Meta’s Muse is an adorable privacy and security dumpster fire

beardyw 372 points 261 comments October 06, 2026
www.techdirt.com · View on Hacker News

Discussion Highlights (20 comments)

whycome

It’s interesting that the only ads I’ve seen for Muse don’t mention meta at all.

coliveira

And it's all by design, Meta and its founder have a long history of releasing products with security "flaws" that are immediately used by them to collect vast amounts of information about their victims.

jeanpah

Again? This seems very intentional at this point

jagermo

I get the appeal of agents, I do. This is the future stuff we always wanted. But I cannot get myself to give one of these things access to my bank account or allow it to do price comparsion and shopping without oversight. Or access to my email or chat history. I just do not trust any of them, not with my money or with access to my conversations.

otikik

Oh Meta not giving a damn about privacy and security? Say it ain't so.

nekusar

"People just submitted it. I don't know why. They 'trust me'. Dumb fucks." -Mark Zuckerberg

alistairSH

Are all of these just flavors of "the agent has the same permissions as the user"? Not that I want to trust Meta with anything, but I'm guessing it asked for "root" access and the users granted it...?

ChrisArchitect

Since this is mostly a collection of links to previously discussed articles: Related: Updates to Full Disk Access in macOS https://news.ycombinator.com/item?id=49937631 Meta’s Muse has a serious 0-day https://news.ycombinator.com/item?id=49802030 Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions https://news.ycombinator.com/item?id=49893709 Maybe don't let Muse run your Facebook Marketplace account https://news.ycombinator.com/item?id=49875006 What Meta got right with Muse https://news.ycombinator.com/item?id=49946526 Muse – Meta’s personal AI agent https://news.ycombinator.com/item?id=49615537

sdcfgy

Isn't that Meta's entire product line?

DebtDeflation

>When one tech YouTuber put Muse in charge of their Facebook Marketplace sales, it sold his stuff way below acceptable rates Why are we depending on LLM "reasoning" to negotiate a price rather than just having the user enter a lowest acceptable price deterministically?

arshxyz

> Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages Can someone explain how this is possible? If an app can do this without Full Disk Access or a popup of some kind that's a way bigger lapse on Apple's part than Meta's.

fridder

This shouldn't be a surprise to anyone. Why would you trust Meta with privacy and security?

labrador

I can finally relax and let a random number generator make my decisions for me

chadd

It's very simple. There is ZERO chance the worlds biggest advertising companies will refrain, long-term, from using your most intimate secrets, gathered through your many conversations with their AI personal assistants, to sell you things.

matltc

Couldn't pay me to use this junk. Trying to think of a number that I would consider it, and honestly $1k/month wouldn't convince me unless - I have root on device - device is on its own vlan, fully segmented - !(SIM || 5G antenna) - no google/apple id authenticated on device - terminate agreement at any time without cost I'm probably forgetting/not aware of ten things I should consider.

Razengan

Does anyone remotely interested in AI use Muse out of explicit choice? Facebook is like Microsoft at this point: The thing your grandparents use. Even if they make something technically superior for a while, like what the Zune was to the iPad, tHey'll never really be cool. and they'll certainly never be trusted.

measurablefunc

Every social media & AI company is also a surveillance company. Targeted advertising doesn't work w/o mountains of behavioral data aggregated across all of Meta's & Google's software "products".

piazz

I’m pretty frustrated with Muse and the last thing I want to be doing with my free time is defending Meta, but this is such clickbait. Point by point: > “OMG you can jailbreak it and get it to spill its VM” This is the whole point; any content on the VM is yours. It runs in an isolated sandboxed VM separate from stored credentials etc; this is effectively your own computer. You don’t have to trick it. > It collects dossiers on your contacts These are more text files that live on your private VM, alongside memory.md, etc. Do you want your secretary to forget every person you contact every day? > It accessed Messages without full disk access This whole story never made sense or was substantiated. Full disk access is an OS level security boundary; the user had to switch this on. > It sold some guys stuff for too cheap and gave out his address OK this one I basically believe, haha. Because this is the problem with Muse: the LLM is just too dumb to perform complex tasks effectively in many cases.

Havoc

The model is decent and cheap under contributor version but no way I’m letting meta AI anywhere near anything that matters in my life. > Zuck: They "trust me" > Zuck: Dumb fucks.

hannofcart

I understand that a typical HN user is very different from the average person. However, surely by now even the lay people who have seen the testimonies before Congress, the lawsuits and the excesses by Meta execs over and over again ought to be atleast somewhat wary of handing them more personal data? I think the average person has very similar self preservation instincts as the rest of us. So it can't be that. Which leaves the fact that there are lot of people who don't know about the above mentioned scandals galore that Meta has been involved in?

Semantic search powered by Rivestack pgvector
8,687 stories · 81,484 chunks indexed