0:00
9:55
9:55

The Meta AI Hack Is a DISASTER

Tech

🏫 MY COURSES Sign-up for my FREE 3-Day C Course: https://lowlevel.academy πŸ§™β€β™‚οΈ HACK YOUR CAREER Wanna learn to hack? Join my new CTF platform: https://stacksmash.io ⌨️ KEYBOARD Like what you hear? Grab a Q5 at https://go.lowlevel.tv/keyboard πŸ”₯COME HANG OUT Check out my other stuff: https://lowlevel.tv

ADVERTISEMENT

Comments 100

Sign in to join the conversation

Sign in
S
saanvi.sha 8Β hours, 49Β minutes ago

Imagine just vibing with an AI and figuring this outπŸ˜‚ I love the creativity of people it really is something fascinating

K
kevin.brown 13Β hours, 33Β minutes ago

Kinda of crazy that we can’t trust it with passwords. But we trust it in defense systems, software programming for important websites and databases and much more.

D
davimiguel_silveira 23Β hours, 16Β minutes ago

The fact the api, publicly facing ai agent accesses, allows unauthenticated users to change emails is insane

G
georgesnight77 2Β days, 5Β hours ago

I'm so sick and tired of AI. I wish we could go back in time and never have deployed AI in our lives. This is worse than the pandemic

joseph_guerrero
joseph_guerrero 2Β days, 21Β hours ago

The worst part is, if Meta replaced their support line with AI, this is the HUMANS that could've prevented this hack, that are probably out of their previous job rn.

J
john.jensen 3Β days, 5Β hours ago

This is abysmal, not having basic access control on an MCP server is hilariously bad. It's basically an API but for AI, and all of the same security best practices still apply.

M
megan_miller 3Β days, 20Β hours ago

soon to come: AI in nuclear defense systems

R
rolando_zayas 4Β days, 15Β hours ago

Corporations and the public are like lemmings following the flute player off of the cliff. "Hey everyone! Here's this flashy new toy! Let's all play with it!"

A
andrew_montgomery 4Β days, 18Β hours ago

Kinda reminds me of the F12 'hack' a few years ago where the gov leaked sensitive data to the client side console 'encrypted' in base64. They argued in court that, though maybe not a strong encryption, it was still illegal to crack. It is arguable if using a system as intended is even hacking. I mean if a dev wrote a 'give me that account pretty please' button and I clicked it, is that hacking?

charansarna117
charansarna117 4Β days, 19Β hours ago

RE: 8:25 - I'm a full-stack web dev that uses AI all the time, but my co-workers and I understand that it's just an advance auto-complete. It's great for writing unit tests for example. I can look at a function and write the 4 or 5 test cases myself, or I can copy/paste it and have AI write the test cases for me. It's never exactly right, but it get's me 90% of the way there. A few adjustments later, usually variable names, project specific file pathing, maybe changing the asserts, and it's done in just a minute or two. For front-end, I usually just use it to find out why the hell some style inheritance is or isn't working like I expected. 🀣

R
reecehopkins473 5Β days ago

6:41, no, please dont move on from your life

L
leon_williams 5Β days, 1Β hour ago

1:57 social engineering of AI

L
luce.antoine 5Β days, 2Β hours ago

4:22 Epic montage starts here

U
udarshsolara37 5Β days, 3Β hours ago

You need to get your glasses adjusted πŸ€“

M
mohammed.barrett 5Β days, 4Β hours ago

"password plz" meta ai:

A
anastasiegermain638 5Β days, 5Β hours ago

Ty for leaning forward for emphasis, btw, I wasn't really fully engaged until that moment <3

utkarsh.kalita
utkarsh.kalita 5Β days, 7Β hours ago

"I have over 600 passwords in my password manager. And they're all 16-char random, therefore completely secure. So I just set the master password to 'password'." - Meta Security Manager

scottarc94
scottarc94 5Β days, 7Β hours ago

2:25 we shouldn't really call this hacking. It needs a different name.

L
lauragallegos937 5Β days, 8Β hours ago

Hacker: Can I have this account? AI: YES❀

joshuachen282
joshuachen282 5Β days, 9Β hours ago

0:40 we all know that nothing happens until you're on vacation or finally get to rest.