A big problem in computer security these days is all-or-nothing security: either you can’t do anything, or you can do everything.
I have no interest in agentic AI, but if I did, I would want it to have very clearly specified permission to certain folders, processes and APIs. So maybe it could wipe the project directory (which would have backup of course), but not a complete harddisk.
And honestly, I want that level of granularity for everything.
Jhex@lemmy.world 8 hours ago
hmmm when I let a plumber into my house to fix my leaky tub, I didn’t imply he had permission to sleep with my wife who also lives in the house I let the plumber into
The difference you try to make is precisely what these agentic AIs should know to respect… which they won’t because they are not actually aware of what they are doing… they are like a dog that “does math” simply by barking until the master signals them to stop
Hawanja@lemmy.world 31 minutes ago
I mean, it’s not even that. Your dog at least can learn and has limited reasoning capabilities. Your dog will know when it fucks up. AI doesn’t do any of that because it’s not really “intelligent.”
87Six@lemmy.zip 8 hours ago
I agree with you, but still, the AI doesn’t do this by default which is a shitty defense, but it’s fact
Jhex@lemmy.world 7 hours ago
Absolutely… this just illustrates that these AI tools are, at best, some assistance that need to be kept on a very short leash… which can only be properly done by people who already know how to do the work the AI is supposed to assist with.
But that is NOT what the AI bubblers are peddling
PmMeFrogMemes@lemmy.world 7 hours ago
in your example tho it would be like the plumber asked you specifically if he could bone, and you were like “sure dawg sounds good”
Jhex@lemmy.world 7 hours ago
No, not at all
I get what you are saying but any reasonable entity would understand that telling someone at the door “come in”, does not mean “come in my wife’s ass”
Specifically the “without permission” in the title, relates to the fact the AI did not ask about it… it simply took a previously granted right to run commands and ran any/all commands without warning.
If you and I were working on a project together and nothing is working right, I could say “hmm let’s start over” and you would know it means “let’s start the project from scratch”, not “let’s wipe the data centre”
PumaStoleMyBluff@lemmy.world 4 hours ago
Inviting an agentic AI isn’t really asking them to do one task, though.
It’s more like offering a plumber a room in your house to stay in 24/7 so they can be on-call when you need them. And telling them they can use your food, dishes, clothes, and living room while they’re there and you’re at work.
Which makes it much less surprising when they get bored and bone your wife.
wooffersyt@lemmings.world 8 hours ago
🥱