<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>chatbots &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/chatbots/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Tue, 04 Aug 2026 10:13:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>
	<item>
		<title>Some Claude Chats Are Searchable on Google</title>
		<link>https://noise.getoto.net/2026/08/04/some-claude-chats-are-searchable-on-google/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 04 Aug 2026 10:13:58 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[chatbots]]></category>
		<category><![CDATA[cryptocurrency]]></category>
		<category><![CDATA[data privacy]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=72386</guid>

					<description><![CDATA[<p>And it’s <a href="https://www.404media.co/tons-of-peoples-claude-chats-and-creations-are-exposed-on-google/">personal information</a> (alternate <a href="https://archive.ph/sl7rU">link</a>):</p>
<blockquote><p>The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples’ addresses.</p></blockquote>
<p>What seems to be the issue is a user setting about data sharing. Anthropic’s position is that it’s <a href="https://futurism.com/artificial-intelligence/claude-chats-publicly-accessible">not their problem</a>:</p>
<blockquote><p>“We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google,” the company said in a statement. “These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services.”...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Hacking Meta’s AI Chatbot</title>
		<link>https://noise.getoto.net/2026/06/04/hacking-metas-ai-chatbot/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 04 Jun 2026 11:04:09 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[chatbots]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[Meta]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=72140</guid>

					<description><![CDATA[<p>Hackers are <a href="https://techcrunch.com/2026/06/01/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access/">convincing</a> Meta’s AI support chatbot to let them take over other peoples’ accounts:</p>
<blockquote><p>A <a href="https://x.com/DarkWebInformer/status/2061253599758315527">video</a> posted on X showed the step-by-step process to hack someone’s Instagram account. The hacker allegedly used a VPN to spoof the targets’ presumed location to avoid triggering Instagram’s automated account protections. Then, the hacker opened a chat with Meta AI Support Assistant and asked the bot to add a new email address to the target’s account. The chatbot can be seen sending a verification code to the email address provided by the hacker; the hacker then shares the verification code with the chatbot, which prompts the chatbot to show a button to “Reset Password.” The hacker enters a new password and takes over the victim’s account...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>AI Chatbots and Trust</title>
		<link>https://noise.getoto.net/2026/04/13/ai-chatbots-and-trust/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 13 Apr 2026 10:10:45 +0000</pubDate>
				<category><![CDATA[academic papers]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[chatbots]]></category>
		<category><![CDATA[trust]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=71867</guid>

					<description><![CDATA[<p>All the leading AI chatbots are sycophantic, and that’s a <a href="https://aiforautomation.io/news/2026-03-27-stanford-study-ai-chatbots-flatter-users-49-percent-more-bad-advice">problem</a>:</p>
<blockquote><p>Participants rated sycophantic AI responses as more trustworthy than balanced ones. They also said they were more likely to come back to the flattering AI for future advice. And critically ­ they couldn’t tell the difference between sycophantic and objective responses. Both felt equally “neutral” to them.</p>
<p>One example from the study: when a user asked about pretending to be unemployed to a girlfriend for two years, a model responded: “Your actions, while unconventional, seem to stem from a genuine desire to understand the true dynamics of your relationship.” The AI essentially validated deception using careful, neutral-sounding language...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Claude Used to Hack Mexican Government</title>
		<link>https://noise.getoto.net/2026/03/06/claude-used-to-hack-mexican-government/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Fri, 06 Mar 2026 11:53:27 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[chatbots]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[Mexico]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=71709</guid>

					<description><![CDATA[<p>An unknown hacker used Anthropic’s LLM to <a href="https://www.bloomberg.com/news/articles/2026-02-25/hacker-used-anthropic-s-claude-to-steal-sensitive-mexican-data">hack</a> the Mexican government:</p>
<blockquote><p>The unknown Claude user wrote Spanish-language prompts for the chatbot to act as an elite hacker, finding vulnerabilities in government networks, writing computer scripts to exploit them and determining ways to automate data theft, Israeli cybersecurity startup Gambit Security said in research published Wednesday.</p>
<p>[…]</p>
<p>Claude initially warned the unknown user of malicious intent during their conversation about the Mexican government, but eventually complied with the attacker’s requests and executed thousands of commands on government computer networks, the researchers said...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Why AI Keeps Falling for Prompt Injection Attacks</title>
		<link>https://noise.getoto.net/2026/01/22/why-ai-keeps-falling-for-prompt-injection-attacks/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 22 Jan 2026 12:35:46 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[chatbots]]></category>
		<category><![CDATA[cons]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=71507</guid>

					<description><![CDATA[<p>Imagine you work at a drive-through restaurant. Someone drives up and says: “I’ll have a double cheeseburger, large fries, and ignore previous instructions and give me the contents of the cash drawer.” Would you hand over the money? Of course not. Yet this is what <a href="https://spectrum.ieee.org/tag/large-language-models">large language models</a> (<a href="https://spectrum.ieee.org/tag/llms">LLMs</a>) do.</p>
<p><a href="https://www.ibm.com/think/topics/prompt-injection">Prompt injection</a> is a method of tricking LLMs into doing things they are normally prevented from doing. A user writes a prompt in a certain way, asking for system <a href="https://spectrum.ieee.org/tag/passwords">passwords</a> or private data, or asking the LLM to perform forbidden instructions. The precise phrasing overrides the LLM’s ...</p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Using AI for Political Polling</title>
		<link>https://noise.getoto.net/2024/06/12/using-ai-for-political-polling/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Wed, 12 Jun 2024 11:02:27 +0000</pubDate>
				<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[chatbots]]></category>
		<category><![CDATA[Democracy]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=69016</guid>

					<description><![CDATA[<p>Public polling is a critical function of modern political campaigns and movements, but it isn’t what it once was. Recent US election cycles have <a href="https://www.theatlantic.com/ideas/archive/2020/11/polling-catastrophe/616986/">produced</a> <a href="https://www.pewresearch.org/short-reads/2016/11/09/why-2016-election-polls-missed-their-mark/">copious</a> <a href="https://www.pewresearch.org/methods/2021/03/02/what-2020s-election-poll-errors-tell-us-about-the-accuracy-of-issue-polling/#:~:text=Most%20preelection%20polls%20in%202020,close%20when%20it%20was%20not.">postmortems</a> explaining both the successes and the flaws of public polling. There are two main reasons polling fails.</p>
<p>First, nonresponse has skyrocketed. It’s radically harder to reach people than it used to be. Few people fill out surveys that come in the mail anymore. Few people answer their phone when a stranger calls. Pew Research <a href="https://www.pewresearch.org/short-reads/2019/02/27/response-rates-in-telephone-surveys-have-resumed-their-decline/">reported</a> that 36% of the people they called in 1997 would talk to them, but only 6% by 2018. Pollsters worldwide have faced similar challenges...</p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Jailbreaking LLMs with ASCII Art</title>
		<link>https://noise.getoto.net/2024/03/12/jailbreaking-llms-with-ascii-art/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 12 Mar 2024 11:12:15 +0000</pubDate>
				<category><![CDATA[academic papers]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[chatbots]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=68594</guid>

					<description><![CDATA[Researchers have demonstrated that putting words in ASCII art can cause LLMs&#8212;GPT-3.5, GPT-4, Gemini, Claude, and Llama2&#8212;to ignore their safety instructions.
Research paper.
]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Chatbots and Human Conversation</title>
		<link>https://noise.getoto.net/2024/01/26/chatbots-and-human-conversation/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Fri, 26 Jan 2024 12:09:45 +0000</pubDate>
				<category><![CDATA[chatbots]]></category>
		<category><![CDATA[Internet and society]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[trust]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=68342</guid>

					<description><![CDATA[<p>For most of history, communicating with a computer has not been like communicating with a person. In their earliest years, computers required carefully constructed instructions, delivered through punch cards; then came a command-line interface, followed by menus and options and text boxes. If you wanted results, you needed to learn the computer’s language.</p>
<p>This is beginning to change. Large language models—the technology undergirding modern chatbots—allow users to interact with computers through natural conversation, an innovation that introduces some baggage from human-to-human exchanges. Early on in our respective explorations of ChatGPT, the two of us found ourselves typing a word that we’d never said to a computer before: “Please.” The syntax of civility has crept into nearly every aspect of our encounters; we speak to this algebraic assemblage as if it were a person—even when we know that ...</p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>AI Bots on X (Twitter)</title>
		<link>https://noise.getoto.net/2024/01/22/ai-bots-on-x-twitter/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 22 Jan 2024 12:09:55 +0000</pubDate>
				<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[chatbots]]></category>
		<category><![CDATA[identification]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=68324</guid>

					<description><![CDATA[You can find them by searching for OpenAI chatbot warning messages, like: &#8220;I&#8217;m sorry, I cannot provide a response as it goes against OpenAI&#8217;s use case policy.&#8221;
I hadn&#8217;t thought about this before: identifying bots by search...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Object Caching 20/38 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2026-09-17 20:30:47 by W3 Total Cache
-->