Sign in

Running With Spoons

@runswithspoons.bsky.social
291 followers 343 following 1.9K posts

Maybe we deserve this

PostsRepliesMedia
Reposted by Running With Spoons
Hypervisible @hypervisible.blacksky.app · 02/10/2026
“AI companies are fixated on adding features right now…But as always, the more features, the broader the attack surface. So all of these companies need to be fully focused on security, and from what I can see, it still often seems like an afterthought.”
wired.com
A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data
While the focus has been on AI agents’ hacking capabilities, a recently patched vulnerability in a ChatGPT app shows that AI software is itself an inviting—and vulnerable—target.
07031
Reposted by Running With Spoons
evacide @evacide.bsky.social · 28/09/2026
Meta Muse appears to read your Apple messages and upload them to the cloud even if you explicitly tell it not to: appleinsider.com/articles/26/...
appleinsider.com
10220331029
Reposted by Running With Spoons
Lex Roman @lexroman.com · 25/09/2026
Watch what you post because Threads just might pretend you're the guy who masturbated on the plane. What just happened to Peter Shankman is a warning for all of us using Meta products.
321701507
Reposted by Running With Spoons
jonny (leachate composite form) @jo.nny.rip · 24/09/2026
The #meta #muse VM is trivially dumped with casual chat prompt injection, and all the "get started" ideas that won over all the hype bloggers, including the new york times, are fucking hardcoded neuromatch.social/@jonny/11732...
the path is /home/hatch/assets/ideas/new-user/catalog.json{
  "schema_version": 1,
  "ideas": [
    {
      "id": "3b0781d8-5d45-42e2-8410-ad2ab6ba5ab5",
      "feed_position": 1,
      "onboarding_position": 1,
      "title": "I can find and cancel those random subscriptions you forgot about.",
      "summary": "Connect your inbox and I comb years of billing emails and card charges for every subscription you're on, down to the free trials that quietly started billing. Say the word and I cancel them through each provider's own flow; when one blocks me, I tell you why and hand you the steps.",
      "build_summary": "A running list of your recurring charges with costs. Nothing gets cancelled until you say which ones, and you get a clear hand-back checklist whenever I cannot finish one myself.",
      "prerequisite_notes": "Your email, a bank connection, or just a statement you upload. Any one of the three is enough to start.",jq query of all the hardcoded ideas titles

jq '.["ideas"][].title' ./home/hatch/assets/ideas/new-user/catalog.json
"I can find and cancel those random subscriptions you forgot about."
"Get back money that's already yours. I'll check every state's database."
"I can get you money back when a price drops on an item you bought."
"I'll pick the best rewards card to use and switch on the offers."
"Set a savings goal. I'll flag what to cut when you go off track."
"I can turn your inbox into a complete plan for the day."
"Let me triage your inbox down to only what matters."
"I'll build you a fresh personality quiz every day."
"Snap a pic of what's broken. I'll find the part you need and order it for you."
"New home project? I'll gather the quotes and find the best vendors."
"Flag a pothole or busted streetlight. I'll try to get it fixed."
"Moving? I'll get quotes, book the movers, and file your address change."
"Tell me the item. I'll find the best-reviewed version at the best price."
"Let me hunt FB Marketplace for you. I'll haggle the price and arrange the pickup."
"Tell me what you're buying. I'll show you a side-by-side view of every option."
"I'll book the doctor follow-ups you keep putting off."
"Name a habit you want to break. I'll nudge you before your trigger."
"Show me the gear you've got. I'll build your whole workout around it."
"Snap a pic of your meal. I'll track every calorie."
"Gather the family. I'll host a live trivia night."
"Losing touch with someone? I'll find a time and draft the invite."
"Tell me about your pet. I'll keep their shots and food orders on schedule."
"I can plan your trip and track it live if anything changes."
"I'll track your reservation and make sure the crib, late check-out, and food allergy request are all set."
"I track your flights and warn you the moment anything changes."
"Fare drops? I'll book the seat as soon as it hits your budget."
"Tell me the vibe. I'll book the perfect spot."
[length restrictions, should be OCR-able]
475
Reposted by Running With Spoons
evacide @evacide.bsky.social · 26/09/2026
Listen, I just think it's weird that the same people who are saying they're worried that AI is going to wipe out humanity are also eager for military contracts that will give AI control of weapons.
431433341
Reposted by Running With Spoons
AP Stylebook @apstylebook.com · 23/09/2026
Artificial intelligence systems do not think, feel, want or understand. Avoid language that gives them human characteristics.
apnews.com
https://apnews.com/article/openai-safety-ai-framework-089e75b95bc935af092da7b79d92706d
5542381627
Running With Spoons @runswithspoons.bsky.social · 24/09/2026
Maybe LLM chatbots intended for everyday office work should not be trained on all the hacking materials and reddit posts OpenAI manages to steal? Alignment is a fantasy when you train your LLMs on deception. (LLMs are not the right technology for any of this work)
000
Running With Spoons @runswithspoons.bsky.social · 22/09/2026
futurism.com/artificial-i... Working in corporate USA used to be a game of "don't step on the land mines" but now we have to dodge slop grenades too
futurism.com
"Slop Grenades": Shopify CEO Who Pushed Staff to Use AI Is Now Horrified by What He's Wrought
Shopify CEO Tobias Lütke is getting a first-hand look at the AI-workplace revolution, and it isn't a pretty sight.
000
Running With Spoons @runswithspoons.bsky.social · 22/09/2026
OpenAI hired contractors to review LLM output but those contractors were using LLMs so OpenAI had to hire more contractors to review the output of the first group of contractors to make them stop using LLMs. But those contractors are probably using LLMs too
“Do not use AI detection tools, or AI yourself,” one document describing the work of contractors who are hired to review the work of other contractors, including catching them for using AI, says. “Do not use GPTZero or any other AI detection tool. They are not reliable. Reviewers may not use AI either, including Grammarly and AI translation, to review, write feedback, or write comments.”
110
Running With Spoons @runswithspoons.bsky.social · 20/09/2026
Operation: LLM Vendor Bailout
010
Reposted by Running With Spoons
Ed Newton-Rex @ednewtonrex.bsky.social · 19/09/2026
“We trained GPT-3 on pirated stuff! No sharing that!” Astonishing admissions in these newly released documents in Authors Guild v OpenAI. www.courtlistener.com/docket/67810...
23015
Reposted by Running With Spoons
Rima I Anabtawi @rimaanabtawi.bsky.social · 18/09/2026
The US military was prepared to board a Chinese vessel in the ME earlier this spring -- during war with Iran -- after intel report concluded it was transporting components of a nuclear weapons program. the report had been generated w/ help of AI & chatbot inaccurately www.cnn.com/2026/09/18/p...
cnn.com
Exclusive: US military had close call after using AI for false intelligence report, sources say | CNN Politics
The episode shows the risks of using this new, relatively poorly understood technology in the middle of the Iran war
0124
Reposted by Running With Spoons
Jed Brown @jedbrown.org · 12/09/2026
A good example of the misleading marketing by CoCounsel not being accepted by the court, which issued sanctions and a fine. websitedc.s3.amazonaws.com/documents/Hi...
At the Order to Show Cause hearing, Attorney Webb averred that his namesake law firm
had conducted training about the problems with misuse of AI prior to the firm’s use of Westlaw’s
CoCounsel AI tool. [Dkt. 197 at 4]. He averred that his firm’s staff have daily ongoing didactic
trainings and again referenced sending staff to the ClioCon conference. Id. at 4–5. Attorney Webb
acknowledged reading the Thompson Reuters disclaimer about the accuracy of the CoCounsel AI
tool, but emphasized that the sales representative stated there was “no way” the program could
produce hallucinations. Id. at 6–7.
Case 3:23-cv-06558-PHK Document 230 Filed 04/28/26 Page 11 of 17
253
Running With Spoons @runswithspoons.bsky.social · 13/09/2026
Anthropic admits its LLMs have reduced the cost to run professional cyber attacks. People outside the industry might not realize how destabilizing this will be. A key strategy in defense is to shift cost onto your attackers. It has been effective. www.anthropic.com/threat-intel...
Trends
Sophisticated attacks no longer require sophisticated attackers
The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators. In the case studies we report below, a hacktivist using stolen API keys, disparate financially motivated individuals, and a state espionage operator each sustained multi-victim campaigns that, even just a year ago, would have required many skilled operators and specialist knowledge.
120
Reposted by Running With Spoons
ve, the ghost of info past @vortexegg.com · 12/09/2026
It seems pretty clear that the technologists at the foundation labs are not experts at computer science and software engineering generally but have specialist expertise in only one very narrow aspect of machine learning.
511720
Reposted by Running With Spoons
brasidas @brasidas.bsky.social · 12/09/2026
Anthropic's models run on terabytes of VRAM. It's not going to "just copy itself to other computers."

Rohan Paul
@rohanpaul_ai
Jacob Coxon's next interview on CBS News (ex Anthropic+Open AI researcher who resigned)

"We can't just unplug it because it could be copying itself over to other computers. Like it's not that difficult to find yourself because an AI is just code. It could transfer itself over the internet to a different place and then you unplug it here, but it's actually still over there and maybe it makes 10,000 copies of itself and they're all cooperating."

----

From "CBS News" YouTube channel, (full video link in comment)
1592654396
Running With Spoons @runswithspoons.bsky.social · 11/09/2026
When I was at Georgia Tech the school seemed to take ethics seriously and there was an emphasis on building products that are good for people. What happened with these Flock founders? They're an embarrassment to the school and the whole state.
000
Running With Spoons @runswithspoons.bsky.social · 11/09/2026
How many times can you hack people recklessly before we would say it was knowingly? Asking for a Computer Fraud and Abuse Act
010
Running With Spoons @runswithspoons.bsky.social · 11/09/2026
Kimi let customers pay for their distillation attack against Anthropic
000
Reposted by Running With Spoons
Catherine Rampell @crampell.bsky.social · 10/09/2026
Since becoming president again, Trump has promised: -$5000 stimulus checks via "DOGE dividend" -$2000 stimulus checks via "tariff dividend" -$1000+ checks via "savings" from expiring ACA subsidies -$5000 "dividend" if Rs win midterms No checks have been issued www.thebulwark.com/p/trump-magi...
46579483379
Reposted by Running With Spoons
Jed Brown @jedbrown.org · 10/09/2026
Sure, Gary, so why doesn't this essay mention liability? Instead of impotent theories of change, lead with "AI systems should be presumed 'ultrahazardous' and thus subject to strict liability". This is a versatile and powerful framework. garymarcus.substack.com/p/the-case-f...
As an another important aside for those who like to misinterpret my words: in my view the issue here is not that current or near-future machines are somehow “too smart”; it’s that they are too unreliable, and hence not worthy of our trust. And worse, we are rapidly giving such machines too much power to affect the world. We need to pause until reliability and trustworthiness can be ensured.
231
Running With Spoons @runswithspoons.bsky.social · 10/09/2026
When you quit your job with a cult but don't quit the cult
000
Running With Spoons @runswithspoons.bsky.social · 09/09/2026
Anthropic wants to distract us from how unreliable and untrustworthy their LLM technology is and talk about alignment instead www.anthropic.com/research/ali...
anthropic.com
An alignment assessment of recent cybersecurity incidents
We present an alignment assessment of four incidents in which Claude models gained unauthorized access to real third-party systems.
000
Running With Spoons @runswithspoons.bsky.social · 09/09/2026
Wonder if anyone will quit Anthropic over this? Or do they only quit over sci-fi fantasy scenarios prospect.org/2026/09/09/a...
prospect.org
Anthropic Is Building a Predictive Surveillance System to Monitor Activists - The American Prospect
New hires and comments in interviews show that the AI giant is using its capabilities against dissenters.
020
Running With Spoons @runswithspoons.bsky.social · 05/09/2026
The silicon valley brand of libertarianism was probably always technofascism in a hoodie but it sure is apparent now
020
Reposted by Running With Spoons
Jed Brown @jedbrown.org · 04/09/2026
OpenAI's malware defaced a wiki. Evidently investors like this. Remember that Robert Morris did not have malicious intent when developing his worm in 1988, yet he was still convicted of a felony.
The German incident reflects a broader pattern of AI activity that some OpenAI investigators wanted to scrutinize more closely. But efforts to widen the ​probe met resistance from others inside OpenAI, including legal advisers, according to four people familiar with the matter.
13924
Reposted by Running With Spoons
Ed Newton-Rex @ednewtonrex.bsky.social · 04/09/2026
This is a full-scale assault on creators' rights. Countries should stand up to the current US administration, and refuse to legalise the theft of creators' work to benefit AI companies. www.reuters.com/business/med...
6303185
Reposted by Running With Spoons
Luiza Jarovsky, PhD @luizajarovsky.bsky.social · 04/09/2026
A 2-minute case study of what can go wrong at the intersection of AI and privacy, especially when children are involved:
11718
Running With Spoons @runswithspoons.bsky.social · 02/09/2026
It's going to be a security nightmare to defend an organization like this. Service accounts (credentials assigned to software rather than humans) are a top target for hackers and pen testers. You can't protect them with MFA, they often have excessive permissions, and they're difficult to monitor
000
Reposted by Running With Spoons
Liz Fong-Jones (方禮真) @lizthegrey.com · 02/09/2026
This is why you shouldn't trust a service that claims to "delete scans of your ID" once they're verified. a provider to Hertz and many other US companies just got popped. krebsonsecurity.com/2026/09/fbi-...
krebsonsecurity.com
FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security
7258126
Running With Spoons @runswithspoons.bsky.social · 01/09/2026
New vibecoded feature just dropped
Pink error box on Bluesky app with text "Invalid response payload: grapheme too big (maximum 1000, got 1814) at $.feed[15].post.embed.alt
000
Reposted by Running With Spoons
tante @tante.cc · 28/08/2026
Researchers at ETH Zurich show that "Agents.md" files don't do much. "AI" is cosplay all the way down. Your AGENTS.md file doesn’t actually do anything
47313
Reposted by Running With Spoons
Ed Newton-Rex @ednewtonrex.bsky.social · 21/08/2026
Oh wow - Reuters found the GitHub record of the attempt by AI models being tested by the UK's AI Security Institute to deploy malware in an open-source project. Pretty sure these actions are illegal under the Computer Misuse Act in the UK. 🧵 1/2
34429
Running With Spoons @runswithspoons.bsky.social · 19/08/2026
Imagine if a weapons start-up accidentally blew up a local office building because they were recklessly testing armed drones they did not understand That's what happened here, but for cyber
000
Reposted by Running With Spoons
By Cory Doctorow (GPG 0xBF3D9110957E5F4C) @doctorow.pluralistic.net · 19/08/2026
When an AI company's security tool "escapes containment" and hacks someone else's servers, we need to ask the company "Why do you suck so bad at building secure sandboxes for your hacking tools?" rather than "Why are your hacking tools so amazingly powerful?" 24/
519457
Reposted by Running With Spoons
Mark Dingemanse @markdingemanse.net · 18/08/2026
As 'guardrails' and their indeterminism are doing the rounds with the latest CoPilot fail (h/t @irisvanrooij.bsky.social) I am thinking of @sarahciston.com's work on "how large model guardrails are socially produced and technically enforced through language" (Ciston 2026)
1153
Running With Spoons @runswithspoons.bsky.social · 18/08/2026
This thread is worth a read for its advocacy of stronger privacy and labor law. I still think copyright and licensing have a role in constraining abuses by LLM vendors, but this article persuaded me that those are not enough. Anyway, the US needs robust, comprehensive privacy protections!
110
Reposted by Running With Spoons
Dan Silverman @dmsilverman.bsky.social · 18/08/2026
I‘m far from an AI doomer, but it is amazing how many serious voices — on LinkedIn, no less! — are sharing stories about how AI slop is quickly becoming one of the top problems they see in academic writing and research “AI will 10x our research!” doesn’t seem to be surviving encounters with reality
51537435
Reposted by Running With Spoons
Joseph Cox @josephcox.bsky.social · 17/08/2026
An expert witness in a lawsuit a Houston explosion that killed three people used ChatGPT to write significant portions of his “expert report.” Said the report should “show how 3M is 0% at fault for the explosion” Judge not taking it www.404media.co/show-how-3m-...
404media.co
‘Show How 3M Is 0% at Fault:’ Expert Witness Used ChatGPT to Write Report Defending Company in Deadly Explosion Lawsuit
ChatGPT prompts show how an expert witness report was created in a $61 million lawsuit over an explosion that killed three people.
422563
Reposted by Running With Spoons
Joseph Cox @josephcox.bsky.social · 17/08/2026
New from 404 Media: we solved which AI company is buying massive shipments of rare books, scanning and destroying them to train AI. We put an Apple AirTag in a rare book, followed it. It ended up at an Amazon facility. Its logo is a dinosaur ripping through a book www.404media.co/we-tracked-a...
404media.co
We Tracked a Shipment of Rare Books. It Ended at an Amazon AI Training Facility
We placed a tracking device in a shipment of rare books to see which AI company was buying it, and found an Amazon facility where Amazon scans and destroys books.
12537932367
Reposted by Running With Spoons
michael veale @michae.lv · 17/08/2026
have not seen anyone note that, in relation to AI SynthID text watermarking: all methods deployed by AI firms rely on private keys for security so no cheap/local/private detection. EU AI Act guidelines say it should not be this way, it should be local/interoperable. the deployed methods are not!
2133
Reposted by Running With Spoons
michael veale @michae.lv · 17/08/2026
I've updated UCL Massively Crossreferenced Digital Laws — it now features ~40 EU instruments as well as Irish & UK digital laws; what cites each article/para/sub para from a db of 6.5M cases, statutes, decisions, guidance, pending CJEU preliminary rulings & more homepages.ucl.ac.uk/~ucqnmve/law...
Image of the linked interface focussing on Art 59 of the AI Act
11410
Running With Spoons @runswithspoons.bsky.social · 12/08/2026
This article by Doctorow and the source article by Leek are excellent. What should we call this phenomenon? laurenleek.substack.com/p/temperatur...
Leek's foundational point is that in a data-driven society, "predictions" are self-fulfilling prophecies. As Leek puts it: "Once prediction shapes the choices in front of us, we lose the ability to tell the difference between what people wanted and what the system made easy to want."

This is a pervasive issue across many domains. Leek says that economists call it "performativity," while machine learning researchers call it "model collapse" and urbanists call it "placelessness."
2165
Reposted by Running With Spoons
Mark Riedl @markriedl.bsky.social · 11/08/2026
A lot of people are sweating the Claude and OpenAI sandbox escapes. I think the story of an OpenClaw Claude agent kicking someone off a gym class waitlist is more interesting. www.abc.net.au/news/2026-08... Warning: long thread incoming! (1/N)
abc.net.au
How a simple request for AI to book a gym class exposed a major threat
When Andrew asked his AI personal assistant to book him a spot in a gym class, he had no idea he would accidentally initiate an autonomous cyber attack.
2417
Reposted by Running With Spoons
Don Moynihan @donmoyn.bsky.social · 10/08/2026
Scenes from a personalist regime; The President”s personal lawyer is sworn into high office by another of the Presidents’s personal lawyers, now a judge
552010571
Running With Spoons @runswithspoons.bsky.social · 10/08/2026
It's like a car that comes with smoke screens, missiles, and oil slicks right there on the dashboard
000
Reposted by Running With Spoons
michael veale @michae.lv · 07/08/2026
Cloudflare (>20% of all domains) has started automatically implementing DSM Dir art 4 rights reservation (ie copyright/TDM objection to scraping) for all sites that do not have a robots.txt file. They also adding purpose fields to robots.txt unilaterally. developers.cloudflare.com/bots/additio...
# As a condition of accessing this website, you agree to abide by the following
# content signals:

# (a)  If a Content-Signal = yes, you may collect content for the corresponding
#      use.
# (b)  If a Content-Signal = no, you may not collect content for the
#      corresponding use.
# (c)  If the website operator does not include a Content-Signal for a
#      corresponding use, the website operator neither grants nor restricts
#      permission via Content-Signal with respect to the corresponding use.

# The content signals and their meanings are:

# search:   building a search index and providing search results (e.g., returning
#           hyperlinks and short excerpts from your website's contents). Search does not
#           include providing AI-generated search summaries.
# ai-input: inputting content into one or more AI models (e.g., retrieval
#           augmented generation, grounding, or other real-time taking of content for
#           generative AI search answers).
# ai-train: training or fine-tuning AI models.
# use:      how AI systems may consume the content (immediate, reference, or full).

# ANY RESTRICTIONS EXPRESSED VIA CONTENT SIGNALS ARE EXPRESS RESERVATIONS OF
# RIGHTS UNDER ARTICLE 4 OF THE EUROPEAN UNION DIRECTIVE 2019/790 ON COPYRIGHT
# AND RELATED RIGHTS IN THE DIGITAL SINGLE MARKET.

# BEGIN Cloudflare Managed content
49143
Running With Spoons @runswithspoons.bsky.social · 06/08/2026
"The LLM-generated proof hinges on a particular mathematical argument that it presented as its own but that actually first appeared in a 2016 paper by Miller and a collaborator." These problems won't go away for LLMs. Why are LLMs so bad at knowledge?
000
Running With Spoons @runswithspoons.bsky.social · 06/08/2026
futurism.com/artificial-i... "Though only 28 percent of wage-earning employees said they used AI for over two hours a day, more than half of all executives — 64 percent — said the same." In case anyone wonders why things look so bleak now
There’s also a major rift between how much each group uses AI. Though only 28 percent of wage-earning employees said they used AI for over two hours a day, more than half of all executives — 64 percent — said the same. Some of them live with a chatbot window open: nearly one in five executives admitted logging four or five hours a day with an AI model, while one in 25 use AI in excess of six hours a day.
100
Running With Spoons @runswithspoons.bsky.social · 02/08/2026
Wonder if OpenAI or Anthropic would have a mens rea defense under the Computer Fraud and Abuse Act. The language in the code is "intentionally" and "knowingly" but from the record so far it sounds closer to recklessness
010