Hacker News new | ask | show | jobs
by 8note 17 days ago
you choosing to throw a log file into eval() without reading it does not make the log file malware.

you are the one executing the log file. this is a smart decision that you chose to make.

executing a thing not intended to be executable is just a bad decision on your part

1 comments

That could have been a valid argument 5+ years ago, but won't fly today. It is a known that AI that are used for coding necessarily read log files. It is also a known that some AI are susceptible to prompt injection. Given that knowledge, and the very clear intent to utilize said knowledge to cause undesirable behavior on a user's computer when certain conditions are met, we're now undoubtedly in malicious territory. It's akin to someone making it clear that they don't like kids and don't want to see any in their favorite park, then taking the extra, deliberate step of placing a disguised loaded gun by the swings where a child could easily find it.