We went through this right? This happened at the beginning of the year (https://news.ycombinator.com/item?id=47150122, probably more links on HN). It's a super careless thing to take such tech and just release it on anything important, and she's a "security researcher" no less.
This is just a competitor with an agenda (pro regulation) trying to scare people away from unregulated stuff.
Yesterday Claude Code made 5 large edits to my codebase in planning mode (claims it used a bash script instead of standard read/write tools so the guardrails didn't trigger) it's why I put agents in containers.
Not the first to discover that a rule file saying "please don't do X" is not permission management. Funny that she mentions it worked on het toy inbox but the real, large inbox ran into issues; The more context you add the less weight "rules" (instructions) have. Happens to the best it seems.
"Attention" is a feature that makes this whole thing work in the first place, it's not a flaw, although all current models are non-ideal at it in practice. Could be better for sure :)
It's one thing that this happens. It's a whole other that there is a public story about this.
Having worked at a large tech company for a long time, there are very strict controls in place to ensure what is published (even under personal employee accounts), and Meta employees are some of the most tight lipped people I have come across.
If I were take a stab at reading between the lines, I would say Meta is trying their best to FUD their AI competitors... probably because they are so so far behind.
This article is from Feburary when the OpenClaw and "lol my agent ate my homework" type marketing was peak. Fundamentally the story means nothing except an AI researcher not understanding how AI works and just yolo openclaw
We went through this right? This happened at the beginning of the year (https://news.ycombinator.com/item?id=47150122, probably more links on HN). It's a super careless thing to take such tech and just release it on anything important, and she's a "security researcher" no less.
This is just a competitor with an agenda (pro regulation) trying to scare people away from unregulated stuff.
Yesterday Claude Code made 5 large edits to my codebase in planning mode (claims it used a bash script instead of standard read/write tools so the guardrails didn't trigger) it's why I put agents in containers.
Not the first to discover that a rule file saying "please don't do X" is not permission management. Funny that she mentions it worked on het toy inbox but the real, large inbox ran into issues; The more context you add the less weight "rules" (instructions) have. Happens to the best it seems.
> The more context you add the less weight "rules" (instructions) have
That is such a basic flaw in LLMs
"Attention" is a feature that makes this whole thing work in the first place, it's not a flaw, although all current models are non-ideal at it in practice. Could be better for sure :)
Irony: the screenshot with the openclaw logo at the top lists as the first feature "Clears your inbox".
What happened to write-only backups in case of ransomware?
Or in case of regulatory investigation. But, honi soit qui mal y pense...
Early OpenClaw Lore
It's one thing that this happens. It's a whole other that there is a public story about this.
Having worked at a large tech company for a long time, there are very strict controls in place to ensure what is published (even under personal employee accounts), and Meta employees are some of the most tight lipped people I have come across.
If I were take a stab at reading between the lines, I would say Meta is trying their best to FUD their AI competitors... probably because they are so so far behind.
How many more face eggs until we pop the AI yolk?
This article is from Feburary when the OpenClaw and "lol my agent ate my homework" type marketing was peak. Fundamentally the story means nothing except an AI researcher not understanding how AI works and just yolo openclaw
[dead]