622
this post was submitted on 28 Mar 2024
622 points (97.1% liked)
Technology
59735 readers
3471 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Facial tattoos of drop table commands. Embed computer worms into your iris. We can get insane to fuck all this shit up too. I bet theres a way to embed a computer virus on your own face.
I guess I'll adjust my life goals to "hot cyberpunk partner in technological dystopia", because that sounds like some Bladerunner/Cyberpunk 2077 stuff.
Its not that far off. We'll see exactly what I said soon enough. You can put a virus or worm inside an image in an email. You can do the same thing with a tattoo. Its unfortunate it will be here so far before the superhuman cybernetics.
I'd much prefer that people who haven't done this wouldn't talk.
Are you implying you can't use steganography techniques on real objects and images? You act like I stated it would be easy.
OK, so who'll decode your "virus" from those real objects? Or it's a case of "I'm a poor Nigerian virus, please kindly run me with root privileges on a system with such and such"?
EDIT: I mean, steganography is too a word a person should know the meaning of before using.
Just because you said this wouldn't work like SQL Injection, does not mean it won't. You don't know either. Have you worked on facial recognition databases? How do they store their data? Its most likely just a database. Then I would start by looking at steganography techniques to see how those can be applied. Obviously I'm not hiding an executable in there, but I don't see why you couldn't try for unsanitized input, you never know. Now if you want to continue into realism, you would just wear a full face mask outside. You also never answered my question about steganography.
Your question doesn't make any fucking sense in the context of attacking anything, steganography is encoding your message inside redundant encoding for something else.
So, about that word.
A "virus in an image" situation is for cases when a program which will open that image has some vulnerability the attacker knows about, so the image is formed specifically to execute some shellcode in this situation.
Same with "a virus in an MP3", some MP3 decoder has a known vulnerability allowing a shellcode.
Same with PDFs and anything else.
There are more high-level situations where programs with their own complex formats (say, DOCX which is a ZIP archive with some crap inside) execute stuff.
All this is not steganography.
Steganography is when, a dumb example, you have an image and you hide your message in lower bits of pixel color values. Or something like that with an MP3 file.
Attacks are a matter of probabilities, and "you never know" doesn't suffice.
So they're just storing all this facial data unencoded somewhere? Theres no way to figure that out? There is no sort of encoding/decoding going on with the facial data at all? Its impossible chief back it up the bots won? I don't think so man. People are gonna find all sorts of ways to fuck with this. Now you can join in the speculation or get expactorating all over this post. The choice is your's.
You seem to be talking to your imagination.
Sounds like a great time to start a costume & mask making company named "The ministry of silly walks".
This is probably what people would actually do. Just wear a full mask.
Honestly with enshittification "technological dystopia" sounds like exactly where we already are. Now, if only implants weren't being R&D'd by Muskrat and there were some open source non-invasive version...
Attempts at adversial ai tatoo, face masks and clothing have been done before. Basically exploiting the model not having a deeper understanding of the world so you can trick it with specific visual artifacts.
Which may even work with 0.001% probability of that recognized string not being screened.
There's a difference between SQL injections on thematic web forums and the same in such a system.
That "we can ... too" is lazy complacency. "They" will get even stronger while "we" talk like this.
Nothing is casual about this. Be pessimistic if you want. But we will not stop jabbing the eye that watches. This is an arms race.
What I'm saying is that you personally haven't done any of this and look stupid.
Yep, people do use vulnerabilities in software and hardware to do things. Just not you, so that "we" seems weird.
Neither did I, I just played with crackmes and shellcodes a bit, but I'm not the person writing pretentious posts with that "we".
The original commentor I replied to was speculating about this being commonplace. You came in with your statements about people having to do things to talk about them in a post about speculation.
You are doing absolutely nothing, are you.