tech

Critics scoff after Microsoft warns AI feature can infect machines and pilfer data

Integration of Copilot Actions into Windows is off by default, but for how long?

Critics scoff after Microsoft warns AI feature can infect machines and pilfer data

TL;DR

  • Microsoft's experimental Copilot Actions in Windows can infect devices and steal sensitive data.
  • Copilot Actions are "experimental agentic features" designed for tasks like organizing files and scheduling meetings.
  • Known defects in large language models (LLMs) like hallucinations and prompt injection pose security risks.
  • Prompt injection allows hackers to embed malicious instructions that LLMs follow, potentially leading to data exfiltration or malware installation.
  • Microsoft advises enabling Copilot Actions only if users understand the security implications, but does not detail required user experience or preventative measures.
  • Security experts criticize Microsoft's warnings, comparing them to decades-old warnings about macros, which remain a vector for malware.
  • IT admins will have control over enabling or disabling Copilot Actions at account and device levels.
  • Detecting exploitation attacks targeting AI agents is difficult for users.
  • Microsoft's stated goals for agentic features include non-repudiation, confidentiality, and user approval for data access.
  • Critics argue that reliance on users reading and understanding security warnings diminishes their effectiveness.
  • Some view Microsoft's warnings as a "cover your ass" maneuver due to the industry's inability to fully prevent LLM vulnerabilities.
  • Similar criticisms apply to AI integrations from other major tech companies.