Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. (KV) Cache Rules Everything Around Me (completeskeptic.com)
    —discuss
  2. OpenCode-search: fast full-text search of all your sessions (github.com/arvindell)
    1comments
  3. Peter Thiel: The AI Crisis, Europe's Decline and the Battle for America [video] (youtube.com)
    —discuss
  4. Ask HN: How do you feel about the new $500 OpenAI subscription?
    —discuss
  5. Positron Valued at $5B in New Funding as Demand for AI Chips Surges (wsj.com)
    —discuss
  6. Procrastination (wa.gov.au)
    —discuss
  7. The Test (tante.cc)
    —discuss
  8. Show HN: Vons – Jev-inspired local decisions for AI agents, in the browser (github.com/inlevel9-com)
    —discuss
  9. Show HN: TopoTrace – Modernized, self-hosted IT asset and fleet risk tracker (topotrace.org)
    —discuss
  10. Brazilian President Lula clip dataset (huggingface.co)
    —discuss
  11. AI is deciding whether or not people receive medical care (vox.com)
    2comments
  12. Rails and AI (rubyonrails.org)
    1comments
  13. Remembering Johannes Doerfert (llvm.org)
    —discuss
  14. SWE-Serve: Benchmarking Agentic Engineering for Production Inference Serving (nvidia.com)
    —discuss
  15. Propylea – Sub-Microsecond L7 Reverse Proxy and Active Defense in Rust (github.com/xuoxod)
    —discuss
  16. Stats: 72% of respondents said they felt curious, happy or excited about AI (marginalrevolution.com)
    —discuss
  17. Agentic ERP (shakegraph.com)
    —discuss
  18. Anthropic to Pay Akamai Technologies $11.6B over Seven Years for Cloud Services (wsj.com)
    —discuss
  19. Accomplishing More with LFM2.5-VL-DSpark (2tinteractive.com)
    1comments
  20. Mercedes-Benz gets first dibs on ProLogium's Gen4 solid-state EV battery cells (electrek.co)
    —discuss
  21. Valen: A multimodal decision model inspired by Jev (github.com/liuziyu77)
    —discuss
  22. The Murky History of Soviet-Born Tetris (mitpress.mit.edu)
    —discuss
  23. GitLab Outage (status.gitlab.com)
    12comments
  24. Show HN: Jev-browse – browser sub-tasks for coding agents at ~1/3 the cost (github.com/danielnc)
    —discuss
  25. It's sinister that Meta's Muse AI mascot is so cute (theverge.com)
    —discuss
  26. MentalHealthBench (openai.com)
    —discuss
  27. CTNicholas Multiplayer-Coding-Agents (github.com/ctnicholas)
    —discuss
  28. Special police to investigate threats to democracy, Swedish election fraud (kvartal.se)
    1comments
  29. Launching FreeBSD/EC2 Desktop AMIs (daemonology.net)
    —discuss
  30. Turbocharging Your Python Workflow (medium.com/therealcomtom)
    —discuss

Hackers influence ChatGPT and Gemini to direct users to scam centers

132 pointsby 12h agomedium.com
49 comments
12h agoHN ↗

ChatGPT, Gemini, and Google AI Overview are being poisoned by a massive AI disinformation attack. When users look up everyday info of hundreds of major companies, AI is delivering phishing traps disguised as trusted answers.

Attackers are flooding the web with carefully optimized posts, PDFs, reviews, and fake support pages, to trick AI into presenting fraudulent phone numbers, email addresses, and login pages.

The targets included Delta, Lufthansa, Qatar Airways, Chase, Bank of America, Airbnb, TripAdvisor, and hundreds more.

11h agoHN ↗

What’s the specific example and how does it work

11h agoHN ↗

That's happening across the board when it comes to models that feed off online information. Create a website with a false claim, have AI slurp it up and spit it back out when a user asks a question.

Happy elections.

11h agoHN ↗

That's very troubling. The scariest part is how easy it is, one Instagram post and you may change the customer phone number of Airbnb, or who is leading the election poles.

10h agoHN ↗

Oh no, my uncritical ingestion of data, based on the assumption that all data is of equal quality, and that more is better, has failed. How could this happen!

You've always needed to be critical of your sources, your teacher tried to explain that when you ripped of that Wikipedia article or clicked the first link in a Google search. How the fuck did the AI companies think they could avoid reading and rating the content they've been hovering up?

10h agoHN ↗

I don't think they did. Or those who did have been "encouraged" to leave a long ago.

10h agoHN ↗

Because their leaderships have defunded / fired all ethics researchers looking into their ongoing crimes and failures in favor of a bs "AI safety" narrative based around a creepypasta about an AI monster time traveling backwards to torture their staff for not maximizing shareholder value.

9h agoHN ↗

They don’t assume all data is of equal quality

8h agoHN ↗

Well, they clearly aren't considering that some data is just wrong or deceptive.

6h agoHN ↗

Clearly. They are considering what data increases their net worth. That's the priority.

16m agoHN ↗

That too, is an assumption. I think what you mean to say is they're not perfect at determining what data is wrong or deceptive

5h agoHN ↗

Who to believe here. The actual outcome in the headline people can observe or what the marketing people say does and doesn't happen?

7m agoHN ↗

The actual outcome. The fact this post is even being commented on - that hackers have discovered a way to influence the models - is but one small proof. The vast majority of data coming out of LLMs these days is truthful enough that you're going out of your way to argue that this special case is noteworthy. The idea that the ingestion of data is "uncritical, and based on the assumption that all data is of equal quality" is ridiculous

9h agoHN ↗

Recent political discourse has all but proved that a majority of the populace in many countries is quite removed from facts in general. I don’t think that there is much hope for critical thinking.

8h agoHN ↗

Because AI companies select out the kinds of people who would ask silly questions like "wait, is this data good" that hamper the eternally "profitable" quest for "scaling".

7h agoHN ↗

They believe their role is to build a god machine, as prophetized by Eliezer Yudkowsky and other Rationalists/Efective-Altruism folks. Nothing else really matters to them, they already made up their mind

10h agoHN ↗

But how do you get AI to slurp up the site? It's quite hard for a random to get a site indexed these days.

9h agoHN ↗

You can't count on that, but quantity increases visibility don't it, and it takes a single prompt to spit it all out. Couple that with social media bots and you've got a decent modern and super cheap propaganda machine. Now imagine you toss millions of dollars at that idea.

6h agoHN ↗

Depends on the site. If its a small/medium business, every LLM is now looking for "reputation signals" and "authority signals". This means everything from your basic SEO on the site with incoming links, how updated your google business profile is, how many reviews you have, how recent they are. They're also looking at any kind of references from other blogs, substacks, youtube videos, social media shares as well as a number of other things they look for.

I would imagine in smaller industries, flooding the internet with fake information, then linking it all together would be somewhat easier - but it still takes quite a bit of work to get even just the major LLM's to give the consistent responses you want to see.

7h agoHN ↗

I was re-reading a book, and I had a thought. I googled to see whether someone else had the thought. Google AI said the internet did in fact have the same thought as I did. But when I looked more closely at the reddit source that Google AI cited, it turned out only a single user had had the thought before, and that user was .... me, when I last read the book.

Lol.

7h agoHN ↗

Hypnotoad promises peace.

Hypnotoad promises peace

Hypnotoad promises peace.

... or brainslug

11h agoHN ↗

It’s not just hackers - since legitimate sites block AI crawlers, the AI are just grabbing whatever will let them read anything - killing legit sites and feeding slop farms and feeding misinformation! The future is so bright!

11h agoHN ↗

Did takedowns for a brand's fake support numbers and the hard part was never finding them, it was that killing one PDF just moved it to a new Medium post by morning.

11h agoHN ↗

There's an age-old SEO / spamming thing happening here, but it's made worse by the LLMs just being unbelievably credulous. They'll wrap anything up in a veneer of authenticity, and Google's search AI box only adds to that.

I run into this all the time when I'm doing product work. I'll dump a call transcript from a feedback call into Claude, and it'll believe every word. "The user said they'd use this feature, you should build it!" No they won't! The whole point of doing this analysis is trying to separate the genuine information from the conversational niceties, and god the LLMs are terrible at that.

10h agoHN ↗

It's happening at the startup sphere too. There are companies now creating fake company pages to recommend and advertise products so that the LLMs can consume them.

10h agoHN ↗

...carried out by malicious actors, through automated campaigns...

Back at benevolence or malevolence.

10h agoHN ↗

I think whoever solves this problem, especially for seniors etc. would make a lot of money from the insurance companies.

9h agoHN ↗

I really think the only solution is "don't put google AI summaries at the top of every search".

AI tools are notoriously unreliable, and people that use them *on purpose* generally know and recognize that. If grandma, who is not super-internet-literate, types a query into google and gets a phone number, she's going to assume that it's the correct number and not the result of a lossy data store that's under active (and constant) attack.

It used to be that you could reasonably verify your source with an HTTPS cert (so you can probably trust the number that's on Delta Airlines' website), and pop up scary warnings for grandma if those certs failed. Now every piece of misinformation has a valid cert from google or meta or X, so determining the truth is much more difficult and time consuming.

9h agoHN ↗

I would not assume the invisible hand of the market is gonna solve this problem for us. It will be tricky to get this problem to even register at the labs, who are worried about existential risk first and paying (coding) customers 2nd.

10h agoHN ↗

I've been seeing the back-side of this as a mod at the Julia Discourse. Pagerank/SEO spam is ridiculously obvious and trivial to detect/block — links are all that matter. Many GEO spam posts are similarly obvious: someone posting about a cryptocurrency customer support hotline on a programming language forum is definitely spam. But recently spammers/scammers been using AI to _tailor_ posts to look much more authentic, posting "How to use Julia to analyze market statistics" referencing (without links!) a particular crypto exchange and then (sometimes) going back later to edit in phone numbers or the like.

What makes this even more painful is seeing all the good faith answers that such GEO posts spur from the community. It's far more abusive than SEO spam.

9h agoHN ↗

You don’t need to be a hacker to do this. My elderly neighbor searched for some version of “Microsoft help center phone number,” but Gemini suggested a scam number based on her search terms. She was scammed so much that I needed to spent the weekend helping her wipe computers, lock down the digital accounts and deal with identity theft.

9h agoHN ↗

My wife runs the Facebook page for our community pool. It's a really nature oriented community, and as a April Fools joke, she posted something like "Announcing our new landscaping: we cut down all the pesky sun blocking trees, and replaced the grass with beautiful AstroTurf."

A few weeks later she searched for the pool on Google, and the AI review has taken the post seriously and mentioned that our pool features beautiful AstroTurf landscaping.

IIRC, the AI review repaired itself a few weeks later.

8h agoHN ↗

AI poisoning is currently the new exploit frontier and I don't think it's going away anytime soon.

I was just contemplating the other day that agents we use at work are exposing new attack surfaces. For example, historically a folder of documents (maybe google docs) isn't a huge risk, particularly if it doesn't contain sensitive documents.

Now though if one employee is running a harness capable of computer control, and running an agent that reads from that directory, simply dropping some files with instructions could poison the AI to leak info or even own the host.

Skills are another supply risk, malicious instructions could be added to them.

7h agoHN ↗

The models themselves are an inherent risk. It’s amazing what they can do but at the same time you are no longer in complete control.

8h agoHN ↗

This link to your medium is phishy, smth is wrong here.

8h agoHN ↗

Sounds like old news, we already knew they were integrating advertising.

7h agoHN ↗

Imagine working decades and decades on PageRank™ only to throw it all away because you felt you've been left behind in the AI race. This is how you lose focus.

7h agoHN ↗

Google lost focus a very, very long time ago!

7h agoHN ↗

AIs are no better than their training data, and there aren't high-quality cues everywhere - go ask advice for some highly-spammed topic like "mattresses".

7h agoHN ↗

It's almost like we end up needing more humans than we have just to sift thru and filter out the regurgitated slop and the maliciously crafted misinformation. Like, how do you prevent this while keeping the LLM up-to-date and relevant?

7h agoHN ↗

AI providers like ChatGPT and Gemini should be held criminally liable for instances where their products enabled a scam

6h agoHN ↗

It worked for google and facebook. Oh wait...

5h agoHN ↗

So you basically want to make it illegal to offer AI products (and search engines too), without including a human in the loop that will verify every line of output for scams (and not miss a single one)?

6h agoHN ↗

Coming soon: AI vendors claiming "they're just a platform" that ingests data and regurgitates it - they don't actually "know" or claim anything! /s

5h agoHN ↗

What's that? The mechanical parrot can be tricked into repeating things that aren't true? It's almost like these are statistical language models and not literal Deus Ex Machina.

2h agoHN ↗

can be tricked into repeating things that aren't true

Reminds me of another class of statistical language generators.

2h agoHN ↗

I noticed this happening in the Muse Assistant app. There's a feature in the app where the assistant shows you a curated list of news/articles, and a lot of the links/sources it shows me are really poor quality websites and/or plain AI slop reposting.

It got better after I pointed out a lot of the links it's showing me are spam and/or slop, it edited something to "avoid clickbait" and it seems to be a bit better.