank account and that decision will be taken out of your hands.
You don't have to, there is a world of things you can do with them without giving them access to your email or bank account.
"Hermes, clone this android app to my computer, add this and this feature and fix this annoyance and then rebuild it and push it to my phone"
"Hermes summarize this YouTube podcast and push the summary and transcript to my Obsidian vault"
"Hermes check mg obsidian notes for when I last wrote a blog article about Neovim's integration with AI agents"
*Hermes, you have an API token that allows read only access to the Zabbix monitoring system, check that and then use the Proxmox API token that only allows you to do limited actions to reboot the VM that is having issues"
YouTube transcripts are increasingly if not completely blocked now. It used to be great to grab content from long tops. I did not have time to watch but wanted to learn about. Now. The only way to do it is to manually copy and paste the transcript information or use computer use. But I cannot easily do it on my VPS it seems unless I'm missing a trick.
I just have Hermes download the video using yt-dlp and transcribe it with a local whisper model using a local whisper server if the transcript is not available through the API, whisper base models works fairly well on CPU only servers nowadays.
It's very simple. There is ZERO chance the worlds biggest advertising companies will refrain, long-term, from using your most intimate secrets, gathered through your many conversations with their AI personal assistants, to sell you things.
In your locality, do you know if there are any upcoming votes/ laws or politicians who are realistically working to preserve your privacy, in these regards?
"That sounds like a tough problem in your relationship right now. Would you like me to order another Crave cookie for you? There's a special right now on free delivery. What about renewing your subscription to aitherapynow.com?"
More like “I have placed an order for which you have saved on delivery fees. Your aitherapynow.com subscription has been renewed and I will transfer you to the therapist momentarily. Just a note: your charges have resulted in using your free overdraft protection on your Chime® by Chase® from Goldman® with Fidelity® debit account - remember interest charges start in 29 days.”
I agree with this but also think it is a first order consequence.
This level of unfettered access to your personality, lifestyle, and secrets allows for an unprecedented kind of manipulation and control. You could see it as a new kind of wealth transfer: not only will They sell you things, They will subtly manipulate behaviors of the masses via trusted agents.
Brother the biggest ad companies already own the platforms most people use for their communications. For over half the world they are the browser, the OS, the TV, the messaging platform, the map, etc.
I think to the vast majority of people having one of these companies run an agent platform is going to be business as usual.
Just remember that Meta (née Facebook) changed the entire Facebook feature set and feed style in search of greater engagement and clickbait so that you would do what was best for it rather than satisfy your preferences. And if you liked it more the old way, tough luck. Your feed is now a stream of rage-bait, half-dressed women, and engagement slop instead of a way to keep in touch with acquaintances.
No way I would allow them to develop the agent that runs my life. Even if it works well now, the rug pull is absolutely inevitable.
[I was never all that into facebook, but it was nice to see old high-school friends' grandchildren once every month or two. Now its completely unviewable.]
Are all of these just flavors of "the agent has the same permissions as the user"? Not that I want to trust Meta with anything, but I'm guessing it asked for "root" access and the users granted it...?
Yes, it is clearly designed to give you access to all of this intentionally. Its system prompt (which you can just read in the interface without asking) explicitly instructs it to act on behalf of the user, not meta. All of its memory files, skills, db schema, memory integration system etc are likewise visible because they went out of their way to add an interface for viewing them!
I don't like or trust meta any more than I always did but I don't see how they could have done a "better" job with this. These kinds of agents are inherently pretty risky IMO but I don't see how this one is particularly more than any others.
Playing around with it I really don't get the sense there's any hidden prompt contradicting what's visible. It's nearly gleeful at using the VM in ways that were not intended and likely against meta's interests. I feel like someone must have won a really interesting internal power struggle to get this thing out in this form.
> I really don't get the sense there's any hidden prompt contradicting what's visible
It will happily disclose its entire system prompt (which is interesting in its own right, and worth a read) or pop a reverse shell for you
> I don't see how they could have done a "better" job with this
I generally agree -- the openness is great. However, from experiences both inside and outside of Meta, good execution, a hacker ethic, and transparency ultimately has very little propping it up when money is on the line. In fact, it could be argued that Meta has a shareholder obligation to do profitable things such that even the best intentions can (and usually will) fall in the face of corporate hierarchy and sales numbers.
I think they did a pretty bang up job with Muse (the lack of communication with first-time agent users around how powerfully and confidently they can make horrifying mistakes, and how careful you need to be with prompting, and how even that sometimes isn't enough, notwithstanding).
I also think it will inevitably be used to squeeze profit, and given Meta's history, I think it's almost comical to not assume that will involve violations of the spirit of privacy. (and that's assuming that a proliferation of "it deleted all my files" "it messaged my ex" "it leaked private info" doesn't poison consumer sentiment before it even gets off the ground)
Probably. But also the agents are finding flaws in the security model.
Also Meta is actively encouraging users to grant them full permission, insisting with all their marketing might that it’s safe, which they know is a complete lie. Hard to blame the user when they’re being actively deceived like this. Other agent companies are more reserved and say things like “be careful” but Meta is the opposite.
I definitely didn't intend to blame the victims here, beyond trusting Meta in the first place.
As for security models, it's probably long since time to sandbox all data and apps. More like mobile devices. Allow users to toggle that all off so they can use their computers for development etc, but the default state should force apps/tools to explicitly ask for permission to any folder, other app, API, CLI, etc. And ask for that permission regularly (or rather, reset the permission after some period of time). Or something like that (I haven't given it a great amount of thought).
> Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages
Can someone explain how this is possible? If an app can do this without Full Disk Access or a popup of some kind that's a way bigger lapse on Apple's part than Meta's.
Reading the linked articles suggests that this is not possible, but Apple did acknowledge that the full-disk access grants you access to other apps (until the most recent update)
Typical "leopards ate my face" moment. You give AI (from Meta, nonetheless) full-disk access and then complain that—wow—it really meant FULL.
In a perfect world where you got nothing to hide, where companies don't sell your data and there are no hackers, even I would love to just hand all my data to Muse and have it be my trusted assistant. People who think we live in such a world are already doing that, evidently.
I saw a theory, just a theory, that it may have accessed the message via its notification preview, which I think was similarly used to leak Signal messages recently?
if you go on meta.com there is not a single mention of Facebook or Instagram anywhere in sight, and those are their leading products and money makers...
I get this, but to be honest he said this when he was in college, I don't put much weight on it. You're telling me that you never said anything stupid in college?
It's always very intentional, especially with Meta/Facebook.
That's their whole modus operandi, a privacy nightmare which will feed their infinite money machine.
Reading "Careless People" didn't make me surprised at all on how the company operates, it surprised me with the personal descriptions of how people like Mark Zuckerberg and Sherryl Sandberg actually are as humans. It scared me how most people at that level of wealth and power isn't too different from the accounts in the book, they're all seriously deranged people with a gigantic lever to impose their distorted realities upon the rest of humanity.
I understand that a typical HN user is very different from the average person.
However, surely by now even the lay people who have seen the testimonies before Congress, the lawsuits and the excesses by Meta execs over and over again ought to be atleast somewhat wary of handing them more personal data?
I think the average person has very similar self preservation instincts as the rest of us. So it can't be that. Which leaves the fact that there are lot of people who don't know about the above mentioned scandals galore that Meta has been involved in?
This "holier than thou" attitude in this comment is precisely the reason why HN users have largely misunderstood tech trends and desires by the general public.
And it's all by design, Meta and its founder have a long history of releasing products with security "flaws" that are immediately used by them to collect vast amounts of information about their victims.
Every social media & AI company is also a surveillance company. Targeted advertising doesn't work w/o mountains of behavioral data aggregated across all of Meta's & Google's software "products".
Point by point:
> “OMG you can jailbreak it and get it to spill its VM”
This is the whole point; any content on the VM is yours. It runs in an isolated sandboxed VM separate from stored credentials etc; this is effectively your own computer. You don’t have to trick it.
> It collects dossiers on your contacts
These are more text files that live on your private VM, alongside memory.md, etc. Do you want your secretary to forget every person you contact every day?
> It accessed Messages without full disk access
This whole story never made sense or was substantiated. Full disk access is an OS level security boundary; the user had to switch this on.
> It sold some guys stuff for too cheap and gave out his address
OK this one I basically believe, haha. Because this is the problem with Muse: the LLM is just too dumb to perform complex tasks effectively in many cases.
I just do not trust any of them, not with my money or with access to my conversations.
Speak for yourself. I hated the idea of agents ever since I first heard of it back in the 90s or 00s. For me, the most valuable feature of computers is predictability. I want tools, not agents. A computer should augment my own skills, not replace them.
Unless these AI assistants are running on self-managed platforms independent of their developers, all I see is immense counterparty risk.
Comments like this are in a different reality than most consumers. Most consumers don’t care about things like avoiding lock in to a platform. If the platform solves their problem then they don’t have any reason to leave it anyway. They’re not worried if their data is used to show them more targeted ads.
Topics like this show a sharp divergence between what you read on Hacker News and how actual users operate. We already knew that people who don’t trust Facebook aren’t going to suddenly start using Muse. They were never going to consider it. For the people who do actually use Meta products, which is a customer base counted in the billions, many will not have any problem using these tools.
But, “most consumers” don’t care about that. The beverage industry is insanely profitable, especially with recent forays into “energy drinks”.
Do people who drink so much dissolved sugar live without consequences? Absolutely not. They have a significantly lower quality of life and die much sooner than people who do not drink dissolved sugar.
I don’t see your comment as a valid dismissal. Just one more way that individual outcomes in our society are increasingly K-shaped.
These types of comments just show what a massive bubble you're in.
Or when they are hit by any other privacy fuckup like that.
[1] https://futurism.com/facebook-beauty-targeted-ads [2] https://www.bbc.com/news/health-61320202 [3] https://tech.yahoo.com/general/articles/facebook-made-money-...
Notes: actual quote is "If you're evil, you're at least competent. And if you're evil, you're not bad. And therefore, maybe you're actually kind of good because you're at least getting something done"
They were discussing how tesla manages problems with full-self-driving.
It was interesting how this realm of problems was viewed.
If there was an accident while the car was driving itself due to some glitch, the police at the scene put all the blame on the driver.
The book had a different viewpoint. obviously there was a tesla bug in full self driving, and they kept their mouth shut.
meanwhile society/government doesn't even think of this and puts responsibility/blame on the user.
We have a lot of deferred problems to go back and solve before all these dreams can come true.
HN must understand that they are not a representative sample of anything.
Am I missing something with the concern about ability to constrain the blast radius?
I am very curious as to what other people of using these agents for? Some of the use cases I hear; comparative shopping, travel planning, etc. don't appeal to me. Our people using them to manage family life issues like school schedules, meetings, etc? I feel like I am missing out, but I also am not seeing the greater appeal yet.
They also have a bad habit of accidentally building URLs that hit Alibaba infrastructure, likely because their training environment had them use those URLs. If you haven’t watched the outgoing network requests you might be very surprised at what your Qwen agents do sometimes.
I could see shopping being the same way, let the agent shop for you or identify good deals on things you want but then push them to you to make the actual purchase. Like you, I'm certainly not going to let an agent make a real purchase for me unattended and I doubt any merchant is going to have much sympathy for "my AI bought this by mistake".
If Meta/OpenAI/etc would guarantee they’d compensate you in full for anything that wasn’t supposed to happen —and had an established track record of doing so— it would make trusting agents to make financial choices easier
lol… talk about delusion.
Last night I had ChatGPT go through an old email account and surface memories that I literally forgot. People who I have fond memories of. Yea I could have spent time querying gmail and digging but the agent did it in a way that really resonated. I don't care if Sama has my emails now. I do care about connecting with my past and enjoying the memories of a time long past.
Paranoid scolds of HN want the average person to be deprived of value like this for some reason.
I am perfectly prepared to believe you had a nice interaction with the robot. But this is an insane thing to say!
I have no doubt they would have no problem outsourcing everything to agents.
Or did they make a fatally wrong diagnosis that was only discovered because the old doctor whipped out their medical encyclopedias? You left us hanging without the relevant part of the story!
It feels and seems too forced.
I find all this is just the next-gen privacy violation, disguised obviously as: "Oh, WOW an agent in the computer is doing all this for me". Bullshit.
It seems that never is enough with these ever thirsty companies, they keep pushing the limits and surprinsingly a lot of people do not care at all nor value the implications of having an arbitrary process running and doing pretty much whatever the agenda of their creators are.
We are an opportunistic species. We don't have perfect knowledge nor thoughtfulness.
We need to protect each other.
We don't.
"Hermes, clone this android app to my computer, add this and this feature and fix this annoyance and then rebuild it and push it to my phone"
"Hermes summarize this YouTube podcast and push the summary and transcript to my Obsidian vault"
"Hermes check mg obsidian notes for when I last wrote a blog article about Neovim's integration with AI agents"
*Hermes, you have an API token that allows read only access to the Zabbix monitoring system, check that and then use the Proxmox API token that only allows you to do limited actions to reboot the VM that is having issues"
Etc, etc,
In mine, I don't.
That seems like an oversight/ opportunity.
This level of unfettered access to your personality, lifestyle, and secrets allows for an unprecedented kind of manipulation and control. You could see it as a new kind of wealth transfer: not only will They sell you things, They will subtly manipulate behaviors of the masses via trusted agents.
I think to the vast majority of people having one of these companies run an agent platform is going to be business as usual.
Let’s not forget Facebook caused a genocide
No way I would allow them to develop the agent that runs my life. Even if it works well now, the rug pull is absolutely inevitable.
[I was never all that into facebook, but it was nice to see old high-school friends' grandchildren once every month or two. Now its completely unviewable.]
I don't like or trust meta any more than I always did but I don't see how they could have done a "better" job with this. These kinds of agents are inherently pretty risky IMO but I don't see how this one is particularly more than any others.
Playing around with it I really don't get the sense there's any hidden prompt contradicting what's visible. It's nearly gleeful at using the VM in ways that were not intended and likely against meta's interests. I feel like someone must have won a really interesting internal power struggle to get this thing out in this form.
It will happily disclose its entire system prompt (which is interesting in its own right, and worth a read) or pop a reverse shell for you
> I don't see how they could have done a "better" job with this
I generally agree -- the openness is great. However, from experiences both inside and outside of Meta, good execution, a hacker ethic, and transparency ultimately has very little propping it up when money is on the line. In fact, it could be argued that Meta has a shareholder obligation to do profitable things such that even the best intentions can (and usually will) fall in the face of corporate hierarchy and sales numbers.
I think they did a pretty bang up job with Muse (the lack of communication with first-time agent users around how powerfully and confidently they can make horrifying mistakes, and how careful you need to be with prompting, and how even that sometimes isn't enough, notwithstanding).
I also think it will inevitably be used to squeeze profit, and given Meta's history, I think it's almost comical to not assume that will involve violations of the spirit of privacy. (and that's assuming that a proliferation of "it deleted all my files" "it messaged my ex" "it leaked private info" doesn't poison consumer sentiment before it even gets off the ground)
Also Meta is actively encouraging users to grant them full permission, insisting with all their marketing might that it’s safe, which they know is a complete lie. Hard to blame the user when they’re being actively deceived like this. Other agent companies are more reserved and say things like “be careful” but Meta is the opposite.
As for security models, it's probably long since time to sandbox all data and apps. More like mobile devices. Allow users to toggle that all off so they can use their computers for development etc, but the default state should force apps/tools to explicitly ask for permission to any folder, other app, API, CLI, etc. And ask for that permission regularly (or rather, reset the permission after some period of time). Or something like that (I haven't given it a great amount of thought).
Can someone explain how this is possible? If an app can do this without Full Disk Access or a popup of some kind that's a way bigger lapse on Apple's part than Meta's.
Typical "leopards ate my face" moment. You give AI (from Meta, nonetheless) full-disk access and then complain that—wow—it really meant FULL.
In a perfect world where you got nothing to hide, where companies don't sell your data and there are no hackers, even I would love to just hand all my data to Muse and have it be my trusted assistant. People who think we live in such a world are already doing that, evidently.
There was no recent update. Apple's announcement was about a future macOS update.
It's not.
Why are we depending on LLM "reasoning" to negotiate a price rather than just having the user enter a lowest acceptable price deterministically?
Trying to think of a number that I would consider it, and honestly $1k/month wouldn't convince me unless
- I have root on device
- device is on its own vlan, fully segmented
- !(SIM || 5G antenna)
- no google/apple id authenticated on device
- terminate agreement at any time without cost
I'm probably forgetting/not aware of ten things I should consider.
the company's brands are toxic and they know it.
> Zuck: They "trust me"
> Zuck: Dumb fucks.
That's their whole modus operandi, a privacy nightmare which will feed their infinite money machine.
Reading "Careless People" didn't make me surprised at all on how the company operates, it surprised me with the personal descriptions of how people like Mark Zuckerberg and Sherryl Sandberg actually are as humans. It scared me how most people at that level of wealth and power isn't too different from the accounts in the book, they're all seriously deranged people with a gigantic lever to impose their distorted realities upon the rest of humanity.
However, surely by now even the lay people who have seen the testimonies before Congress, the lawsuits and the excesses by Meta execs over and over again ought to be atleast somewhat wary of handing them more personal data?
I think the average person has very similar self preservation instincts as the rest of us. So it can't be that. Which leaves the fact that there are lot of people who don't know about the above mentioned scandals galore that Meta has been involved in?
Facebook is like Microsoft at this point: The thing your grandparents use.
Even if they make something technically superior for a while, like what the Zune was to the iPad, tHey'll never really be cool.
and they'll certainly never be trusted.
The question implies you already are. But yes, obviously.
Related:
Updates to Full Disk Access in macOS
https://news.ycombinator.com/item?id=49937631
Meta’s Muse has a serious 0-day
https://news.ycombinator.com/item?id=49802030
Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions
https://news.ycombinator.com/item?id=49893709
Maybe don't let Muse run your Facebook Marketplace account
https://news.ycombinator.com/item?id=49875006
What Meta got right with Muse
https://news.ycombinator.com/item?id=49946526
Muse – Meta’s personal AI agent
https://news.ycombinator.com/item?id=49615537
-Mark Zuckerberg
Today’s version of the platform targets just the right emotions to keep users “engaged.”