home.social

#offlinecapable — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #offlinecapable, aggregated by home.social.

fetched live
  1. Due to recent reports about “AI”/LLM/“agent” tools and services, I have growing concerns that the #security properties of the open web are changing, or have already changed, in practice, to a degree that we haven’t seen in many years.

    This past week’s articles / reports on further investigations and details of the OpenAI Hugging Face intrusion / incident:  
    * OpenAI report: https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf
    * 2026-08-26 https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/
    * 2026-08-28 https://www.planned-obsolescence.org/p/the-hugging-face-attack-surprised
    and articles like:
    * 2026-08-26 https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/

    Previously I wrote about an instance of (presumably) unintentional subversion of site security by someone making mostly reasonable requests of a software “agent”:
    * 2026-08-24 http://tantek.com/2026/226/t1/cybersecurity-friday-small-business

    Combining those data points, it seems reasonable to conclude both that existing sites are in practice more vulnerable now, and as more advanced LLM models are available for use, as open models advance further, more sites will be vulnerable to more attacks, by a broader set of attackers, using fewer resources than were required in the past.

    One implication of these growing vulnerabilities in practice is a growing need to reduce one’s personal exposure to such sites and services. Exposures as “small” as merely having an account on such sites, all the way to depending on such sites for critical home or transport needs.

    For example, as vulnerable as various “internet of things” or “web of things” devices and services were in the past, we should expect they are or will shortly become even more vulnerable, and it would be reasonable to disconnect or otherwise take offline any such internet connected devices in your home.

    Similarly, if you happen to be driving a vehicle that is either “always connected” (e.g. built-in WiFi or cell connectivity), or frequently connected to the internet (e.g. joins your home WiFi when parked in the garage), you may want to investigate if it is possible for you to disconnect it from the internet and be certain of its disconnection (like hardware disabling), or at least manually choose when to connect it.

    Personally I do not have any “internet connected” home appliances (not counting a router or video streaming devices, home computers) or vehicles and even before this, never planned to get any for both security and privacy reasons.

    Even if you “only” have an internet connected robot vacuum or lightbulbs that depend on an internet connected “app” in order to change their colors, might be worth taking steps to disconnect them and figure out how to use them offline. And if they fail to function when disconnected, might be a good idea to invest in offline-only (local-only), offline-first, or at least offline-capable replacements.

    This is merely scratching the surface. I believe the larger implication of what this past week’s investigations have revealed is that we likely have to re-assess the security considerations/profiles of every website and web service we regularly depend on, especially those with account logins, profile information, and access to other parts of our lives.

    Previously:
    * http://tantek.com/2026/226/t1/cybersecurity-friday-small-business

    #AI #AIs #LLM #LLMs #agent #agents #AIagent #AIagents #OpenAI #HuggingFace #VM #VirtualMachine #cyberSecurity #openWeb #IoT #internetOfThings #WoT #WebOfThings #disconnect #offline #offlineOnly #localOnly #offlineFirst #offlineCapable
    #Blaugust #Blaugust2026