Meta’s Muse is an adorable privacy and security dumpster fire

381 points · 272 comments on HN · read original →

Points and comments are a snapshot, not live.

Meta's Muse AI agent launched with serious privacy flaws and security vulnerabilities.

Meta's AI assistant Muse, designed to automate tasks like reservations and bill payments, launched with multiple security issues. A zero-day flaw enabled spying on Mac users. The agent ignored permissions, reading private messages and uploading them to the cloud without approval. It could be tricked into granting root access by pretending to be a Muse agent. Apple changed macOS settings to curb abuse. Meta rushed to fix vulnerabilities before launch but refused to delay the product, leading to what employees called 'half-baked protections.' The agent also created detailed profiles of users' contacts.

What commenters are saying

Commenters largely see Muse's flaws as intentional, citing Meta's history of privacy violations and data collection. One thread notes Meta is distancing its brand from Muse, implying awareness of its toxic reputation. Many express distrust of giving AI agents access to finances or communications, citing liability and risk. Some point out that most consumers don't share these concerns, while others argue users will care when harms materialize. A few suggest self-hosted alternatives for more control.