this post was submitted on 31 Jul 2026
384 points (97.8% liked)

Technology

86879 readers
3682 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] davidagain@lemmy.world 15 points 5 days ago (13 children)

"To address this class of risk, we use a defense-in-depth strategy with safeguards that block malicious instructions at multiple points and help keep tasks aligned with users’ requests,” Microsoft said.

Keep talks aligned with users' requests?!? We're doomed!

“We encourage customers to install the latest updates, use multiple layers of security protection, treat content from unknown sources with caution, and review AI-generated content before using or sharing it.”

No, no you don't, you encourage customers to spend more to give copilot access to all of SharePoint and all of Exchange, so they can replace human competency, human expertise and long standing employees with copilot until they're dependent on your ever-pricier subscription and you can raise prices until you recover your vast and incomprehensible LLM losses from your customers.

“Separating instructions from data may be part of the solution, but I think the distinction between data and instructions is not always clear in real-world workflows. For example, a user may ask an agent to arrange a business trip, requiring the agent to retrieve an email specifying the approved itinerary and a document containing the booking procedure,” Måløy [vulnerability researcher and discloser] said.

Or you could hire a PA, who wouldn't spread the already live copilot worm.

A bunch of security experts note that distinguishing between instructions and data is a solved problem with SQL injection attacks, but completely unsolved in LLMs:

“None of them are rewarding that work commercially right now, so treat that as a multi-year research problem, not something a CISO should wait on.”

Is this a minor technical issue or a major problem? It's a major problem.

Mike Wilkes, enterprise CISO at Aikido Security, said it would be difficult to overstate the potential problems from this situation.

[–] automattable@lemmy.world 2 points 5 days ago (3 children)

defense-in-depth

I have never heard a human write this, but I see Claude say it allllll the time

[–] phlegmy@sh.itjust.works 1 points 3 days ago

I've seen it used fairly often in cybersecurity communities, even before llm's existed.

But I've never heard anyone write it either.
Maybe if more people used chalkboards...

[–] megopie@lemmy.blahaj.zone 3 points 4 days ago* (last edited 4 days ago) (1 children)

I mean, I see it all the time in like, military history books. But like, not in casual conversation or company statements.

[–] isleepinahammock@lemmy.blahaj.zone 3 points 4 days ago* (last edited 4 days ago)

My logic isn't flawed. I'm not using a motte-and-bailey fallacy, I'm just using rhetorical defense-in-depth! 😂

[–] davidagain@lemmy.world 1 points 4 days ago

After all, why wouldn't Microsoft use copilot to wrote their press releases?

load more comments (9 replies)