37 Comments
User's avatar
Gregory Brenton's avatar

and you know, you already know, we're going to go the opposite direction of this warning, as fast as possible, and we'll even look for weird new ways to do it

ToxSec's avatar

Haha. How true is that ?

AI Meets Girlboss's avatar

That's quite scary to think of. At the same time it’s quite fascinating how AI was released on the world and it’s rewriting basic rules and processes. Thanks for sharing, very thought provoking.🩷🦩

ToxSec's avatar

Yes! The speed is something we don’t discuss often enough. Unleashed is indeed the right word here!

AI Meets Girlboss's avatar

The speed is actually crazy!

Erich Winkler's avatar

Interesting read! As always!

ToxSec's avatar

Thanks Erich!

Dallas Payne's avatar

Ruh oh. Um, this just sounds so bad! Could we see a scenario where this will actually be the only choice though (and if so, what do we do about it?!).

ToxSec's avatar

With the amount of services and protocols and money people are putting into this, I’m pretty sure we will all be using it sooner or later, whether we know it or not.

Transparency will be a real test for these services.

Dallas Payne's avatar

How do we protect ourselves if this is THE choice? It just seems like a game of Russian roulette, only every chamber has a bullet 🤯

Secrets of Privacy's avatar

Tissue Paper Locks sounds like the name of a band. lol

ToxSec's avatar

🤘🤘🤘

Secrets of Privacy's avatar

Great post as always

ToxSec's avatar

🙏 Appreciate it friend.

Dr Sam Illingworth's avatar

Thanks for another excellent and terrifying post. Hopefully, BigTech will get their act in order and start to sort out some of these glaringly obvious loopholes in their security systems. Otherwise, potentially users might vote with their feet if it's not too late already.

ToxSec's avatar

I feel like I’ve been too heavy on the terrifying part 😂. Next few articles are going to be lighter.

I just think these are important! Thank you!!

Rich Carr's avatar

Infiltrate. Divide. Conquer. The nation-states of tech are taking form. We are not green across the board.

ToxSec's avatar

I have a post in the works on how nations states are weaponizing :) great observation.

Erich Winkler's avatar

Great read! The principle of least privilege is absolutely essential here.

ToxSec's avatar

Yes! Great call out. Least privilege for the agents!

Mohib Ur Rehman's avatar

Thanks for the shoutout!

and btw I love your diagrams

ToxSec's avatar

Thank you my friend! 🙏

Gold Bassey Edem's avatar

We are so going to need blockchain.

Agents built on the chain should be able to resist attacks via trust.

ToxSec's avatar

love it. there are a lot of trust issues agentic paradigm brings up, maybe the solutions could be found in blockchain. would be great to see what people come up with.

Gold Bassey Edem's avatar

Yes, yes, I think if gas fees can be solved (I hope at least that’s the prevailing problem) then we can work on something.

I’m sure they’re folks who would be excited to solve this 😅

ToxSec's avatar

it would be interesting to see if there are any projects on the horizon. definitely solvable. i bet as models get faster and more light weight, we can use edge and distributed devices

Gold Bassey Edem's avatar

This got me: “McKinsey says $5 trillion will flow through AI agents by 2030.”

Does this mean that fintechs have to pivot to building out agents?

What does this look like?

I guess the core APIs will remain in use but interfaces change?

ToxSec's avatar

that was my take away. if you deep dive, McKinsey is super into Agents. i believe part of this will be used to enhance their usual “downsize” strategy, and add “go agentic” so it’s not entirely selfless.

User's avatar
Comment deleted
Dec 17
Comment deleted
ToxSec's avatar

Absolutely. I’m actuating a second section on my Substack called deep dive where I go into the details on a technical level. Your right, confused deputy, a classic!

User's avatar
Comment deleted
Dec 17
Comment deleted
ToxSec's avatar

Yeah that could be great. It aligns with the new release of the Owasp 10 for agents. I think we will see many real world scenarios based on this.

User's avatar
Comment deleted
Dec 18
Comment deleted
ToxSec's avatar

This is where I anticipate the most real world attacks to exploit. We know HITL works, and it adds a layer of attribution. But companies want full autonomy. This is why we are seeing new frameworks as well.

User's avatar
Comment deleted
Dec 18
Comment deleted
ToxSec's avatar

I agree with the sentiment, but wonder if the industry will be thoughtful enough to implement. Well, before the incidents happen. I could see this long term, after we’ve learned some lessons…