Hacker News new | ask | show | jobs
by rolph 4 hours ago
it is forseeable that MS would be very interested in taking a security stance vs a very possible vector.
2 comments

I was going to guess that they accused the author of copying code from Office. Was AI used in the project? Perhaps a model regurgitated copyrighted code leading to a sternly worded notice from legal...?
Ooooh yeah. Looking through the author's past posts: "got a lot of skepticism because we're developing heavily with AI"

So AI was in use. Then the author says that following the spec alone wasn't enough to get it working, they got "active community feedback" and fed that feedback into the AI until it worked just like Word. I have to think that if there were ANY conditions under which a model might output code that Microsoft legal would threaten to sue you for, these would be them

How do you copy code from Office? Is the source code public?
I suspect the source code for at least some older versions of Office is absolutely in the training materials of some LLMs. There have been leaks before, and the early models were trained on the entire contents of the internet without regard to legality
Today's LLMs are perfectly capable of disassembling.
Clearly, it was the fault of the AI, and it should be thrown in jail.
I think this (if it is what happened) is a perfect demonstration of the dynamics. If you use AI to do things you couldn't have done on your own, you're copying off someone else's homework and the real risk is that you don't know who you're copying from, but they probably do.
A vector against a standardized XML+ZIP document format?
‘’ <—— li’l Dr Evil air quotes to put around ‘standardized’ ;-)

If anything it’s DOCX itself that was the vector!

IP is not the only issue. BTW this discussion is being chilled so now an exercise in abusive DV harvesting.

Understanding DOCX Malware and Hidden Threats

https://cloudmersive.com/article/Understanding-DOCX-Malware-...

Hackers using Weaponized Office Document to Exploit Windows Search RCE

https://cybersecuritynews.com/office-document-to-exploit-win...