11 ms·
The scariest part of the interaction is the first video at https://x.ai/bot https://x.ai/bot where the bot just snags your creds from the browser and takes over
by anthonyskipper 1mo ago
The scariest part of the interaction is the first video at https://x.ai/bot https://x.ai/bot where the bot just snags your creds from the browser and takes over. So many people are going to give x all their data and creds.
- edoceo 1mo agoWhat? How? Just the x.com creds or other ones too?
- kylecazar 1mo agoI assume they store your session state/token for whatever SaaS it needs to work with but not the creds.
- bakies 1mo agoMany people assumed they didnt upload your whole home dir when you launched their IDE
- solid_fuel 1mo agoYeah, assuming that X is doing the honest and well-behaved thing is a mistake given their past actions.
- walrus01 1mo ago[flagged]
- nozzlegear 1mo agoWell, it's the "Everything App" after all! /s
- roughly 1mo agoThe world ends not with a bang, but with a “you’re right, I shouldn’t have done that. It’s right there in my agents.md file.”
- miguelspizza 1mo agoAI Session Hijacking is such a dead end and I think this will be the thing that kills it. Just register these things in the IDP and let them sign into their own accounts. Maybe if we give these things their own identity people will stop letting their AIs post as them in linkedin
- 0x3f 1mo ago> Just register these things in the IDP and let them sign into their own accounts. And when you get blocked by whatever anti-bot tech the site is running?
- miguelspizza 1mo agoNot sure I understand the point your are making. how is this unique for bots with their own identity? Bots hijacking a user session can also be blocked
- ACCount37 1mo agoBots skinwalking their users inherit the behavioral scoring of that user. As a rule, they'll take a lot longer to get blocked than new bot accounts would.
- ares623 1mo agoBut then whoever added them to the IDP becomes accountable for what the bots do. By hijacking a real person's credentials, that person becomes the accountability sink. Very neat. Very deliberate.
- xyzsparetimexyz 1mo agoit's crazy that we have multi-user computers and all this permission stuff on linux and none of it is used