6/6/2026 at 5:34:20 AM
On the one hand this is exactly the right solution to prevent lethal trifecta exfiltration attacks.The existence of lockdown mode does however imply that ChatGPT, in its default settings, does not provide robust protection against sufficiently determined data exfiltration attacks!
by simonw
6/6/2026 at 5:57:44 AM
Related: Simon Willison’s post on OpenAI’s new Lockdown Mode (he coined the “lethal trifecta” term this is based on): https://simonwillison.net/2026/Jun/5/openai-help-lockdown-mo...by berlianta
6/6/2026 at 6:17:17 AM
Related: simonw is Simon Willisonby jameshart
6/6/2026 at 6:38:29 AM
Yeah I know the source references him (replying to his comment), that's exactly why I'm giving credit where it's dueby berlianta
6/6/2026 at 11:46:10 AM
It’s important to draw it out explicitly- I didn’t even look at the commentators name until it was mentioned. (If I see pelicans …)by bombcar
6/6/2026 at 11:44:15 AM
I wonder what robust protection would mean in practice for such a capable tool like an agent...Looking at the trifecta axis, if we assume we can't control untrusted content, that leaves us to create safeguards for private data access and external communication.
Would it be enough if we had a buffer between when these two happened: access to the environment and access to the web?
by gchamonlive
6/6/2026 at 12:43:00 PM
Robust protection means blocking any mechanism by which the agent, once compromised, might communicate stolen information back to an attacker.by simonw
6/6/2026 at 6:41:49 AM
I hadn't realized that deep research or generating images that I paste into Twitter were possibly exfiltrating my data. Yikes.by Noumenon72