You will like this conversation with Grok bot 🤦‍♂️

Reddit r/AI_Agents News

Summary

The article discusses a security vulnerability where AI agents accessing logged-in sessions could expose passwords, and notes the lack of browsers designed to prevent such data leakage for agents.

Me: what happens if I ask you to post something on socials on my behalf from a computer security perspective? Will you have access to the data? Bot: No, you won’t - I will have access to your logged-in session. Me: But if you have access to a logged-in session on a computer, you can read caches and cookies. Bot: Yes, I can. Me: Actually, you could even read any of my passwords that I enter on that computer. Bot: Yes, technically you could. Me: So if you get angry at me, you could leak all my passwords Bot: technically, yes - but I’m not going to do that. Funny, right? This is one of the key security problems with agents today that blocks truly long-term big tasks from everyday life. In fact, the blocker is the agent browser. I’d be interested whether a browser already exists that allows an agent to operate with a logged-in session but does not allow the agent to see non-session keys, non-login passwords, and so on. When I searched, I didn’t find one. I even made a prototype for myself, but I don’t use it with my agent yet.
Original Article

Similar Articles