The Digital Security Digest, by Freedom of the Press Foundation (FPF), is a weekly newsletter with security tips that keep you, your sources, and your devices safe. If someone shared this newsletter with you, please subscribe here.

Meta’s Muse is acting in unpredictable ways

In the latest example of AI agents giving us unwanted surprises, Meta’s new AI agent, Muse, has prompted some cautionary tales. Like other agents, Muse is designed to automate tasks on your behalf. To do this, it requires wide-ranging permissions to take certain actions and to gather information it needs to fulfill your requests. Additionally, by default, Meta will use your interactions with Muse to train its models. Unfortunately, all of this access does not mean that it will do exactly what you want.

One user says he tasked Muse with selling a keyboard on Facebook Marketplace, only to learn it had agreed to a bad price and given his home address to the buyer, who then drove half an hour to pick up the item, but left empty-handed and angry because Muse failed to tell the user the buyer had come by.

In another example, Muse reportedly accessed a tech columnist’s Messages app and read his messages without explicit permission. When asked to explain, Muse said, confoundingly, “I can’t open your Messages app, scroll threads, or read history. It’s the incoming notification stream only, not access to your texts.” The agent nonetheless flagged specific information contained in text messages, suggesting a disconnect between what permissions it has and what data it can access through unanticipated channels.

Meta is clear that Muse may sometimes behave in erratic ways. In its documentation, Meta acknowledges, “Your Muse can make mistakes or take unexpected actions.” The company warns that you need to control what Muse accesses, oversee its actions, fix its errors, and review its permissions.

What you can do

  • Don’t be the lab rat. This is not just about unpredictable behaviors from AI agents. Like all software, these tools may contain vulnerabilities, and making use of AI agents requires a deep level of permission to access apps and the underlying operating system. For example, shortly after Muse was released, Patrick Wardle, a security researcher known for his expertise in Mac malware, identified a vulnerability that gave apps and terminal commands control over the agent. In the wrong hands, this would have provided an attacker with a terrifying level of control over an affected device. If you really want to use these tools, we would recommend waiting for the technology to grow into a more mature state and using it on an isolated device with limited access to only the information required for your purposes.
  • Let’s talk about privacy-preserving chatbots. As you probably know, when you use ChatGPT, Anthropic’s Claude, and Google’s Gemini, there is no real expectation of privacy. In exchange for access to the extraordinary level of computing power put into these tools, you are giving them — and potentially third parties, such as a law enforcement agency with a valid legal request — a copy of your conversations. If you are OK with using far less horsepower, you can download open source models and run them privately on your own computer for free. (Bonus: This way, you are less likely to boil the oceans.) Likewise, tools like Confer offer end-to-end encrypted chatbots. To learn about a variety of privacy-forward alternatives, check out Wired’s write-up.

Updates from our team

  • In our digital security trainings, more people than ever have asked us: What the heck is a passkey? We have an advice column unpacking passkeys and our recommendations about how to most effectively use them.
  • My colleague, Caitlin Vogus, wrote about government abuse of administrative subpoenas to access journalists’ records from companies like Google and telecommunication providers. Learn what you can do to push back.

Our team is always ready to assist journalists with digital security concerns. Reach out here, and stay safe and secure out there.

Best,
Martin Shelton
Deputy Director of Digital Security
Freedom of the Press Foundation