Point by point:
> “OMG you can jailbreak it and get it to spill its VM”
This is the whole point; any content on the VM is yours. It runs in an isolated sandboxed VM separate from stored credentials etc; this is effectively your own computer. You don’t have to trick it.
> It collects dossiers on your contacts
These are more text files that live on your private VM, alongside memory.md, etc. Do you want your secretary to forget every person you contact every day?
> It accessed Messages without full disk access
This whole story never made sense or was substantiated. Full disk access is an OS level security boundary; the user had to switch this on.
> It sold some guys stuff for too cheap and gave out his address
OK this one I basically believe, haha. Because this is the problem with Muse: the LLM is just too dumb to perform complex tasks effectively in many cases.
Why though? The comment you're replying to is explaining how the accusations of poor privacy are nonsense and you've just replied "I disagree because they have poor privacy".
I mean I'm not going to hand over any data to Facebook if I can help it but it doesn't seem like there are any specific issues here.
Yesterday everyone was all worked up about OpenAI generating an image with a signature on it.
Caveat emptor. Don’t be an idiot. Grow up. Make informed decisions regarding your use of these products and take responsibility for those decisions.
Feigned outrage, indeed. I don't think it's unreasonable to point out that Meta has been consistently predatory, reckless, and creepy with user data before, and that this is a very aggressive expansion of that.
The old facebook booster retort of "if you don't like it, don't use it, take responsibility" or whatever is nonsense. You're in their system whether you use their product or not. Even if you somehow avoid their pervasive web-wide tracking, a single contact you know installing this thing and gobbling up all your correspondence with them can compromise your privacy choices, and that's well beyond your control, unless you seriously suggest I audit every single one of my contact's devices and browbeat them into using the privacy choices I prefer.
Get real.
I just do not trust any of them, not with my money or with access to my conversations.
Unless these AI assistants are running on self-managed platforms independent of their developers, all I see is immense counterparty risk.
Comments like this are in a different reality than most consumers. Most consumers don’t care about things like avoiding lock in to a platform. If the platform solves their problem then they don’t have any reason to leave it anyway. They’re not worried if their data is used to show them more targeted ads.
Topics like this show a sharp divergence between what you read on Hacker News and how actual users operate. We already knew that people who don’t trust Facebook aren’t going to suddenly start using Muse. They were never going to consider it. For the people who do actually use Meta products, which is a customer base counted in the billions, many will not have any problem using these tools.
But, “most consumers” don’t care about that. The beverage industry is insanely profitable, especially with recent forays into “energy drinks”.
Do people who drink so much dissolved sugar live without consequences? Absolutely not. They have a significantly lower quality of life and die much sooner than people who do not drink dissolved sugar.
I don’t see your comment as a valid dismissal. Just one more way that individual outcomes in our society are increasingly K-shaped.
I even have a Talos workstation. Open hardware motherboard and open spec CPU both made in the US with fully open hardware. Also a Precursor which is similarly open.
I support these efforts as much as I financially can, but I admit open firmware/hardware is not a gap I have fully closed day to day. Yet. Deep down in some hardware is firmware I do not control, such as on the inside of my AMD GPUs. But I wallet-vote for those over Nvidia who require proprietary code in user space where it requires rights within my operating system.
Try as I might some are so addicted and gone now that they just come over, doom scroll for a few hours, and leave. Maybe they feel like they get something out of just being in the same room as other people. It confuses me, but I will not force my views on guests.
Doesn't that imply Meta itself believes users care?
These types of comments just show what a massive bubble you're in.
The fact you think it's a "clear majority" and not a "sizable, but still loud minority" of workers shows that you're in a bubble.
The vast, vast, majority of people are largely apathetic to AI as a technology at large, with general techbro-sentiment trending very negative (for all technology, across the board), especially towards SV/AI figureheads.
Or when they are hit by any other privacy fuckup like that.
[1] https://futurism.com/facebook-beauty-targeted-ads [2] https://www.bbc.com/news/health-61320202 [3] https://tech.yahoo.com/general/articles/facebook-made-money-...
Notes: actual quote is "If you're evil, you're at least competent. And if you're evil, you're not bad. And therefore, maybe you're actually kind of good because you're at least getting something done"
They were discussing how tesla manages problems with full-self-driving.
It was interesting how this realm of problems was viewed.
If there was an accident while the car was driving itself due to some glitch, the police at the scene put all the blame on the driver.
The book had a different viewpoint. obviously there was a tesla bug in full self driving, and they kept their mouth shut.
meanwhile society/government doesn't even think of this and puts responsibility/blame on the user.
HN must understand that they are not a representative sample of anything.
It is reasonable to assume the majority of humans are intellectually lazy to the point of killing themselves and their families if told to with the right marketing.
We should all make our own individual well researched choices and not ever buy into the worthless argument of "everyone does it".
There are plenty of happy, successful people who didn't die because they used a Meta product.
In fact I'd even argue that all things equal, a Meta user is happier than a paranoid-meta-hater who worries every minute that someone is going to serve them an Ad that fits them
"oh, the horror!!!. How am I ever going to recover from the trauma and financial ruin of seeing a targeted ad."
And plenty of teens that never became happy and successful people because they used a Meta product.
These companies are predatory, and have nothing to offer us we cannot easily setup at home these days with privacy and sovereignty.
Did you just move the goalposts to “it didn’t kill me”?
We’re talking about society-wide effects here, including harm to children for which Facebook is paying 17 billion dollars.
https://oag.dc.gov/release/attorney-general-schwalb-announce...
Your comment implies no harm matters so long as people can sue for it later?
We have a lot of deferred problems to go back and solve before all these dreams can come true.
Am I missing something with the concern about ability to constrain the blast radius?
They also have a bad habit of accidentally building URLs that hit Alibaba infrastructure, likely because their training environment had them use those URLs. If you haven’t watched the outgoing network requests you might be very surprised at what your Qwen agents do sometimes.
Speak for yourself. I hated the idea of agents ever since I first heard of it back in the 90s or 00s. For me, the most valuable feature of computers is predictability. I want tools, not agents. A computer should augment my own skills, not replace them.
Last night I had ChatGPT go through an old email account and surface memories that I literally forgot. People who I have fond memories of. Yea I could have spent time querying gmail and digging but the agent did it in a way that really resonated. I don't care if Sama has my emails now. I do care about connecting with my past and enjoying the memories of a time long past.
Paranoid scolds of HN want the average person to be deprived of value like this for some reason.
I am perfectly prepared to believe you had a nice interaction with the robot. But this is an insane thing to say!
If Meta/OpenAI/etc would guarantee they’d compensate you in full for anything that wasn’t supposed to happen —and had an established track record of doing so— it would make trusting agents to make financial choices easier
lol… talk about delusion.
I am very curious as to what other people of using these agents for? Some of the use cases I hear; comparative shopping, travel planning, etc. don't appeal to me. Our people using them to manage family life issues like school schedules, meetings, etc? I feel like I am missing out, but I also am not seeing the greater appeal yet.
Some of my recent use cases...
Help me find cheap flights and a hotel and plan some interesting sights to see because I am speaking at x conference on x date.
Download all my favorite music from x streaming service as FLAC files locally, then convert them to OGG and put them on my portable music player.
Download all my youtube subscriptions locally to this folder and strip out any ads or sponsored content.
Here are a list of all the books I own. Can you find me DRM-free epub copies and put them on this e-reader for me?
Here is a picture of an object next to a measuring tape. Can you 3d print me a holder perfectly sized for it based on a openscad file i can easily tweak?
I am really stressed right now. Can you help me talk through everything I have to do and help me rationally prioritize? Can you remind me and keep me on track and be my fake boss for today?
Can you look through my email and keep track of any appointments or invites so I stop missing meetings?
I could see shopping being the same way, let the agent shop for you or identify good deals on things you want but then push them to you to make the actual purchase. Like you, I'm certainly not going to let an agent make a real purchase for me unattended and I doubt any merchant is going to have much sympathy for "my AI bought this by mistake".
> (…)
> I just do not trust any of them
So… Actually not the future stuff we wanted? That’s what bothers me when people say “we have the Star Trek computer”¹. We clearly don’t, because if we did we knew we could trust it with a high degree of certainty. Instead what we have is a computer we must distrust to a high degree. One of the two crucial variables is flipped.
¹ I’m not saying you are saying that, but several people have expressed that sentiment on HN.
I have no doubt they would have no problem outsourcing everything to agents.
Or did they make a fatally wrong diagnosis that was only discovered because the old doctor whipped out their medical encyclopedias? You left us hanging without the relevant part of the story!
It feels and seems too forced.
I find all this is just the next-gen privacy violation, disguised obviously as: "Oh, WOW an agent in the computer is doing all this for me". Bullshit.
It seems that never is enough with these ever thirsty companies, they keep pushing the limits and surprinsingly a lot of people do not care at all nor value the implications of having an arbitrary process running and doing pretty much whatever the agenda of their creators are.
We are an opportunistic species. We don't have perfect knowledge nor thoughtfulness.
We need to protect each other.
We don't.
"Hermes, clone this android app to my computer, add this and this feature and fix this annoyance and then rebuild it and push it to my phone"
"Hermes summarize this YouTube podcast and push the summary and transcript to my Obsidian vault"
"Hermes check mg obsidian notes for when I last wrote a blog article about Neovim's integration with AI agents"
*Hermes, you have an API token that allows read only access to the Zabbix monitoring system, check that and then use the Proxmox API token that only allows you to do limited actions to reboot the VM that is having issues"
Etc, etc,
This level of unfettered access to your personality, lifestyle, and secrets allows for an unprecedented kind of manipulation and control. You could see it as a new kind of wealth transfer: not only will They sell you things, They will subtly manipulate behaviors of the masses via trusted agents.
I think to the vast majority of people having one of these companies run an agent platform is going to be business as usual.
In mine, I don't.
That seems like an oversight/ opportunity.
Let’s not forget Facebook caused a genocide
What most people are arguing is whether or not it's worth it. These things are essentially executive assistants, which historically have also been massive vectors for security leaks. EAs know the most about you, your behaviors, and your motivations. Still an EA is almost always worth it if you can afford one. Given now the cost is free, Muse is something I've both used and recommended. It's worth the risk for me.
at the cost of all your data and probably your eternal soul
A free digital EA confers none of that—and it will annoy everyone you know. The only use case I see having legs is dealing with large bureaucracies like canceling subscriptions or medical billing issues, but there I think the common man will lose as the rise of this automation will see a distributed adversarial response from bureaucracies who will happily put up whatever barriers are needed to prevent Muse and other digital EAs from impacting their bottom line.
There's a 50/50 chance I'm just getting old here, but I really think we're going through an epochal shift where new consumer tech won't have the same reception as the smart phone and increasingly addictive bite-sized algorithmic media did over the last couple decades. I think going forward there will be more palpable questioning from younger generations about why do we even want some of these tech products? At some point convenience reaches diminishing returns and we have to think deeper about what we're trying to get out of life.
I don't like or trust meta any more than I always did but I don't see how they could have done a "better" job with this. These kinds of agents are inherently pretty risky IMO but I don't see how this one is particularly more than any others.
Playing around with it I really don't get the sense there's any hidden prompt contradicting what's visible. It's nearly gleeful at using the VM in ways that were not intended and likely against meta's interests. I feel like someone must have won a really interesting internal power struggle to get this thing out in this form.
It will happily disclose its entire system prompt (which is interesting in its own right, and worth a read) or pop a reverse shell for you
> I don't see how they could have done a "better" job with this
I generally agree -- the openness is great. However, from experiences both inside and outside of Meta, good execution, a hacker ethic, and transparency ultimately has very little propping it up when money is on the line. In fact, it could be argued that Meta has a shareholder obligation to do profitable things such that even the best intentions can (and usually will) fall in the face of corporate hierarchy and sales numbers.
I think they did a pretty bang up job with Muse (the lack of communication with first-time agent users around how powerfully and confidently they can make horrifying mistakes, and how careful you need to be with prompting, and how even that sometimes isn't enough, notwithstanding).
I also think it will inevitably be used to squeeze profit, and given Meta's history, I think it's almost comical to not assume that will involve violations of the spirit of privacy. (and that's assuming that a proliferation of "it deleted all my files" "it messaged my ex" "it leaked private info" doesn't poison consumer sentiment before it even gets off the ground)
Also Meta is actively encouraging users to grant them full permission, insisting with all their marketing might that it’s safe, which they know is a complete lie. Hard to blame the user when they’re being actively deceived like this. Other agent companies are more reserved and say things like “be careful” but Meta is the opposite.
As for security models, it's probably long since time to sandbox all data and apps. More like mobile devices. Allow users to toggle that all off so they can use their computers for development etc, but the default state should force apps/tools to explicitly ask for permission to any folder, other app, API, CLI, etc. And ask for that permission regularly (or rather, reset the permission after some period of time). Or something like that (I haven't given it a great amount of thought).
I don't trust any of the hyperscalers to place me as a user first, I expect them to guide me into a stall, strap on a feedbag, and start the value extraction process while they build the meatrix[1] around me.
I want tools like Muse, and Meta Glasses, Google Gemini and a horizontally integrated AI agent, but I want it on my terms, where I am in control and accountable, and without a layer of data collection and harvesting on top of it.
Fortunately I am skilled enough to assemble most of what I want, but I fear a world where people who lack the skills and resources I have available have no choice but to onboard and give up control in order to remain competitive, employed, and connected in the world to come :(
Trying to think of a number that I would consider it, and honestly $1k/month wouldn't convince me unless
- I have root on device
- device is on its own vlan, fully segmented
- !(SIM || 5G antenna)
- no google/apple id authenticated on device
- terminate agreement at any time without cost
I'm probably forgetting/not aware of ten things I should consider.
Why are we depending on LLM "reasoning" to negotiate a price rather than just having the user enter a lowest acceptable price deterministically?
(As a human, it's more physically taxing to think, and less taxing to relax. Conserving internal resources improves our survival odds. So when an opportunity presents itself to use less effort and still gain out of that, we tend to take it.)
As human technologists, I believe we need to protect humanity more.
In everything that we do, we need to think about the ways that our proclivities as a species can be compromised by our development of technology.
Can someone explain how this is possible? If an app can do this without Full Disk Access or a popup of some kind that's a way bigger lapse on Apple's part than Meta's.
Typical "leopards ate my face" moment. You give AI (from Meta, nonetheless) full-disk access and then complain that—wow—it really meant FULL.
In a perfect world where you got nothing to hide, where companies don't sell your data and there are no hackers, even I would love to just hand all my data to Muse and have it be my trusted assistant. People who think we live in such a world are already doing that, evidently.
There was no recent update. Apple's announcement was about a future macOS update.
the company's brands are toxic and they know it.
No way I would allow them to develop the agent that runs my life. Even if it works well now, the rug pull is absolutely inevitable.
[I was never all that into facebook, but it was nice to get an update on an old high-school friends once every month or two. Now its completely unviewable.]
The MOMENT they can, Meta will take all data they have about you and sell it to anyone who wants it, including to people who wish to do you harm.
Honestly, this is where actual government regulations with teeth would make me significantly more comfortable. But self-regulated? Absolutely not.
That's their whole modus operandi, a privacy nightmare which will feed their infinite money machine.
Reading "Careless People" didn't make me surprised at all on how the company operates, it surprised me with the personal descriptions of how people like Mark Zuckerberg and Sherryl Sandberg actually are as humans. It scared me how most people at that level of wealth and power isn't too different from the accounts in the book, they're all seriously deranged people with a gigantic lever to impose their distorted realities upon the rest of humanity.
People who give their data to Meta are uncomfortable with Meta collecting that data.
Hmm.
> Zuck: They "trust me"
> Zuck: Dumb fucks.
What lessons could zuck have learned, when he's been incredibly successful since these college days? The guy has become one of the richest and most powerful people on the planet _because_ of disregarding trust, and continues to operate the same way, I guess it's not impossible he fundamentally changed but I don't see a reason to think he did
Or it might just have been a dumb thing a young person said
Facebook is like Microsoft at this point: The thing your grandparents use.
Even if they make something technically superior for a while, like what the Zune was to the iPad, tHey'll never really be cool.
and they'll certainly never be trusted.
The Muse app is very polished and it seems to actually be popular with younger people.
I have tried it out but I’m still struggling with use cases, same problem I had with OpenClaw
The question implies you already are. But yes, obviously.
However, surely by now even the lay people who have seen the testimonies before Congress, the lawsuits and the excesses by Meta execs over and over again ought to be atleast somewhat wary of handing them more personal data?
I think the average person has very similar self preservation instincts as the rest of us. So it can't be that. Which leaves the fact that there are lot of people who don't know about the above mentioned scandals galore that Meta has been involved in?
-Mark Zuckerberg
Today’s version of the platform targets just the right emotions to keep users “engaged.”
Related:
Updates to Full Disk Access in macOS
https://news.ycombinator.com/item?id=49937631
Meta’s Muse has a serious 0-day
https://news.ycombinator.com/item?id=49802030
Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions
https://news.ycombinator.com/item?id=49893709
Maybe don't let Muse run your Facebook Marketplace account
https://news.ycombinator.com/item?id=49875006
What Meta got right with Muse
https://news.ycombinator.com/item?id=49946526
Muse – Meta’s personal AI agent