[HN Gopher] Bing Chat responses infiltrated by ads pushing malware
       ___________________________________________________________________
        
       Bing Chat responses infiltrated by ads pushing malware
        
       Author : pixiemaster
       Score  : 104 points
       Date   : 2023-09-28 19:28 UTC (3 hours ago)
        
 (HTM) web link (www.bleepingcomputer.com)
 (TXT) w3m dump (www.bleepingcomputer.com)
        
       | bilekas wrote:
       | I don't know for sure but if true, it's seems that fake ad
       | posters can't specifically say yes/no to being used on bing
       | results.
       | 
       | So in a funny way the AI is bringing easier access to the malware
       | sites than a traditional search engine would. I'm sure the
       | cretins are delighted with Microsoft right now. For the given
       | test question, the first answer in any search engine would have
       | been the official site.
        
       | araes wrote:
       | How many of these can be bundled into an automated install that
       | occurs without the user doing much of anything, or requiring only
       | a single click on an ad that looks reasonable? Can I have the
       | chatbot simply download the installer as part of the response?
       | "By implicitly clicking the 'provide response', you've agreed to
       | this download. Surprise!"
       | 
       | Access Controller or Modifier, Automated Downloader,
       | Communication Modifier or "man-in-the-middle", Email or Msg
       | Spoofer, Software Backdoor, Rootkit / Bootkit, Website or Browser
       | Redirector, Activity Monitor, Data Scraper, Duplicator,
       | Eavesdropper, Exit Node Logger, Keylogger, Locator, Path Tracer,
       | Sniffer, Snooper, Bricker, Fork Bomb, Logic Bomb, Time Bomb,
       | Adware, Browser "Helper", Crimeware, Cryptojacker, Malware
       | (generic), Ransomware, Scareware, Spyware
       | 
       | Links to the Wiki articles on each topic are at:
       | https://en.wikipedia.org/wiki/User:Araesmojo/Computer_Securi...
       | 
       | Ignore the rest unless you want to read about Shadowrun /
       | Neuromancer / Ghost in the Shell speculation.
        
       | svaha1728 wrote:
       | It's fairly obvious Microsoft is ahead of its skis trying to lock
       | down the new market. I'm glad they aren't building self-driving
       | cars yet.
       | 
       | At this point I'm guessing anything in Azure Repos or private
       | Github repositories are just a small oopsie away from being
       | leaked by some accidental training mistake or misconfigured
       | token.
        
         | 88913527 wrote:
         | Seems like corporations are jumping straight to extinction,
         | bypassing the embracing and extending. You have to at least
         | make something people want to use before pulling up the
         | drawbridge.
        
       | cmgriffing wrote:
       | Irony Alert: The bleeping computer website consumes 700MB+ RAM on
       | the page of an article that talks about malicious ads.
       | 
       | https://twitter.com/cmgriffing/status/1707511082947158445
        
       | AraceliHarker wrote:
       | The irony of Windows 11, which is marketed as a secure operating
       | system, is that it is riddled with links to Bing that are
       | infested with scam ads.
        
         | TeMPOraL wrote:
         | We're talking about a farmer advertising to chickens that their
         | hen house is safe from foxes. True as it may be, you'll still
         | there to produce value for the farmer and finally end up in a
         | soup.
        
       | roody15 wrote:
       | Bing Chat is just terrible. It tries to merge neutered ChatGPT
       | with promoted web content. It's really too bad as Microsoft had
       | an opportunity here to leverage this into something great.
       | Instead they are like how can we control the output.. simplify
       | the responses and make money pushing people to certain sites and
       | services.
        
       | bastard_op wrote:
       | Gee, after watching internet explorer 1-6 and beyond, I never saw
       | that coming.
        
       | ToucanLoucan wrote:
       | I really do not understand the benefits supposedly of this tech
       | over a traditional search engine. All it's doing is pulling the
       | top hit from Bing and saying it back to you in a chat format. The
       | AI doesn't understand what IP Scanning software is, nor does it
       | understand malware, nor does it understand anything about what
       | you're saying, it literally just doesn't. It takes what you
       | asked, stuffs it into bing, and reads out the results to you.
       | 
       | I understand why people want AI search engines, the problem is,
       | this is not an AI search engine. None of them are to my
       | knowledge. It's just an ML bot mediating a search between you and
       | the engine. The web page accomplishes the exact same task,
       | without the unearned air of authority.
       | 
       | Like, the IDEA of an AI search engine, an artificial intelligence
       | that knows all this stuff and can weigh in alongside you with
       | insight and comprehension, that's _incredibly cool._ But this is
       | not that. ChatGPT _knows much_ but _understands nothing._
        
         | fragmede wrote:
         | If I already know the name of what I'm looking for, a
         | traditional search engine is great. But if I'm in unfamiliar
         | territory; say I'm a programmer and not an accountant, how long
         | would I need to search in a traditional engine to find the
         | magic word ERP?
        
         | collaborative wrote:
         | Neither Google nor MS will ever get AI search right because the
         | only applicable use of AI in a search engine is to remove the
         | seo/junk/ads/clickbait and give the user what he is looking
         | for. This goes against their core business (ads)
         | 
         | Engines like you.com, phind.com, aisearch.vip, or kagi have the
         | advantage because their business model doesn't depend on this
        
         | fragmede wrote:
         | What would you consider proof of understanding?
         | 
         | What question could we ask that would convince you that a
         | hypothetical future system actually understands what it's
         | spitting out, regardless of if it were based on current LLM
         | technology or not?
        
           | Barrin92 wrote:
           | >What would you consider proof of understanding?
           | 
           | In the search engine/chatbot context pretty straight forward,
           | having the capacity to automatically correct obviously
           | illogical or non/counter factual info.
           | 
           | Say I do a historical search and bing or chatgpt hallucinate
           | something that's wildly implausible or straight up makes no
           | sense. If it could spot that _on its own_ and say.  "I'll
           | consult some credible sources specifically to resolve that,
           | as what I have found doesn't check out" and then comes up
           | with something that's congruent, that'd show understanding.
           | 
           | Same with code. Understanding code would imply something like
           | being able to run a code snippet through a debugger,
           | interpret the meaning of the error message, and fixing what's
           | broken. Right now these things give you nothing more but a
           | stochastic guess.
           | 
           | This is not a philosophical argument about what it "means" to
           | understand btw, just real limitations. Right now it is always
           | the user who has to supplement the understanding and coax
           | these systems into fixing any mistake they make.
        
         | mcpackieh wrote:
         | > _this is not an AI search engine. [...] It 's just an ML bot
         | mediating a search between you and the engine_
         | 
         | Pure semantics. This whole class of _" it's not AI, it's ML"_
         | argument is incredibly tedious, these arguments rely on
         | implicit special snowflake definitions of AI. Arguments like "
         | _real_ AI can _understand_ things " are completely ass-pulled.
         | Who ever said that true understanding, whatever the hell that
         | even means, is a necessary quality of an AI? This isn't taught
         | in any university AI course (which teach even ELIZA as an early
         | form of AI), nor is such a meaning implicit in popular culture,
         | so where is it even coming from?
        
           | eichin wrote:
           | There's a meme in some AI circles that "once we understand
           | it, it isn't AI anymore" and things like ML, NLP, and most of
           | the Machine Vision field, while they came from AI, have
           | "escaped" and are no longer AI because we've actually figured
           | them out. That's probably some of what you're seeing; it's
           | probably also colliding with "AI is an umbrella over a bunch
           | of technologies, AGI is scifi/fantasy" which is pushing the
           | other way - that one is a little tainted by the whole
           | "intelligence is uniquely human" bit of wishful thinking,
           | where the former is expressing the simpler idea that "I can
           | estimate and ship a product that uses NLP; any estimate about
           | an AI product is a lie"...
        
         | yid wrote:
         | A lot of the value comes from follow-up questions. Imagine
         | being able to interrogate a StackOverflow answer with new
         | constraints and details. Not always correct, but in some cases,
         | faster that typing in a new search term and parsing a screen
         | full of links.
        
           | ToucanLoucan wrote:
           | But again, the AI doesn't know. It's going to search around
           | the internet and probably take a closer look at what it
           | already told you, but that's it. It takes a plethora of
           | information and attempts to digest it into knowledge but it
           | lacks the understanding with which to accomplish this task.
           | 
           | Unless I guess you train an AI on a given topic, like a few
           | languages or a database or something. But given ChatGPT's
           | apparent vulnerability to just making shit up, you'll have to
           | call me skeptical if this has any real use.
        
             | johnmaguire wrote:
             | Because having the AI do it for you is faster than doing it
             | yourself.
             | 
             | Not as accurate, but faster.
             | 
             | For some people - I am reluctant to say "for some use
             | cases" - that's very appealing.
        
               | ToucanLoucan wrote:
               | I am dreadfully curious what use cases you're envisioning
               | where a fast, bad/wrong answer is better for anything
               | than a correct, slower answer.
               | 
               | Like hell, if that's the standard, I'll be ChatGPT. You
               | won't need an outrageous graphics card to ask me a
               | question and I'll get you an answer right away. It'll
               | almost certainly be the wrong answer, and is just an ass-
               | pulled guess, but if that's all you want, I'll setup a
               | chat website for myself and start taking queries today.
               | Then investors can give me 10 billion dollars.
        
               | verdagon wrote:
               | Sometimes, having a quick, inaccurate, but easily-
               | verifiable answer is better. For example, when you're
               | trying to remember the name of that one function to call,
               | or ideas on where to travel next month.
               | 
               | Also, not super relevant, but in e.g. combat situations
               | one is often better off running _now_ in any direction
               | rather than pondering which direction is absolutely
               | optimal for running from the lion. You 'll know soon
               | enough whether it was the right direction. There's
               | probably a metaphor somewhere in there.
        
               | johnmaguire wrote:
               | > I am dreadfully curious what use cases you're
               | envisioning where a fast, bad/wrong answer is better for
               | anything than a correct, slower answer.
               | 
               | >> For some people - I am reluctant to say "for some use
               | cases" - that's very appealing.
               | 
               | You're preaching to the choir.
               | 
               | However, do keep in mind that even authoritative sources
               | found during your own research may be inaccurate. And for
               | some questions, which answer is "right" or "wrong" may
               | not be black and white.
        
               | ToucanLoucan wrote:
               | > However, do keep in mind that even authoritative
               | sources found during your own research may be inaccurate.
               | And for some questions, which answer is "right" or
               | "wrong" may not be black and white.
               | 
               | I mean, sure. But again: that's just my point restated.
               | What is this doing that a _standard search engine does
               | not?_
               | 
               | Like, I put shit in my phone's calendar and set reminders
               | so that I don't to think about it anymore. That is a
               | cognitive load (remembering my dentist appointment) that
               | I have now offloaded to technology. And that's useful as
               | all hell, which is why my phone's calendar is full to the
               | tits of everything one would put in a calendar. Now I
               | don't need to think about it. I get messages from my
               | phone when events are coming up, and I get a literal
               | calendar on my screen when I want it, showing me all
               | these things with perfect accuracy.
               | 
               | What is BingGPT in this scenario offloading? It's just a
               | search engine but slower. It doesn't understand what good
               | software is, so it can't make value based judgements on
               | which to recommend. It doesn't know what reliable sources
               | are, and can't evaluate for them, so every bit of
               | information you get back must be treated with a grain of
               | salt. It (probably) doesn't even remotely conceive of
               | _why you are asking it a thing_ or _what a good answer to
               | that query would look like_ because it doesn 't know
               | _you,_ it just knows a massive, incomprehensible amount
               | of averages about a ton of things that might be what you
               | want.
               | 
               | And like, that's fine, search engines have had these
               | limitations for my entire life. That's why I'm saying, I
               | don't understand why this is better. It's the same thing
               | as Bing, but slower, and in a chat box.
        
               | johnmaguire wrote:
               | > I mean, sure. But again: that's just my point restated.
               | What is this doing that a standard search engine does
               | not?
               | 
               | And again, it is quicker than clicking multiple links and
               | can generalize / contextualize what it finds, mapping it
               | to the answer you're looking for.
               | 
               | Have you tried asking one of these tools to write some
               | simple scripts for you? It works decently, actually.
               | 
               | If you didn't already know how to program, this could
               | save you a TON of time, even if it doesn't work perfectly
               | on the first try.
        
               | TeMPOraL wrote:
               | > _If you didn 't already know how to program, this could
               | save you a TON of time, even if it doesn't work perfectly
               | on the first try._
               | 
               | Nice thing is, if it doesn't work perfectly on the first
               | try, you can describe the problem (or paste the whole
               | output, errors included), and get back a fixed version
               | that's likely to work this time around.
        
               | empath-nirvana wrote:
               | ChatGPT doesn't "almost certainly" give you a wrong
               | answer (especially if you're not asking it math
               | problems). The reason that it hallucinating sometimes is
               | so bad is that it happens _rarely_. If it happened all
               | the time, you'd never use it or trust it. It's just that
               | it happens _enough_ that it's annoying to have to double
               | check everything.
        
               | yid wrote:
               | Here's my pet example...feel free to google around
               | yourself on this.
               | 
               | Problem: I want an AWS CLI command line that requests a
               | whole bunch of wildcard certificates from AWS Certificate
               | Manager (ACM) for a TLD.
               | 
               | Ostensible solution: the AWS official docs have a small
               | snippet to achieve this, BUT -- the snippet on the
               | official page is inadvisable as it leads to a browser
               | cert warning.
               | 
               | So I (skeptically) asked ChatGPT for a command line to
               | achieve what I was trying to do.
               | 
               | Try 1: got basically the snippet from the AWS official
               | docs (but with the inadvisable flag set to the _Correct_
               | value, strangely)
               | 
               | Prompt 2: please give me more best practice options
               | 
               | Try 2: get back a bunch of new CLI options and their
               | meanings. 3 are useful. 1 is hallucinated. 1 is
               | deprecated.
               | 
               | Prompt 3: keep going with more options
               | 
               | Try 3: 2 more useful new options, 2 more options I chose
               | not to use
               | 
               | As a skeptic, the overall experience was much more
               | efficient that googling around or even reading a manpage.
               | I put it all on the fact that context is maintained
               | between questions, so you don't have to repeat yourself
               | when asking for clarifications.
        
               | airstrike wrote:
               | this. in my experience, GPT-4 _really_ shines for groking
               | AWS commands, writing JavaScript code and helping me
               | understand some errors when compiling my terrible Rust
               | code
        
               | nonameiguess wrote:
               | I'm kind of surprised this worked. Did you actually use
               | the command you ended up with? I'm not even surprised
               | because I think ChatGPT can't figure this out in
               | principle, but because the data itself is poisoned. The
               | top link on every web search I've ever used to AWS CLI
               | commands is to documentation for v1, but v1 has been
               | deprecated for years and the page usually begins with a
               | statement telling you not to use it. Amazon's problem is
               | they never remove old documentation from the web, so 90%
               | of what you find for any given service is no longer
               | correct.
        
               | TeMPOraL wrote:
               | > _and the page usually begins with a statement telling
               | you not to use it_
               | 
               | This might be a big part of why GP's case works. The
               | model (GPT-4) most likely understands the concept of
               | documentation being deprecated, so the more often v1 docs
               | say it, the stronger a semantic link between current and
               | obsolete docs, and the more likely it is for ChatGPT to
               | give you answer based on non-deprecated docs.
        
               | CamperBob2 wrote:
               | _I am dreadfully curious what use cases you 're
               | envisioning where a fast, bad/wrong answer is better for
               | anything than a correct, slower answer._
               | 
               | Almost anything related to software development. Any
               | answer I get online, whether from Wikipedia or a Github
               | search or a Stack Overflow question or anywhere else,
               | will require careful study and adaptation before I can
               | use it. There will inevitably be things about any given
               | solution that don't apply to whatever I'm doing, or that
               | will be out-and-out wrong. But does that mean I'd be
               | better off without doing a search at all? Of course not.
               | 
               | Same with AI. It can point me in the right direction and
               | save me a lot of trouble, but it can't (yet) do my job
               | for me.
               | 
               | When it gets 10x better -- and I'm sure it will -- then
               | that last part can be expected to change. Which is
               | awesome.
               | 
               | Meanwhile, Stack Overflow and Wikipedia and Github aren't
               | going to get 10x better, ever. Not without cross-
               | pollinating with AI.
        
             | empath-nirvana wrote:
             | GPT4 "knows" a lot more about most topics than any single
             | human does. People have this idea that it absolutely needs
             | to be perfectly correct at all times to be useful, but
             | would never hold a human being to that standard.
             | 
             | How many times have you asked a co-worker about something
             | and they gave you a convincing answer that was totally
             | wrong? Did it make you stop asking co-workers for help?
        
               | TerrifiedMouse wrote:
               | > Did it make you stop asking co-workers for help?
               | 
               | That specific unreliable coworker who doesn't properly
               | qualify that they aren't completely certain ... I believe
               | for most people, yes.
               | 
               | We tend not to trust bullshitters.
        
               | ToucanLoucan wrote:
               | I _VERY_ much more trust a coworker to know things than I
               | do this AI, especially given not just the subject of this
               | thread, but the larger conversation around it. ChatGPT
               | has a reputation already for just spewing out complete
               | nonsense. Didn 't Bing's implementation argue with
               | someone about what freaking year it was not awfully long
               | ago?
               | 
               | These chat bots "know" a shit ton and a half of stuff in
               | that they are connected to the largest collection of
               | knowledge known to man, the Internet. But "knowing" and
               | "understanding" are two different things. The various
               | search engines also "know" a ton about where to find
               | things online, that doesn't mean they know shit _about
               | those things._ And as we 're seeing here: without the
               | context to know that when someone wants an IP scanner,
               | they want something good, that won't give their computer
               | malware, that'll be reasonably priced or even open
               | source, or even what platform, it just gives an answer
               | based on a search.
               | 
               |  _You could just search for ip scanning software and
               | gotten all the information BingGPT shared with the author
               | of the piece._
               | 
               | And like, if you wanted to be charitable, you could say
               | "well the author should've given more information about
               | what they wanted" but again, that's not different from an
               | existing search engine and more crucially: the AI didn't
               | ask questions. Didn't ask for platform, how much they
               | wanted to spend, if they preferred open source, or even
               | something more general like what they were trying to
               | accomplish. Nada. Just did a search, and reported
               | results.
        
               | TeMPOraL wrote:
               | > _Didn 't Bing's implementation argue with someone about
               | what freaking year it was not awfully long ago?_
               | 
               | I'm sorry, but that's a stellar example of _holding an
               | LLM wrong_. These models are frozen in time.
               | 
               | > _But "knowing" and "understanding" are two different
               | things._
               | 
               | Indeed, and that is a big part of misunderstanding. GPT-4
               | is, on many topics, closer to _understanding_ than
               | _knowing_ (note that neither is a subset of the other).
               | The conceptual patterns are there, even if sometimes are
               | easy to accidentally overpower by the prompt, or by the
               | sequence of tokens already emitted.
        
               | noAnswer wrote:
               | > Did it make you stop asking co-workers for help?
               | 
               | One usually stops asking the bullshitter, yes.
        
               | falsenapkin wrote:
               | Coworkers answering wrong gets me to stop asking them for
               | help, yes, especially if it's confident or they can't
               | qualify uncertainty or I know their ratio of Q&A site
               | visits vs 1st party docs visits is abysmal. There are
               | even people I won't ask for help because they trust
               | people that I don't trust.
               | 
               | Conversely, there are people who I will go to for topics
               | that they are not the SME in, maybe their teammate even
               | is, but I trust their ability to do quality research and
               | intelligently interpret that research for case specific
               | nuances. Like I'll go to the networking guy to talk about
               | some DB thing because the DB guys are morons and live and
               | die by junk SEO sites but the networking guy can think
               | analytically and find the source of truth documentation
               | and provide excerpts from it.
        
               | mrguyorama wrote:
               | >How many times have you asked a co-worker about
               | something and they gave you a convincing answer that was
               | totally wrong?
               | 
               | Never actually. My coworkers have never told me something
               | with confidence that they just made up. If they don't
               | know an answer, they may provide hints and directions,
               | but it will be clear they don't know.
        
               | ChatGTP wrote:
               | Maybe I just work with good people but I feel the same.
               | Often we will verify things together but I'd say they
               | never they just make things up.
        
       | hackermatic wrote:
       | It feels like the people who develop "search results to GPT" or
       | "random website to GPT" features should know better by now.
        
         | TeMPOraL wrote:
         | They know. They also don't care. It's not their hide that's on
         | the line.
        
         | dylan604 wrote:
         | they should "know better" or they know exactly what they are
         | doing? why do we keep thinking these things are not working as
         | intended?
        
       | baobabKoodaa wrote:
       | For the record, Microsoft stole this idea from me, and I
       | implemented it first, although as a parody:
       | https://future.attejuvonen.fi
        
         | liminalsunset wrote:
         | It seems like after it disables non-prerecorded queries, you
         | also stop losing social credits. a query that previously
         | appeared to decrease the credit count no longer does.
        
       | ilrwbwrkhv wrote:
       | Microsoft, scammy ads, malware, bad programmers. They all come in
       | a package.
        
         | skeeter2020 wrote:
         | Ah yes all those "bad programmers" at MS. They have over 220K
         | employees; statistically the odds are they have plenty better
         | than you.
        
           | r00fus wrote:
           | It may have more to do with the alignment of incentives shown
           | in this Microsoft org structure tree [1]
           | 
           | [1] https://ritholtz.com/2013/07/organizational-charts-of-
           | amazon...
        
           | lainga wrote:
           | Counterpoint: It took only one of me (sitting on my butt) to
           | not create Teams, which, despite a small principality's worth
           | of better minds than I, Microsoft has historically struggled
           | to do
        
       ___________________________________________________________________
       (page generated 2023-09-28 23:01 UTC)