Elektrine lite

← Feed

@neilk@xoxo.zone

Post #4153080

2026-07-16 23:45 UTC

Wronger because we shouldn't be giving an agent passwords when they have READ AND WRITE ACCESS TO THE WHOLE WEB. The attack surface is infinite and the LLM is unmonitored and is making its own decisions. It's been shown you can trick them just by sending extra instructions in *HTTP headers.* If you're really serious about automating web interactions with an LLM, you need to constrain exactly what it's allowed to visit (maybe on the network level) and give it a time-limited and scoped auth token

Replies (1)

  • @neilk@xoxo.zone 2026-07-16 23:59

    So I hope that becomes a possibility in the future - that you don't share passwords, but delegate authorizations for a limited time to a predictable set of websites Not that this helps the nontechnical user much. I can't imagine how we keep a normal person safe once we establish the pattern of sharing passwords with your LLM They'll probably solve it with more AI? Something like Claude Code's very imperfect "auto mode", all watched over by machines of loving grace.

    Open ##4153078