Comment by paxys
1 hour ago
People are (rightfully) concerned about superintelligent AI but social engineering continues to be by far the biggest attack vector for digital infrastructure. And it’s being made worse by companies continuously cutting costs in areas like support.
The call center employee making third world minimum wage doesn’t give a shit who the real owner of the domain is. They want to end the call quickly and get 5 stars from the customer on the feedback form.
I have made it a point to move off services that force SMS-based 2fa for this exact reason. Recently even changed banks because of this.
Superintelligent AI is getting very good at social engineering. See e.g. voice cloning scams
Honestly I'm wayyy more concerned with social engineering attacks than some theoretically superintelligent AI. Social engineering is, IMO, the far worse of the too
Isn't prompt injection basically social engineering for LLMs already anyway?