Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

1) This is not APT.

2) While injection has potential, this is fairly well mitigated. Look at comet and others.

These are all whataboutisms coming from a place of fear.



Pretty sure simonw's lethal trifecta [1] has not been "fairly well" mitigated.

[1] https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/


Good thing we're not talking about a LLM then.

From the article: It's a side page agent that has only access to the page, and outputs content in text only, and awaits user confirmation on actions. It's all on the page. It's I guess it's a mono-fecta?


Then it's contained but depending on the user it can be a vector for a (para)-social engineering attack.

PS: It is Gemini based, that's an LLM.


No LLM model has enough mitigations to prevent injections.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: