Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
0 points
johnisgood
5mo ago
0 comments
Save
Share
The response to the user is itself an exfiltration channel. If the LLM can read secrets and produce output, an injection can encode data in that output. You haven not cut off a leg, you have just made the attacker use the front door, IMO.
0 comments
No comments yet.