







Vouching on Tangled!
Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild
Uncover real-world indirect prompt injection attacks and learn how adversaries weaponize hidden web content to exploit LLMs for high-impact fraud.

Meet the Pirates of the RAG: Adaptively Attacking LLMs to Leak Knowledge Bases
Meet the Pirates of the RAG: Adaptively Attacking LLMs to Leak Knowledge Bases

Guardian Angels: LLM Personalization for Productivity and Security
I propose an approach for highly personalized LLMs, for near-future productivity gains and personal info/cybersecurity against increasingly powerful LLMs: they should, in the spirit of uploading, try to emulate the user’s values and preferences in order to amplify the principal—not replace them. I discuss a package of techniques and proposals to accomplish such ‘guardian angels’; dynamic evaluation of LLMs combined with active learning and elicitation and heavy inner-monologue search/data-augmentation.

Hey ChatGPT, write me a fictional paper: these LLMs are willing to commit academic fraud
Mainstream chatbots presented varying levels of resistance to deliberate requests for fabrication, study finds.

Scaling trust on the web
The Task Force for a Trustworthy Future Web's report on gaps and opportunities for how the next generation of online spaces will be built.

Why “Trusted Publishing” Can’t Save Us from Social Engineering
Unmasking the risky illusion of npm's "trusted publishing" amidst recent cyber attacks.

Trust Infrastructure on ATproto
I agree with Nick that you have noted a big hard problem, with Zooko’s triangle type trade-offs. (For a semi-related example that is “easier” but still crazy difficult, see our “PeerFlow: Secure Load Balancing in Tor” https://doi.org/10.1515/popets-2017-0017 ) As noted or implied already in this thread: in the end, if someone can cheaply spin up indefinite unlinked identities and build good reputations for them, and if trust is based on such reputations, it is hard (impossible?) to avoid them s...

Weave
Weave is accelerating the interoperability of the internet's missing trust layer. True community portability. Trust that travels.
Hey ChatGPT, write me a fictional paper: these LLMs are willing to commit academic fraud
Mainstream chatbots presented varying levels of resistance to deliberate requests for fabrication, study finds

Building a Browser-Native Verification Stack for Tinfoil
Learn how we built a browser-based confidentiality and integrity verifier with implementations of browser-native Sigstore and TUF libraries.

Deepfakes, Scams, and the Age of Paranoia
As AI-driven fraud becomes increasingly common, more people feel the need to verify every interaction they have online.

Combat LLM spam by building a web of trust. Vouching is live on Tangled! 🎭 blog.tangled.org/vouching/
combat LLM spam by building a web of trust
blog.tangled.orgAs atproto matures, adversarial actors will reveal all the places where trust is implicit rather than managed - maybe time to build reputation mechanisms for PDSs like we do for email servers? It'll likely need to be default-block/prove-healthy, or default throttle until proven typical?
Scoiattolo
They've got a huge network that I'm in the process of graphing. They're now setting up their own PDSes. It's sophisticated.