11 ms·
AI browser extensions are a security nightmare
- kypro 3y ago> Yes, large language models (LLMs) are not actually AI in that they are not actually intelligent, but we’re going to use the common nomenclature here. I'm sorry for the off-topic comment, but why do I keep seeing this? What am I missing here – is it that some people define intelligence as >= human, or that LLM are not intelligence because they're *just* statistical models?
- guy98238710 3y agoMore like intelligence == human. ChatGPT is superhuman in many ways.
- wongarsu 3y agoThere's long been a divide between what people call hard vs soft AI, or strong vs weak AI, or narrow vs general. The definitions are a bit fuzzy, but generally a hard AI or strong AI would be able to think for itself, develop strategies and skills, maybe have a sense of self. Soft AI in contrast is a mere tool where you put something in and get something out. Now some people don't like using the term AI for soft/weak/narrow AI, because it's a fleeting definition, mostly applied to things that are novel and that we didn't think computers were able to do. Playing chess used to be considered AI, but a short time after AI beat the human chess world master it was no longer considered AI. If you buy a chess computer capable of beating Magnus Carlsen today that's considered a clever algorithm, no longer AI. You see the same thing playing out in real time right now with LLMs, where they go from AI to "just algorithms" in record time.
- sublinear 3y ago> LLM are not intelligence because they're just statistical models This is exactly it for me.
- xigency 3y agoAre you intelligent or just a bunch of cells? Given that I can query it for all sorts of information that I don’t know, I would consider LLMs to, at the very least, contain and present intelligence…artificially.
- vel0city 3y agoI can query Wikipedia or IMDB for all sorts of information I don't know. I wouldn't consider the search box of either site to be "intelligent", so I don't know "query it for all sorts of information" is a generally good rubric for intelligence.
- ericd 3y agoAnd if your brain is mostly a statistical model of the world, with action probabilities based on what parts of it happen to be excited at the moment?
- jmopp 3y agoHow do we know that the brain is a statistical model of the world? It sounds like explaining an unknown phenomenon using the technology du jour - just 10/20 years ago, the brain was a computer.
- JohnFen 3y agoThis touches on a dichotomy that has fascinated me for decades, from the very beginning of my interest in AI. One side of the dichotomy asserts that "if it walks like a duck..." that is, if a computer appears to be intelligent to us, then it must be intelligent. This is basically the Turing Test crowd (even though Turing himself didn't approve of the Turing Test as an actual test of AI). On the other side, you have people who assert that the human mind is really just a super-complicated version of "X", where "X" is whatever the cool new tech of the day is. I have no conclusions to draw from this sort of thing, aside from highlighting that we don't know what intelligence or consciousness actually are. I'm just fascinated by it.
- JohnFen 3y agoBecause we don't have a real handle on what "intelligence" actually is, any use of the word without defining it is essentially just noise.
- ethanbond 3y agoYeah this is exactly it. It’s interesting seeing a precision-oriented discipline (engineering) running into the inherently very, very muddy world of semantics. “What do you mean it’s not intelligent?! It passed Test X!” “Yes and now that tells us Test X was not a good test for whatever it is we refer to as ‘intelligence’”
- shagie 3y agoI think its the "just" statistical models part. If you pull up the TOC for an AI textbook, you'll find lots of things that aren't "intelligent". Machine learning is just a subset of it. I recall a professor in the AI department back in the 90s working on describing the shape of an object from a photograph (image to text) based on a number of tools (edge detection was one paper I recall). Also in AI is writing a deductive first order logic solver is covered in there as are min-max trees and constraint satisfaction problems. http://aima.cs.berkeley.edu http://aima.cs.berkeley.edu https://www.cs.ubc.ca/~poole/ci/contents.html https://www.cs.ubc.ca/~poole/ci/contents.html (note chapter 4) https://www.wiley.com/en-us/Mathematical+Methods+in+Artificial+Intelligence-p-9780818672002 https://www.wiley.com/en-us/Mathematical+Methods+in+Artifici... People are trying to put a box around "AI" to mean a particular thing - maybe they want AI to mean "artificial general intelligence" rather than all the things that are covered in the intro to AI class in college. I ultimately believe that trying to use a term that has been very broad for decades to apply to only a small subset of the domain is going to end up being a fruitless Scotsman tilting at windmills. ... And you know what, I think it does a pretty good job at being intelligent. https://chat.openai.com/share/01d760b3-4171-4e28-a23b-0b6565a9646c https://chat.openai.com/share/01d760b3-4171-4e28-a23b-0b6565...
- ravenstine 3y ago> is it that some people define intelligence as >= human I just want to say that this seems to be how many, if not most people define intelligence internally. If an LLM gets something wrong or doesn't know something, then it must be completely unintelligent. (as if humans never get anything wrong!)
- xigency 3y agoClearly the test isn’t >= as ChatGPT is already more coherent than large swaths of the population. The AI test for some is that its intelligence >>> human intelligence. Which is funny because by that point in time, their opinion will be more than worthless.
- ethanbond 3y agoLike with humans, there are intelligent ways to be wrong and unintelligent ways to be wrong. LLMs do a whole lot of “wrong in a way that indicates it is not ‘thinking’ the way an intelligent human would.”
- ravenstine 3y agoWhat's concerning about this is we are evaluating AI on a basis that humans are not subject to. LLMs in their current form are built on the knowledge of the internet, while humans have both the internet and realtime feedback from their own lives in the physical world. If a human brain could be trained the same way as an LLM, might it also connect seemingly unconnected ideas in a way that would appear as non-thought? Maybe, maybe not. LLMs seem to be biased heavily towards making best effort guesses on things it doesn't know about, whilst humans are far more modest in doing so. I just don't know if we're really at a point where we can conclusively decide that something isn't thinking just because it doesn't appear to be thinking by the standards we place upon ourselves.
- russdill 3y agoIt's statistical models all the way down.
- ryanklee 3y agoThat is not a very good reason to call an entity unintelligent. There are uncontroversial models of human intelligence that are Bayesian.
- russdill 3y agoThat's what I'm alluding to.
- ryanklee 3y agoAh, apologies, I read your comment as alluding to statistics as a reason to dismiss intelligence in machines
- tremon 3y agoThere are uncontroversial models of human intelligence that are Bayesian But they're still models. Anyone claiming that Bayesian/statistical models have intelligence is confusing the map for the territory.
- bee_rider 3y agoVery clever people have located true intelligence in the gaps between what an machine can do and what a human can. Therefore, to show that you aren’t a starry-eyed rube you put a disclaimer that you aren’t really talking about intelligence, but something that just looks and acts like it. True intelligence is, of course, definitionally the ability to do things like art or… err, wait, sorry, I haven’t checked recently, where have we put the goalposts nowadays?
- hospitalJail 3y agoStable Diffusion doesnt make art, it makes photos. We can deem them art. Its denoising software.
- lucubratory 3y agoOoh, this is a rare one! A comment directly noting the similarities between AI art with photography, but insisting both aren't art. You're in very historical company: https://daily.jstor.org/when-photography-was-not-art/ https://daily.jstor.org/when-photography-was-not-art/
- hospitalJail 3y ago>Photography couldn’t qualify as an art in its own right, the explanation went, because it lacked “something beyond mere mechanism at the bottom of it.” That has nothing to do with the technology, that has everything to do with the quality. Is it art if I take a picture with the cap on? No. Is it art if I take a picture of a tan colored wall? No. Is it art if I set up something beautiful and take a picture. Its closer to art than the previous few examples. If I write a prompt that says: "a green bedroom with art work on the walls", to be inspired, that still isnt trying to be art. Basically, have higher standards.
- ethanbond 3y agoI’m hesitant to even call this moving the goal posts. Intelligence has never been solidly defined even within humans (see: IQ debate; book smart vs street smart; idiot savants). It’s unsurprising that creating machines that seem to do some stuff very intelligently and some other things not very intelligently at all is causing some discontent with regard to our language. I see a whole lot more gnashing of teeth about goalposts moving than I do about people proposing actual solid goalposts. So what’s your definition?
- deleted 3y ago[deleted]
- majormajor 3y agoAI's a very soft term, and there's long been a technical vs "casual" split in what it means. Five or ten years ago you'd say your photo was retouched with AI dust removal, say, and we'd all know what that means. And that there was a big gulf between that and the sci-fi "AI" of Blade Runner or Her or Star Wars, etc. The user interface to Chat GPT and similar tools, though, has made a lot of people think that gap is gone, and that instead of thinking they are using an AI tool in the technical sense, they now think they're talking to a full-fledged other being in the sci-fi sense; that that idea has now come true. So a lot of people are careful to distinguish the one from the other in their writing.
- VoodooJuJu 3y agoIt's a way for the author to distinguish himself as one who is neither a purveyor of, nor fooled by, the magic, grift, and cringy sci-fi fantasizing that currently comprises the majority of AI discussion. Currently, most mentions of AI, outside of a proper technical discussion, are coming from crypto-tier grifters and starry-eyed suckers. Even further, a lot of discussions from otherwise technical people are sci-fi-tier fearmongering about some ostensible Skynet, or something, it's not quite clear, but it's clearly quite cringe. The latter is one of the many calibers of ammunition being used by AI incumbents to dig regulatory moats for themselves. Anyway, I understand why the author is distinguishing himself with his LLM...AI disclaimer, given the above.
- dguest 3y agoIn my field it's accepted (by some) that you write "AI" for your grant proposal and say "ML" when you talk to colleagues and want to be taken seriously. It feels a bit wrong to me, because as you say it's arguably a grift, in this case on the taxpayer who funds science grants. More charitably it might just be the applicant admitting that they have no idea what they are doing, and the funding agency seeing this as a good chance to explore the unknown. Still, unless the field is AI research (mine isn't) it seems like funding agencies should giving money to people who understand their tools.
- sebzim4500 3y agoMost people outside of academia understand AI to include way more than just ML. People refer to the bots in video games as AI and they are probably a few hundred lines of straightforward code. I don't think there is anything wrong with using the colloquial definition of the term when communicating with funding agencies/the public.
- dguest 3y agoI agree that using a colloquial definition is fine. And I don't mean to be too harsh on people who use buzzwords in their grant proposal: it's just sort of the sea you swim in. But I only wish we could say that a few hundred lines of code was "AI": that would mean funding for a lot of desperately needed software infrastructure. Instead AI is taken as synonymous with ML, and more specifically deep neural networks, for the most part.
- nathan_compton 3y agoI say that large language models are not intelligent because of the way they fail to do things. In particular, they fail in such a way as to indicate they have no mental model of the things they parrot. If you give them a simple, but very unusual, coding problem, they will confidently give you an incorrect solution even though they seem to understand programming when dealing with things similar to their training data. An intelligent thing should easily generalize in these situations but LLMs fail to. I use GPT4 every day and I frequently encounter this kind of thing.
- NumberWangMan 3y agoIs there a definition of intelligence that rules out large language models, but that does not also rule out large portions of humanity? A lot of people would readily admit that they don't have programming aptitude and would probably end up just memorizing things. Do we say those people are not intelligent? It seems to me that the perceived difference is mostly in being able to admit that you don't know something, rather than make up an answer -- but making up an answer is still something that humans do sometimes.
- nathan_compton 3y agoI have to admit this is a genuinely interesting question. Language models demonstrably do have some models of the world inside of them. And, I admit, what I say that they aren't intelligent, I mostly mean they are very stupid, rather than like a machine or algorithm. Artificial stupidity is progress.
- pixl97 3y agoOk, so from your other comment, I think this is where our definition of intelligence is breaking down... Biological agents have a consistent world model based on their capabilities because an inconsistent model would lead to lack of reproduction or death. We could call this environmental intelligence. Meanwhile we have LLMs that have appear to have what I would consider 'micro' world models for some things, but not a large consistent world model. I'm guessing this is due to a few things, but for example not being culled for bad world models would be one, and another is they are only grounded in text and we've not really explored multi-modal grounding in models very far. I guess what's going to be interesting is to see how multi-modal and embodied models do as they are trained in the environment and create a more consistent world model.
- LudwigNagasena 3y ago> is it that some people define intelligence as >= human Just like some people define stupid as <= them. Aptitude is a multivariate spectra. It is already hard to come up with a cutoff on a single measure, way harder to do so for a bunch of different skills that for some reason happen to correlate in humans (and sometimes they diverge wildly as in the case of savant syndrome).
- CyberDildonics 3y agoBrowser Extensions Are a Security Nightmare - I guess you can add AI in front to make it seem new.
- mahogany 3y agoExactly - it blows my mind how normalized the permission Access your data for all websites is (I think it's Read and Change all your data on all websites for Chrome). I use only one or two extensions because of this. Why does a procrastination tool need such an insanely broad permission?
- hoosieree 3y agoI wrote a Chrome extension[1] that reads no data but places a colored translucent div over the page. It requires that same "change all your data" permission. My takeaway lesson is that the permissions model for extensions is confusing and nearly useless. [1] https://chrome.google.com/webstore/detail/obscura/nhlkgnilpmpddehjcegjpofpiiaomnen https://chrome.google.com/webstore/detail/obscura/nhlkgnilpm...
- youreincorrect 3y agoDo you suppose it's possible that accessing the DOM to add a div implicitly requires access to page data?
- hoosieree 3y agoI can see how many applications might want to read the page, but in my case it's not necessary. My extension tries to add a <div> under the <body> element, regardless of what's going on in the page. If there's no <body>, my extension stops working but the browser keeps going. In short, if there were separate "read" and "write" permissions, I would only need "write". For privacy-concerned people, that's a very important distinction.
- 3y ago
- FL33TW00D 3y agoBut what is the "AI" ran entirely locally? https://pagevau.lt/ https://pagevau.lt/
- williamstein 3y agoThe "Download for Chrome" link on that page is broken. "404. That’s an error. The requested URL was not found on this server. That’s all we know."
- Tycho 3y agoI wonder when we’ll start seeing computer viruses that communicate with a remote LLM in order to get help circumventing barriers. Alternatively, maybe anti-virus software can phone home to get on-the-fly advice.
- ronsor 3y ago> Alternatively, maybe anti-virus software can phone home to get on-the-fly advice. Modern antivirus software already does this, more or less. It's usually called something like "cloud scanning."
- ricardo81 3y agoOnly skimmed through the article, it seems -AI from the title would be an old story? Also, that huge 4.7MB image in the head of the article...
- SCUSKU 3y agoSEO, who needs it!
- Anthony-G 3y agoAnother good reason to use uBlock Origin and select the “Block media elements larger than x KB” option (x defaults to 50). Edit: Wow! I just tried loading the page and see that the ridiculously large image still loads. That’s a particularly obnoxious website: the image’s HTTP header says that its Content-Length is 0 so it still gets downloaded by the browser.
- amelius 3y agoActually, aren't all browser extensions a security nightmare? Or has something changed recently?
- LapsangGuzzler 3y agoshout out to the Arc browser, which has it's own browser sandbox and WYSIWYG tools to build JS snippets that run in your browser. I'm not affiliated with them in any way, but they're really changing the way I look at browsing online.
- moffkalast 3y agoDoes that come on a CD along with Intel Arc GPUs? :D
- jprete 3y agoNo, because a typical safe-to-run browser extension is written in such a way that it can be examined to see what it does. AI-based tools can’t be analyzed based on their code, so the only way to make them safe is by limiting their capabilities. Any such capability limit is likely to be either too constraining, not constraining enough, or require as much planning ability as the AI itself.
- amelius 3y agoThe problem is the permission system. Like apps, extensions have an all-or-nothing attitude to permissions. Browsers should allow the user to be more specific about permissions, and let extensions think the user gave more permissions than they actually did. E.g. if extension insists that they need "access to entire filesystem", the browser should make the extension believe they have access to the entire filesystem, but of course the entire thing is sandboxed and the user can restrict the access behind the scenes. Without this feature, extensions will keep insisting they need access, and the user will eventually fall for it.
- josteink 3y ago
- matheusmoreira 3y agoPretty much every single extension that isn't uBlock Origin is a security nightmare.
- vorticalbox 3y agoEven unblock is, only takes the repository owners login to be taken an update pushed.
- hxugufjfjf 3y agoNo. There are many good, secure browser extensions.
- madeofpalk 3y agoSuch as?
- hxugufjfjf 3y agoPrivacy Badger, 1Password, HTTPS Everywhere, Dark Reader, to name a few.
- madeofpalk 3y ago> Add "Dark Reader"? > It can: Read and change all data on all your websites It already has the broadest permissions available. Dark Reader injects arbitary code into every page you visit. It's one silent update away from stealing all your sessions. This is a security nightmare. All browser extensions are a security nightmare.
- hxugufjfjf 3y agoInteresting!
- dustyharddrive 3y agoIf you have the time, will, and ability, audit the latest release and turn off auto update. That’s counter productive when the extension has its own attack surface of course. I also haven’t read anything concerning about Mozilla’s Recommended review system yet.
- Garcia98 3y agoThe issue is not AI, nor browser extensions per se, the issue is the lackluster permission system that Chrome extensions have, it's pretty similar to what Android had 7 (?) years ago, which should not be acceptable in 2023.
- activiation 3y agoAutomatic updates should be disabled by default...
- Roark66 3y ago>Actually, the current AI situation may be even more perilous than Jurassic Park. In that film, the misguided science that brought dinosaurs back to life was at least confined to a single island and controlled by a single corporation. In our current reality, the dinosaurs are loose, and anyone who wants to can play with one. I'm really tired of reading stuff like this above. Seriously, AI is a disruptive tech and some people will oppose any change, but this is too much. All of the "security issues" mentioned in the article are true for browser extensions,and perhaps even software in general. Then the author talks about "copyright mess" just before describing how it is pretty much resolved in their company (copilot banned). The only real "problem with AI" is really a "problem with cloud" or more precisely "problem with people's lack of understanding of it". Average people should be interested in finding software alternatives that don't undermine their privacy. For example look at AI image up scaling. Every single android app other than mine sends user's images to a server somewhere. Are those images retained? Are they scanned for whatever "legal purposes" the maker deems adequate? No one knows. No one cares. Well specifically in the entire world about 90 people seem to care. Why 90 people? Because that's how many users my android app has 6 months after release. (the app does all processing locally, free version is ad supported, paid version can be used 100% offline).
- deleted 3y ago[deleted]
- cyanydeez 3y agoWhile true, the main problem the ChatGPT era presents is the ability to do powerful things with weakly defined understand. This is like handing out footgun coupons to all citizens who become "of age" and saying it's cool cause they were already legally allowed to buy footguns.
- drtgh 3y agoI do not understand how is it possible that Internet browsers do not currently have already built-in firewall that allows the user to control where the connection requests in the browser in general -the tab, the loaded web, the addon- are going to and from, and filter them.
- deathlight 3y agoI have perment unstoppable hiccups that have occurred in the last week or so. Nothing I have tried has made them stop in fact I just hit up more every time I try to report record anything. I would like to just breathe without having hiccups and it's not even a choice for me I'm not even permitted to even attempt to stop this Behavior May hiccups are constant and unending. I have run out of ideas of who to pursue for help this is just Agony I can't even breathe without constant hiccup interruption I don't know how to make it stop and I'll do anything at this point.
- mptest 3y agohttps://pubmed.ncbi.nlm.nih.gov/3395000/ https://pubmed.ncbi.nlm.nih.gov/3395000/ In case you're not joking
- pastyvolz62dn 3y ago[dead]