|
|
|
|
|
by tee-es-gee
54 days ago
|
|
I do think that as service providers we now have a new "attack vector" to be worried about. Up to now, having an API that deletes the whole volume, including backups, might have been acceptable, because generally users won't do such a destructive action via the API or if they do, they likely understand the consequences. Or at the very least don't complain if they do it without reading the docs carefully enough. But now agents are overly eager to solve the problem and can be quite resourceful in finding an API to "start from clean-slate" to fix it. |
|
It was never acceptable, major service providers figured this out long time ago and added all sorts of guardrails long before LLMs. Other providers will learn from their own mistakes, or not.