29 points
*

Do not mix code and input data.

permalink
report
reply
17 points

Right. I don’t know how the hell someone managed to reveal their OpenAI key to the LLM itself

permalink
report
parent
reply
17 points

I don’t think it gave him the openAI key, he just had the ability to send as many hijacked (not game related) prompts as he wanted through the game on the devs’ dime.

permalink
report
parent
reply
0 points

Which, now given the ability to inject arbitrary code, you could conceivably now write code to list every variable it had access to.

permalink
report
parent
reply
7 points
*

They didn’t. The point was that the guy could use their implementation freely as if he was paying for a chat gpt license. Basically he made the ai let him run any query he wanted trough it so he just has unlimited access to the paid version of chat gpt at the company’s expense

permalink
report
parent
reply
22 points

It’s kind of magic how we are finding that having a third party resolves a lot of the issues. I wonder if the future structure will rely on more of a Prompt > Filter AI > Generative AI > Filter AI > Output. It seems ChatGPT and the Bing implementation have at least some level of AI detection on the image side already.

permalink
report
reply

We tried this same solution six months ago. It works, ish, but it can still be circumvented. It’s not foolproof enough to trust with any situation where you need real security / confidentiality.

If you haven’t played Gandalf try it out. It will teach you how to craft attacks against these kinds of strategies.

permalink
report
reply
2 points

If you haven’t played Gandalf try it out. It will teach you how to craft attacks against these kinds of strategies.

Well, that was fun!

permalink
report
parent
reply
18 points

Once they explained the problem I instantly thought this would be a great job for a LLM haha

permalink
report
reply
20 points

It’s LLMs all the way down.

permalink
report
parent
reply
13 points

The technology worked great, but let me tell you, no amount of regular expressions stands a chance against a 15 year old trying to text the word “penis” onto the Jumbotron.

permalink
report
reply

Programming

!programming@programming.dev

Create post

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person’s post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you’re posting long videos try to add in some form of tldr for those who don’t want to watch videos

Wormhole

Follow the wormhole through a path of communities !webdev@programming.dev



Community stats

  • 3K

    Monthly active users

  • 1.7K

    Posts

  • 28K

    Comments