π Newsletter #014 - Many, Many Leaks; Being "Opted In;" and Cursed "Podcasts" for your Children
β¨ In This Edition β¨
- π Short-Form Content: On many, many leaks - of credentials, unpublished games, and entire passports; being ""opted in"" to chatbot activities; and on having the robot create a "podcast" instead of talking to your children in the car.
- π Good News!: Top court in France blocks the under-15's social media ban; A judge in the US has ruled that Google needs to make it easier to use rival app stores; and there's now a font to fool AI scrapers.
- π― The Post-Script: Reading How to Talk about 'AI' without Adding to the Anthropomorphization by Emily M. Bender and Nanna Inie.
Original images by Nathan Kelly and Joe Zlomek on Unsplash. Cropped and edited.
π Short-Form Content
Chatbots ("AI")
- There's been a huge leak of credentials and secrets apparently stemming from devs using LiteLLM. Nothing to see here! Adopt AI now! No, adopt it faster!
- A solo game dev discovered that a player found out the name of a character in their unreleased game through Google Search AI.
- The reason? Google automatically opted everyone in to having their Drive files scanned & used for AI training. Suuuuuper cool.
- If you use Google Drive, you may want to check your settings as you too may have been "opted in."
- More on being "opted in:" Twitch is now mining people's streams to train Amazon's AI. Twitch is also "positioning this setting as a favor to users." Which, yes! Yup. Totally.
- Rovo, Atlassian's chatbot that hooks into Jira, Confluence, etc., and is thus used by a ton of companies for task work, issue tracking, and documentation, appears to be susceptible to zero-cllick data exfiltration via prompt injection. (PromptArmor)
- This meme has been making the rounds - train a chatbot on your family's calendars, feed it your kids' interests, and bam! You can have it create a "podcast" for the drive to school. Instead of, y'know, using your meaty brain pans and mouth pieces to talk to your children about their hobbies and interests. Phew! That's that solved.
- "Just let the money run out, it'll be fine in two years" may actually be a valid viewpoint to adopt for those among us who are forced to work with chatbots all day everyday by their bosses and workplaces?
Non-Chatbots
- One of the reasons age gating is not, in fact, a great idea: Nearly a million passports and photo ID's were left unprotected on the public internet. This data set containing heaps of PII appears to stem from age verification related to access to "cannabis clubs" in Spain, for example. As Schneier on Security says:
A high-value credentialβa passportβwas used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And itβs the low-value system that got hacked, putting the high-value credential at risk.
- Google has disbanded the AlphaFold team, assigning some of its members (those that hadn't left already) to the Gemini chatbot. AlphaFold, notably, had won a Nobel Prize for its relevance to medical research, especially around nerogenerative diseases, as it was incredibly useful in figuring out the "protein folding problem." But hey, β¨ chatbot! β¨
- Flock's automated license plate readers (ALPR's) may in fact not just be grabbing license plates, but also bumper stickers and timestamped GPS locations. Because, uh, why not, right!? I'm sure there is absolutely nothing nefarious that could be accomplished with a combination of these data points.
- More from Google: DeepMind's AGI Safety and Alignment team is advising that applicants avoid the company's AI hiring tools. "Fill in this form so we can make sure a human sees your application!" ... I don't even need to add a quip here, this is humorous enough all by itself. And sad. And aggravating. But humorous too!
- Apparently NHS England's patient records were visible to Palantir after all.
π Good News!
- Here's a big one on age gating & age-related surveillance: France's top court blocks social media ban for under-15's. The council blocked it on two grounds, one being the infringement of freedom of expression of minors, and the other being citizen privacy. More of this!
- This one should be interesting, especially given Google's plans to lock down android later this year: A judge in the US has ordered Google to make it easier to install rival app stores.
- There's now "fonts" out there that fool AI scrapers and foil unauthorized AI training. "ShieldFont" uses the same technology behind ligatures to poison the well for scrapers. Sad that we need this, cool that this has been invented. (ShieldFont :: ShieldFont Demo :: FastCompany article)
- Adding a note here as some have voiced concerns re: accessibility - the project claims that screen readers are not seeing the scrambled version of the text, but instead the real, underlying words.
- Digital rights advocates are launching petitions against smart glasses, which secretely record everything in their field of vision - without consent.
- Speaking of protest and resistance, Ben Baril, a student at the University of Alberta, is planning to protest "AI" data centres proposed for Alberta at upcoming town halls.
- There are alternatives to Google Search! Check out this post by Tuta (as well as this Technically Good blog post) for search engines whose primary goal isn't to monetize your eyeballs over serving you good search results.
π― The Post-Script
Reading How to Talk about 'AI' without Adding to the Anthropomorphization by Emily M. Bender and Nanna Inie.
Follow this blog via RSS | Find me on Mastodon | Bubbles
Recent Posts
