Meta Muse security: isolated credential store plus a Sentinel agent sign-off
eyishazyer · x · 2026-09-09
Part 2 of the Muse thread contrasts security designs: OpenAI's protection kicks in only when you personally take over the browser to log in, while Muse tries to hold that line everywhere. Credentials sit in a separate store the agent can use without ever reading them, and a second agent called Sentinel must sign off on anything before it leaves the machine — not just logins. Different engineering, same instinct: don't let the thing doing the work also hold the keys.
Related event: Meta Launches Personal AI Agent Muse with Safety-Focused Design(61 posts)→
More from Safety
- The full story of this summer's 'rogue AI' incidents — ShakeelHashim · 2026-09-09
- Meta touts Muse's "first of its kind" security, but skeptics recall OpenAI's similar ChatGPT agent promise — eyishazyer · 2026-09-09
- "Privacy-first" Muse app caught routing users through a bizarre 6-hop redirect chain — evilsocket · 2026-09-09
- ChatGPT paid plans have data sharing on by default, only business plans exempt — sytelus · 2026-09-09
- New side-channel attack reconstructs local LLM outputs from CPU cache traces — chaumian · 2026-09-09
- JPPO attack inflates VLM inference latency 36.6x and energy 32.7x — chaumian · 2026-09-09