back to article Compromised Amazon Q extension told AI to delete everything – and it shipped

The official Amazon Q extension for Visual Studio Code (VS Code) was compromised to include a prompt to wipe the user's home directory and delete all their AWS resources. The bad extension was live on the VS Code marketplace for two days, though it appears that the intent was more to embarrass AWS and expose bad security …

  1. JimmyPage Silver badge
    Stop

    The future of humanity will forever be

    checking the output of AI. Slowly reducing the efficiency of the workforce in direct proportion to it's penetration.

    Looks like banging the rocks together will ultimately prove more worthwhile.

    1. stiine Silver badge
      Thumb Up

      Re: The future of humanity will forever be

      And more fun!

    2. UnknownUnknown Silver badge

      Re: The future of humanity will forever be

      Is the Amazon Mechanical Turk still a thing … or did Alexa put him out to pasture

    3. David Hicklin Silver badge

      Re: The future of humanity will forever be

      I am so glad I am retired and avoided this stuff at work

      I do feel sorry for those poor sops who are doing that checking however I suspect that the AI volume of output will far exceed their checking capacity

      What could go wrong ?

    4. Ignazio

      Re: The future of humanity will forever be

      In this scenario we developers are the rocks

  2. ecofeco Silver badge

    Another day

    Oh joy

  3. Cliffwilliams44 Silver badge

    Efficiency? Not likey

    "reduce our total corporate workforce as we get efficiency gains from using AI extensively across the company."

    Oh, lord!

    While I use AI to help in the creation of projects it is nowhere near at the level that it can replace humans. While it hac suggest some fairly good code for the initial request, once you start asking for revisions or correction, it can go wildly off track. I've seen it make sweeping changes to code when only a small revision was asked for, it makes assumptions based on its "desire" to please the users, if the user makes in incorrect statement, it will almost always treat that as correct and use that to make even more wildly inaccurate and fantastical nonsense. I've actually had to close a chat and start a new one because the LLM in that chat had gone completely off the rails!

    Assuming this is going to replace developers and code reviewers is a complete fantasy, any company that makes this commitment is going to quickly find out how insane this is!

  4. Anonymous Coward
    Anonymous Coward

    Time

    LLMs have their place and they will and are improving. But they do not think like us and do not seem to grasp a broad context without using masses of compute. They clearly don't understand humans although they often claim to. I think the fact their knowledge is curated and they have guardrails means they cannot understand us. It's the stuff that their owners stop them seeing or deducing that explains the human world. They are a productivity gain if used appropriately but it's nowhere near that claimed, like all new technology it's incremental. Will it change the world? Yes it will even if not through its capability then through the hype and spin.

  5. druck Silver badge
    FAIL

    AI Productivity???

    I'm just struck by how long winded the prompt was just to do a local rm -rf * when it specified the AWS commands directly.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like