logoalt Hacker News

anthonyskipperyesterday at 10:30 PM7 repliesview on HN

The scariest part of the interaction is the first video at https://x.ai/bot where the bot just snags your creds from the browser and takes over. So many people are going to give x all their data and creds.


Replies

roughlytoday at 6:10 AM

The world ends not with a bang, but with a “you’re right, I shouldn’t have done that. It’s right there in my agents.md file.”

miguelspizzatoday at 7:07 AM

AI Session Hijacking is such a dead end and I think this will be the thing that kills it. Just register these things in the IDP and let them sign into their own accounts.

Maybe if we give these things their own identity people will stop letting their AIs post as them in linkedin

show 2 replies
kylecazaryesterday at 11:27 PM

I assume they store your session state/token for whatever SaaS it needs to work with but not the creds.

show 1 reply
xyzsparetimexyztoday at 9:33 AM

it's crazy that we have multi-user computers and all this permission stuff on linux and none of it is used

edoceoyesterday at 11:16 PM

What? How? Just the x.com creds or other ones too?

nozzlegeartoday at 3:24 AM

Well, it's the "Everything App" after all!

/s

walrus01yesterday at 11:35 PM

[flagged]