Best Products
Launches
Launch archive
Most-loved launches by the community
Launch Guide
Checklists and pro tips for launching
News
Newsletter
The best of Product Hunt, every day
Stories
Tech news, interviews, and tips from makers
Changelog
New Product Hunt features and releases
Forums
Forums
Ask questions, find support, and connect
Kitty Points Leaderboard
The highest scoring community members
Streaks
The most active community members
Events
Meet others online and in-person
Advertise
Subscribe
Sign in
Clear text
recent
p/murror
by
Mona Truong
•
23h ago
Your "summarise this link" feature is a security boundary. 15,300 pages are already testing it.
... nobody covered, which is worse, because it changes a line of code a lot of us shipped this year without thinking about it. If your product has a "paste a URL" box, a link unfurler, an enrichment step, a
competitor
-monitoring job, or anything that fetches a page and hands it to a model, this is about you. What was actually measured. The paper is "Indirect Prompt Injection in the Wild" by Khodayari, Zhang, Acharya and Pellegrino, out of CISPA ... ... trial effectiveness study is the part I'd most want replicated. The exercise. Twenty minutes, on your own product. List every place text you did not write reaches a model. Most people stop at the obvious
fetcher
1
2
p/general
by
Alex Goldwyn
•
10d ago
Three requests to my pricing page, three different session ids, and nothing on the page reads them
... first is present, that page is out of every shared cache in front of you no matter what the second one claims, and the clients collecting those identities are your uptime monitor, your link checker, every social preview
fetcher
and every crawler, none of which will ever send one back. The part I got wrong is worth more than the finding. I assumed the pages that have to know who is asking were the ones behind sign ...
1
2
Subscribe
Sign in