In a completely unsurprising turn of events, Meta’s Muse AI is stealing Apple Messages, past and present, and uploading the contents to its cloud, even if explicitly told not to.

  • jj4211@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    45 minutes ago

    How many times does it have to happen for folks to understand “telling an AI not to do something” doesn’t work reliably? Feels like the AI providers need to explicitly direct them to provide an explanation that such directives aren’t reliable and any expression of an agreement/promise doesn’t mean what one word intuitively think.

    • jj4211@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      49 minutes ago

      I don’t know the answer to this, but the AI agent would be at one of the “ends” of the conversation, so e2ee wouldn’t be a particularly relevant promise to that scenario.

  • tyler@programming.dev
    link
    fedilink
    arrow-up
    32
    arrow-down
    1
    ·
    18 hours ago

    Just an FYI for anyone that didn’t know, your iMessages on your computer are literally just stored in a SQLite db. They’re very very easy to read without the app.

    • atomicbocks@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      1
      ·
      13 hours ago

      Source? AFAIK iMessages are stored encrypted by the Secure Enclave and can only be read through the same process that Touch ID works through. That’s why they can’t do iMessage through a browser because there must be a Secure Enclave present on the device. Pretty much the same reason Graphene OS only works on some devices.

      • tyler@programming.dev
        link
        fedilink
        arrow-up
        8
        arrow-down
        1
        ·
        11 hours ago

        Me? I wrote an app to read my iMessage database to pull two factor codes out and type them in automatically cause I was lazy.

            • atomicbocks@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              2
              arrow-down
              1
              ·
              10 hours ago

              This is describing the ability to read the messages from the actively booted and decrypted partition. This would absolutely not work without being able to log onto the machine. So while you are technically correct you are leaving out the caveat that this only works when you can also access the app not strictly without the app.

              • Elvith Ma'for@feddit.org
                link
                fedilink
                English
                arrow-up
                4
                ·
                8 hours ago

                But the context is, that Meta’s software can extract them. For the software to run the system must be booted and the partition is likely already decrypted. So we’re exactly in this state.

    • Pronell@lemmy.world
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      14 hours ago

      Is Android any better in this regard?

      Not whatabouting, generally ignorant and curious.

      • tyler@programming.dev
        link
        fedilink
        arrow-up
        7
        ·
        11 hours ago

        I don’t think Android has a corresponding computer operating system so no? This doesn’t apply to iPhones or iPads. Just Macs. And I’m not even sure if it applies to M series MacBooks, but it applied to the old intel ones about 5 years ago at least which was the last time I read my messages that way.

    • Leon@pawb.social
      link
      fedilink
      arrow-up
      9
      arrow-down
      2
      ·
      13 hours ago

      Hard disagree! Yes, we know that Facebook does this. The average person doesn’t necessarily, and they still deserve privacy!

      This victim blaming nonsense plays right into the corpo playbook. It’s the privacy equivalent of “with what she was wearing she was practically asking for it” and we all know that’s bullshit.

  • TootSweet@lemmy.worldM
    link
    fedilink
    English
    arrow-up
    9
    ·
    18 hours ago

    without consent

    I’m surprised the EULA doesn’t say “by using Muse you agree to any fuckin’ thing Meta/Muse wants to do including ones we haven’t thought of yet”.

    Not that that constitutes “consent” in my book, but I wouldn’t think the article would say “without consent” if there was something in the EULA permitting them to do basically anything.