← Back to context

Comment by efitz

8 days ago

This is amazing and terrifying (I am a security engineer and parsing complex document formats is a never-ending treasure trove of vulnerabilities).

The amount of attack surface in various format parsers is pretty stunning and terrifying indeed

AI agents run in isolated VMs, but PDFs have been out here running in the open for 30 years!

  • But can your PDF run an AI agent?

    • In my opinion the question isn’t so much “if” but rather “when”.

      When will AI research and hardware capabilities reach a point that it’s practical to embed something like that into a regular document?

      We’ve already seen proof of concept LLMs embedded into OpenType fonts.

      I guess the other question is then “what capabilities would these AI agents have?” You’d hope just permission to present within that document. But that depends entirely on what unpatched vulnerabilities are lurking (such as the Microsoft ANSI RCE also featured on the HN front page)

      3 replies →

    • The first widespread AI Malware will be a historic moment in this century. It will adapt like a real biological virus to its host and we have no cure for this.

      1 reply →