Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Show HN: Local First AI Calculator(clor.app)
    discuss
  2. Jev Against a Cross-Encoder(getunblocked.com)
    discuss
  3. Paperclip: Open-source orchestration for teams of AI agents(github.com/paperclipai)
    discuss
  4. Websites that read in the terminal: the TermWeb standard(andros.dev)
    discuss
  5. Healthy Feedback(martinfowler.com)
    discuss
  6. Towards a future space-based, highly scalable AI infrastructure system design(arxiv.org)
    discuss
  7. 5G Live Streaming: Benefits, Challenges, and How It Works(red5.net)
    discuss
  8. CIA warns Russia preparing attacks on Spain, France, Italy with drones from sea(independent.co.uk)
    discuss
  9. "Not Conio but Compatible" for Amiga VBCC(retrogamecoders.com)
    discuss
  10. Show HN: CraftCX – Observability and intelligence tooling for AI Support team(craftcx.com)
    discuss
  11. DHH at Rails World – Ruby on Rails no longer needed now because AI can make apps(twitter.com/_architected)
    discuss
  12. AI companies don't bribe reporters. They fund fellowships(drjoshcsimmons.com)
    discuss
  13. Human labour is largely invisible to AI(fohlen.dev)
    discuss
  14. Pixel Joint(pixeljoint.com)
    discuss
  15. The Academy for unusually ambitious young people(theacademysf.com)
    discuss
  16. Show HN: Jev-phone – driving iOS and Android apps with jev(github.com/rajmeet)
    discuss
  17. Adventures in using AI to write papers(andrewpwheeler.com)
    discuss
  18. Modern Motherfucking Website(dreamstation.systems)
    discuss
  19. Local JEV, fine tuned in < 30 mins on Mac Air(shmcsensei.github.io)
    discuss
  20. Elizabeth Holmes scheduled to move to halfway house in August 2027(abcnews.com)
    discuss
  21. Unlike many parents, children are fearless around AI(uc.edu)
    discuss
  22. Polling has become a playground for grifters, liars, and frauds(theargumentmag.com)
    discuss
  23. Make Videos Programmatically with React(github.com/remotion-dev)
    discuss
  24. Disney+ and Hulu raise prices by up to 13 percent after doubling profits(arstechnica.com)
    1comments
  25. The Year AI Came for Us: Teaching Entrepreneurship Will Never Be the Same(steveblank.com)
    discuss
  26. What Australia's Hidden Caves Can Teach Us About Martian Terrain(nautil.us)
    discuss
  27. Show HN: Are My ETFs Overvalued?(etf-copilot.com)
    discuss
  28. Mel: A Real Programmer(melsloop.com)
    discuss
  29. Air – nightly discovery scores for 1,800 US small-caps, with a paper trail(aistockradars.com)
    discuss
  30. Show HN: Learn SQL free with no tracking or ads(sql-easy.com)
    discuss

Hackers influence ChatGPT and Gemini to direct users to scam centers

75 pointsby 3h agomedium.com
23 comments
3h agoHN ↗

ChatGPT, Gemini, and Google AI Overview are being poisoned by a massive AI disinformation attack. When users look up everyday info of hundreds of major companies, AI is delivering phishing traps disguised as trusted answers.

Attackers are flooding the web with carefully optimized posts, PDFs, reviews, and fake support pages, to trick AI into presenting fraudulent phone numbers, email addresses, and login pages.

The targets included Delta, Lufthansa, Qatar Airways, Chase, Bank of America, Airbnb, TripAdvisor, and hundreds more.

2h agoHN ↗

What’s the specific example and how does it work

3h agoHN ↗

That's happening across the board when it comes to models that feed off online information. Create a website with a false claim, have AI slurp it up and spit it back out when a user asks a question.

Happy elections.

2h agoHN ↗

That's very troubling. The scariest part is how easy it is, one Instagram post and you may change the customer phone number of Airbnb, or who is leading the election poles.

2h agoHN ↗

Oh no, my uncritical ingestion of data, based on the assumption that all data is of equal quality, and that more is better, has failed. How could this happen!

You've always needed to be critical of your sources, your teacher tried to explain that when you ripped of that Wikipedia article or clicked the first link in a Google search. How the fuck did the AI companies think they could avoid reading and rating the content they've been hovering up?

1h agoHN ↗

I don't think they did. Or those who did have been "encouraged" to leave a long ago.

1h agoHN ↗

Because their leaderships have defunded / fired all ethics researchers looking into their ongoing crimes and failures in favor of a bs "AI safety" narrative based around a creepypasta about an AI monster time traveling backwards to torture their staff for not maximizing shareholder value.

58m agoHN ↗

They don’t assume all data is of equal quality

29m agoHN ↗

Recent political discourse has all but proved that a majority of the populace in many countries is quite removed from facts in general. I don’t think that there is much hope for critical thinking.

3m agoHN ↗

Because AI companies select out the kinds of people who would ask silly questions like "wait, is this data good" that hamper the eternally "profitable" quest for "scaling".

1h agoHN ↗

But how do you get AI to slurp up the site? It's quite hard for a random to get a site indexed these days.

1h agoHN ↗

You can't count on that, but quantity increases visibility don't it, and it takes a single prompt to spit it all out. Couple that with social media bots and you've got a decent modern and super cheap propaganda machine. Now imagine you toss millions of dollars at that idea.

2h agoHN ↗

It’s not just hackers - since legitimate sites block AI crawlers, the AI are just grabbing whatever will let them read anything - killing legit sites and feeding slop farms and feeding misinformation! The future is so bright!

2h agoHN ↗

Did takedowns for a brand's fake support numbers and the hard part was never finding them, it was that killing one PDF just moved it to a new Medium post by morning.

2h agoHN ↗

There's an age-old SEO / spamming thing happening here, but it's made worse by the LLMs just being unbelievably credulous. They'll wrap anything up in a veneer of authenticity, and Google's search AI box only adds to that.

I run into this all the time when I'm doing product work. I'll dump a call transcript from a feedback call into Claude, and it'll believe every word. "The user said they'd use this feature, you should build it!" No they won't! The whole point of doing this analysis is trying to separate the genuine information from the conversational niceties, and god the LLMs are terrible at that.

2h agoHN ↗

It's happening at the startup sphere too. There are companies now creating fake company pages to recommend and advertise products so that the LLMs can consume them.

1h agoHN ↗

...carried out by malicious actors, through automated campaigns...

Back at benevolence or malevolence.

1h agoHN ↗

I think whoever solves this problem, especially for seniors etc. would make a lot of money from the insurance companies.

1h agoHN ↗

I really think the only solution is "don't put google AI summaries at the top of every search".

AI tools are notoriously unreliable, and people that use them *on purpose* generally know and recognize that. If grandma, who is not super-internet-literate, types a query into google and gets a phone number, she's going to assume that it's the correct number and not the result of a lossy data store that's under active (and constant) attack.

It used to be that you could reasonably verify your source with an HTTPS cert (so you can probably trust the number that's on Delta Airlines' website), and pop up scary warnings for grandma if those certs failed. Now every piece of misinformation has a valid cert from google or meta or X, so determining the truth is much more difficult and time consuming.

20m agoHN ↗

I would not assume the invisible hand of the market is gonna solve this problem for us. It will be tricky to get this problem to even register at the labs, who are worried about existential risk first and paying (coding) customers 2nd.

1h agoHN ↗

I've been seeing the back-side of this as a mod at the Julia Discourse. Pagerank/SEO spam is ridiculously obvious and trivial to detect/block — links are all that matter. Many GEO spam posts are similarly obvious: someone posting about a cryptocurrency customer support hotline on a programming language forum is definitely spam. But recently spammers/scammers been using AI to _tailor_ posts to look much more authentic, posting "How to use Julia to analyze market statistics" referencing (without links!) a particular crypto exchange and then (sometimes) going back later to edit in phone numbers or the like.

What makes this even more painful is seeing all the good faith answers that such GEO posts spur from the community. It's far more abusive than SEO spam.

30m agoHN ↗

You don’t need to be a hacker to do this. My elderly neighbor searched for some version of “Microsoft help center phone number,” but Gemini suggested a scam number based on her search terms. She was scammed so much that I needed to spent the weekend helping her wipe computers, lock down the digital accounts and deal with identity theft.

23m agoHN ↗

My wife runs the Facebook page for our community pool. It's a really nature oriented community, and as a April Fools joke, she posted something like "Announcing our new landscaping: we cut down all the pesky sun blocking trees, and replaced the grass with beautiful AstroTurf."

A few weeks later she searched for the pool on Google, and the AI review has taken the post seriously and mentioned that our pool features beautiful AstroTurf landscaping.

IIRC, the AI review repaired itself a few weeks later.