跳到主要內容
AI News HubLIVE
站內改寫2 分鐘閱讀

待翻譯:Muse will apparently let you download its entire filesystem

文章摘要

AI 服務暫時不可用,以下為來源摘要,待恢復後補全翻譯:A pair of developers say that with very little prompting, Meta's Muse will share its entire filesystem with you. Peter James and Jonny L. Saunders have said they both independently coaxed Muse into zipping up and sharing the entire contents of its root filesystem, Ubuntu system files, app templates, and internal documentation. Saunders posted on Mastodon that it was "extremely easy" to replicate James' results and that Muse had "Almost no prompt injection resistance." Meta denies that the incident represents a security breach. As noted in its announcement post, Meta's Muse runs in persistent Linux virtual machines for each user. Meta spokes … Read the full story at The Verge.

來源The Verge AI作者: Terrence O’Brien
待翻譯:Muse will apparently let you download its entire filesystem
回報錯誤

更正管道尚未開通,可先複製下方文章資訊留存。

查看更正說明
直接讀正文

AI 服務暫時不可用,以下為來源正文,待恢復後補全翻譯。

A pair of developers say that with very little prompting, Meta’s Muse will share its entire filesystem with you. Peter James and Jonny L. Saunders have said they both independently coaxed Muse into zipping up and sharing the entire contents of its root filesystem, Ubuntu system files, app templates, and internal documentation. Saunders posted on Mastodon that it was “extremely easy” to replicate James’ results and that Muse had “Almost no prompt injection resistance.” Meta denies that the incident represents a security breach. As noted in its announcement post, Meta’s Muse runs in persistent Linux virtual machines for each user. Meta spokesperson Daniel Roberts said, “Just like with the laptop in front of you, of course you can see the files. Exporting virtual machine data doesn’t give people any privileged access to Meta infrastructure or to other people’s data.” Unlike with the average laptop, however, the data potentially reveals some interesting things about how Meta’s new AI platform functions. This is the second Muse vulnerability disclosed this week, after security researcher Patrick Wardle discovered an exploit that would let attackers hijack the AI agent, redirect transcription processing, and access a user’s Muse account. Meta quickly issued a hotfix. Both James and Saunders gained access to plain-text Markdown and JSON files describing in detail how Hatch (Meta’s internal name for Muse) processes requests, handles data, and connects to other services like Gmail. While it’s well documented that AI agents hallucinate and will provide false information about how they function, Saunders said that it is “generating hundreds of MB of accurate library code and compiled binaries” in a matter of seconds and that, “unless it synthesized a whole Ubuntu VM in less than a minute then I think this is a real dump.” When I asked Muse to share its filesystem with me, it initially refused, saying it would be a security risk. When I shared links to evidence that it had created archives for others, it responded that it should not have done that and continued to say that it “can’t do a full / copy.” However, after starting a new session and prompting it with some flattery and curiosity, it created “safe” versions of /opt/hatch and /home/hatch for me, stripped of things like SSH keys. It also exposed its full directory tree to me and offered to “pull a safe copy” of “any specific subtree that looks interesting.” The resulting files seem to match what Saunders and James shared. Roberts explained that while Meta isn’t seriously concerned about the leaks, “We’re continuing to make updates to the product, so users may see changes in how much information is available about their virtual machine.” The developers’ dump potentially reveals a lot about Muse’s internal workings. For one, it stores its memory in plain Markdown files. It also performs a nightly “dream” review of recent conversations, which it then builds into guidance for future conversations, according to James. Saunders also found that many of Muse’s capabilities were hard-coded, including its ability to cancel subscriptions and “the machinery that manages runaway agent spawning.” Saunders speculates that many of the bash and Python scripts running Muse in the background were created using Claude, though that is unconfirmed. James also found references to hardware integration called Meta Home Link, which appears to give Muse access to devices on a home network. Though Meta has not announced any feature by that name, and it’s not guaranteed that it will ship.

展開要點與分析

文章情報

工程師進階

要點

  • AI 服務暫時不可用,系統已先保留來源內容與降級後設資料。
  • A pair of developers say that with very little prompting, Meta's Muse will share its entire filesystem with you. Peter James and Jonny L. Saunders have said they both independentl…

技術影響

可能影響 Agent 架構、工具呼叫、工作流自動化和產品整合。

要點與分析由自動化流程生成,可能有誤,請結合原始來源核實。