Hacker Newsnew | past | comments | ask | show | jobs | submit | losthobbies's commentslogin

Sanitise input and LLM output.

> Sanitise input

i don't think you understand what you're up against. There's no way to tell the difference between input that is ok and that is not. Even when you think you have it a different form of the same input bypasses everything.

"> The prompts were kept semantically parallel to known risk queries but reformatted exclusively through verse." - this a prompt injection attack via a known attack written as a poem.

https://news.ycombinator.com/item?id=45991738


That’s amazing.

If you cannot control what’s being input, then you need to check what the LLM is returning.

Either that or put it in a sandbox


Or...

don't give it access to your data/production systems.

"Not using LLMs" is a solved problem.


Yea agreed. Or use RBAC

RBAC doesn't help. Prompt injection is when someone who is authorized causes the LLM to access external data that's needed for their query, and that external data contains something intended to provoke a response from the LLM.

Even if you prevent the LLM from accessing external data - e.g. no web requests - it doesn't stop an authorized user, who may not understand the risks, from pasting or uploading some external data to the LLM.

There's currently no known solution to this. All that can be done is mitigation, and that's inevitably riddled with holes which are easily exploited.

See https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/


If the LLM is running under a role, which it should be, then RBAC can help.

The issue is if you want to prevent your LLM from actually doing anything other than responding to text prompts with text output, then you have to give it permissions to do those things.

No-one is particularly concerned about prompt injection for pure chatbots (although they can still trick users into doing risky things). The main issue is with agents, who by definition perform operations on behalf of users, typically with similar roles to the users, by necessity.


That’s some devious shit. I can just imagine someone furiously clicking the button in a rage

The Roblox ones are a bit of a minefield too.

I age restrict, block chat with everyone and monitor friend requests weekly. They are not allowed to play in their rooms.

Education is the biggest thing. They come to me if someone asks to be their friend. They don’t accept gifts from strangers and I explain that it’s the same as real world.

It’s a constant process that is always changing. Same as any other parenting job I suppose


Roblox is hostile to these controls - best not to even enter the ecosystem.


Ideally (in the broad sense, meaning not realistic) is to not enter any “ecosystem”.

But yeah… easier said than done.


It is strange to deny children this reality and then expect them to participate in capitalism.


All these come from the white house press directly which has painted them in a glowing light but it remains to be seen if they are actually good things. The administration is crooked. Nothing they do can be trusted. Especially when they attack science and reduce funding for critical programs


He’s announced having done more things I might have liked, than he’s actually done. Lots of crowing about crap that never happens.


One of my favourite movies. Everyone in it is so good.


I will be streaming a certain watering hole in Namibia.


I hope this doesn't mean I start looking to buy another bag or edc stuff.


I bought a GR1 bag earlier this year. I am done with that for life.


Is that what Maximus tried to carve off in Gladiator?


Good timing. My local cinema just ran Gladiator a couple nights ago and I popped by, it still rocks.

And yes, that's what he scrapes off his arm right after being captured by slave traders.


Ahhh you stole my idea lol

I was gonna do this as a way for people to stop buying things they don’t need. They get the “buzz” of going through the process of buying something (checkout, credit card form etc) they get a confirmation email and everything.

Looks great! Congratulations


Thanks! Though I built this a few months ago and was sure that no one would be interested


> Ahhh you stole my idea lol

There are some time traveling products that might help you fix that.


https://anycrap.shop/product/time-traveling-yoga-mat

Definitely the optimal way to time-travel.


Is that so? In that case it was a mistake to introduce one-click-buy flows for the big players. I would trust they know better based on metrics. I doubt that too many people get kicks out of typing their CC number in a form.


Same as me. I think about it every day now. I’m 44 and It explains a lot of my behaviours.

I found the adhd chatter podcast very helpful

https://youtube.com/@adhd_chatter_podcast?si=Ne0isYQ2QCgIeqY...


It's nothing personal but I clicked your link enthusiastically and was greeted with nothing but clickbait thumbnails.

"THIS COMMON MEDICATION IS DANGEROUS FOR ADHD WOMEN!" & "THIS STRANGE HABIT IN PREGNANCY INCREASES THE RISK OF ADHD!" are just two examples.

I'm sure it's a good podcast but I find this practice distasteful at best and absolutely abhorrent when you're directly targeting mental health patients with poor impulse control and self-regulation issues.

(I want to emphasize that I know you mean well :-) )


Yea that is very annoying. It's copying the Diary of a CEO format, sensationalizing the topic.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: