Sean
@troed@swecyb.com @briankrebs@infosec.exchange okay, so we're accepting anecdotal evidence? Every time that I've tried GenAI, it's been a mess, error prone, and wasted my time.
Just two days ago, I tried to use GenAI to help with a problem. It's first response was wrong and outdated. I pointed out it was missing current functionality. It's updated, second response still turned out wrong. My actual results in terminal did not match its claims and the actual source code for the functionality also indicated it was wrong. When I pointed this out, it was all, "You're right! Here is the actual...."
A month ago, I was asking for help with a subject. Thirty minutes (or more) into the session, after manually reviewing product documentation I realized the GenAI solution was just poorly written and could never work. I pointed out its incorrect foundational component and it corrected its response. So, its suggestion now worked but it was insecure. I pointed out that this was an insecure implementation and that its answers should include secure principles. Well, unsurprisingly, this didn't stick and it was still suggesting or "forgetting" to apply secure designs.
This has been my experience nearly every time. It's just wrong and I have to guide it like a moronic intern. I can't trust anything that it generates. And, this is just my anecdotal evidence.
Actual research, studies, and the news show and support that GenAI technology cannot be trusted. Every week we read or hear about some bullshit GenAI content. Even the GenAI companies themselves admit this by reminding everyone that a human needs to review GenAI output.
This is just discussing the functionality side of GenAI. It's also a disaster for the environment, intellectual property, the global market, the job market, mental health, local communities, the open Internet, and much more.
I think it was Sam Altman that even admitted that if GenAI companies were held accountable to intellectual property laws the companies and technology would gail. A little over a decade ago, Aaron Swartz was prosecuted to point of suicide just for accessing content he had a legal right to access. Yet, these billion dollar companies are giving free reign to magnitudes more protected content.
Society is being used to socialize the R&D costs of Alpha-level technology and its consequences.
These GenAI tools nearly all phone home and share private data with massive corporations and governments. They're a privacy and intellectual property nightmare. Are you using End-to-End Encryption (E2EE)? Well, that doesn't matter much when you have a spy bot or software scanning, monitoring, and reporting your data and conversations to Big Brother.
I will wrap with a final asks:
-
if GenAI technology is so amazing then why is it being forced into everything and onto everyone? I don't recall the iPod or iPhones being forced on consumers. I don't recall any recent amazing technology having to be forced onto consumers.
-
If GenAI is truly such a multiplier then why are these companies sharing it and forcing it on everyone? Shouldn't they be keeping it secret and proprietary while they crush their competition? Why are so many of these big companies scaling back their actual usage of GenAI tools?
-
If GenAI is truly so accurate then why do most experts decry its usage in their field? Isn't it weird how it is mostly executives and non-experts pushing this technology so heavily when they are not qualified to judge capabilities?
Etc
Etc
Etc.
More accurate title: Human Meta developer caused security incident by following GenAI advice and lack of secure Meta development controls
This was not a "rogue AI" that misbehaved. The GenAI bot was performing as expected: providing believable, yet garbage and dangerous output.
More importantly, it was a human that performed the actual changes by acting on inaccurate GenAI information and lack of technical controls and policies by Meta. It should be clear by now that GenAI output is not to be trusted, yet this human followed the GenAI output without properly understanding or validating the provided information. Additionally, Meta's development controls and security tools failed to stop the harmful changes from being made by the human.
No, I'm not going to enable JavaScript for your random Fediverse/Lemmy service. I'm sick and tired of having to trust random websites to execute code on my system. You don't need more than HTML and CSS to display a rich website. There is no reason for the JavaScript dependency. It should provide extra functionality, not base functionality.
Also, this website appears to be using Cloudflare, which is protecting the folks DDoSing Ubuntu infrastructure right now. What a joke.
I guess this tells us the state of Microsoft and Windows when Microsoft employees excitedly flee to MacOS.
According to Wikipedia, Android 16:
- Developer preview: November 2024 (almost two years ago)
- Final release: June 2025 (over one year ago)
Releasing a "new" product that is running an OS already outdated and likely missing hundreds of security fixes is negligent. Google does not fully backport security fixes to older generations of Android.