Arcjet CEO David Mytton Warns of Rising Cybersecurity Risks in AI Browsers
Arcjet CEO David Mytton explains the inherent cybersecurity risks associated with adopting artificial intelligence (AI) browsers that many end users are not likely to appreciate.
Transcript
Hey guys, thanks for the throw. We're here with David Mitten, who's the CEO for Arc Jett. And we're having a little chat about, well, the security implications of all these AI browsers 'cause they're not quite like the browsers we used to know.
David, welcome to the show. Thanks. How me All?
Well, on the one hand, we're kind of all excited about AI browsers. They connect to all these AI agents and we can connect those to our apps and we can automate all kinds of interesting workflows and productivity will be awesome. So what could go wrong here my friend?
Absolutely nothing. Everyone was completely fine. A hundred percent secure, no problems at all.
Well, of course nothing is a hundred percent secure, right? So the question is, what is interesting about these new browser? What does it do?
Because it is just chrome under the, under the hood. So what has been added on top to make it interesting and what are the security challenges? That's kind of what we're we're talking about.
And really, when you've got a browser going off and doing things by itself, you can start to imagine where things can go wrong when it's accessing your personal information, when it's doing things on your behalf. And how much technology do you have over that? It seems like the bad guys, it's a relatively trivial thing for them to do.
They're gonna create some sort of malicious prompt sticking on some sort of website somewhere and it's gonna direct my browser, therefore to go do some task, which could be anything who knows what. But it could be for example, uh, exfiltrate all sensitive data into something that sends an email and a and a file to somebody else out there and away we go. And so I'm just wondering like, well, what are the security guardrails that we need to put in place and how do we put 'em in place?
Prompt injection was the key there and that's, that's what you mentioned. And this is an unsolved problem. Even the head of security for OpenAI has said that this isn't be solved yet.
There's a, an interesting paper that that meta put out just a few days ago that described three key areas that we need to think about when it comes to autonomous agents, AI agents doing things. If you have all three, then you're in a serious danger zone. Each of them prevent, creates a risk, but you can start to mitigate them, depending them.
But when you add them all together, it becomes a problem. So the first one of those is just processing untrustworthy inputs. That's what you talked about with the, the prompt injection.
If anyone can just inject anything into the prompt, then that could be potentially be malicious or you could control for that. The second one is then when you have access to sensitive private data. So if you've got untrustworthy the employer accessing your sensor data, then you've got potential for a data breach.
But for it to do anything with that, you've got the third component, which is the ability to communicate externally or change state in some way. Because if you've got access to that private data, the only interesting thing you can really do with it is to overwrite it or send it out somewhere. And it's when you have all three, which is what you get with AI browsers, the this becomes a real problem.
So is this gonna become an issue that we're gonna discover later and then react to? Because I feel like every time I turn around somebody's downloading one of these browsers and you know, they're kind of like extremely, shall we say cavalier and just, you know, digging the joy and are we just gonna wake up one morning and go, Hey, what happened? And then people will start figuring out, maybe we should be more careful.
This is the story of humanity maybe, but certainly security and certainly computing. Um, and when it comes to security is we tend to only really make meaningful changes after there's been some kind of major instant and it has to be a pretty big incident for anyone to pay attention. And even then you look at public companies that have suffered a data breach and it doesn't really affect their stock price for any me format of time.
And so this is the question right now, as the AI is so new that we haven't really experienced any serious security incidents as a result, there have been them particularly with vibe coded apps, which just have terrible security because you're, you're building things quickly and it's trading, which is the whole point. But then if you don't take that extra step to think about security or just build in as you're going, um, then you have some real problems. It's just that these haven't been using any real critical applications yet.
And I think that is probably to come some serious breach that makes everyone think, again, It doesn't seem like the people who are making these browsers are taking any responsibility for this. So, um, you know, at what point will somebody kind of come back to them and say, you know, you need to solve this issue. Because if I recall back in time we used to have browser security issues and eventually the people who made the browsers kind of figured out they needed to fix it.
That's right. Well Chrome and the other browsers they update regularly, you, you've probably seen that little button that gets bigger and bigger and bigger in the top right corner to tell you to update your browser. And most people ignore it for as long as they can.
But eventually you've gotta update things. And I think this just part of human psychology, developers don't update their dependencies. Users don't update their browsers, people don't update their phones because it's annoying, right?
You have to restart, you lose your tabs. It's a lot of work to upgrade dependencies and the browser vendors have done a good job at making the the updates, silent downloads behind the scenes. All you have to do is restart your browser.
But even that one step is annoying to people. And what we're seeing with new AI browsers is that they're a layer on top of top of that. Google is updating Chrome all the time, but is OpenAI updating their version, brave updating their version?
They're all built on top of the open source components. And so you've got these multiple layers where the updates have got filter through. So then the question becomes all who's responsibility is it?
Is there a browser vendor bug? Is there an issue with the ai? Is it somewhere else?
Where does the liability lie? And maybe there's some interesting legal component that's gonna come out as a result of legal cases putting the liability on different people. Mm-hmm.
Do you think there'll be lawsuits about this at some point? I mean, will somebody kinda say, oh you know, I didn't read the fine print on the user license agreement buried in line 472 that just basically said that, you know, bad things can happen. There's always lawsuits and I think this is just opportunistic attempts, but also some serious lawsuits will come out that will demonstrate where the liability lies.
And there's a lot of case law that already talks about this, but we know that liability can be disclaimed, you can uh, set limits on it, but there are certain things you just can't. The um, the underlying kind of legislation of the country prevents you from uh, excluding liability for certain things even though there are serious things that happen. And so this is gonna be a question of what is the impact?
If someone's emails get leaked, that's annoying for that person, but it's not an existential problem that the, the congress needs to think about. But if it's a, an AI tool that's taking control of some critical system, then that's a different story, Right? It's roughly equivalent, at least in my mind to somebody made a car but there's no locks on the car and anybody can drive it and do anything they want with it.
No locks or no no speed limit. I suppose there's no no control that stops you from going 200 miles an hour, but the, the laws are there and maybe the police are there. Um, and I dunno how far that analogy goes 'cause we don't really have police on the internet.
It's not really the same kind of thing, but like the tool is there, it's used by most people in a normal way, but some people can abuse it. And then the question is, well who's liable for that? Is it the user?
Is it the manufacturer? So far we've, we've err on the sides of it being the user's responsibility, but when it comes to vulnerabilities that are inherent to the software, it becomes more the manufacturer of the tool. It needs to think about this from the very beginning, building security in as a feature rather than as something you add later.
So what is your advice to security people who are a little tired of being, you know, constantly the naysayers and the office of no and they get beat up by their end users and yet, you know, they probably know or realize that, you know, this is maybe unsafe at any level. Yeah, this is the challenge. I developer there to build things and deliver customer value and security teams are often left to mitigate risk and say no.
And that creates this adversarial relationship between the developer and the security team or the user and the security team saying you can't do certain things and blocking access is a legitimate response. It just means you're not gonna benefit or potentially benefit from the latest tools. What we've seen with the Chad GBT type products is initially they were just, anyone would use them for any things and people were pasting all their sensor the data, their business data into 'em.
And then over time they've created controls where they can charge businesses more and in return they get access to data management features, not training on the data, making sure it's secure. You've got all the audit logs, you've got team features, and I suspect this is what will happen with new features like the, the browsers. They will start out completely open as they have done and then we'll start to see more enterprise features built into them that can be charged as an extra feature to give you controls over what the agent can do and what data can access.
But it comes down to these, the the three fundamental components that I mentioned earlier. And if you have all three of them together, the current thing is it's just impossible to secure them. And I think this is where the research is gonna go into is can we create a sandbox so the agent can run where you give it very specific permissions and it's always asking for user feedback, but how many times have you just clicked on that, that popup box on computer to give, give permission for something without actually reading or understanding what it means.
And this is the really difficult trade off between user experience and then the ability to access these new features. Do you think as we go along here that um, maybe people will shift away from, you know, what I call consumer grade browsers and they might look for something that's a little more enterprise grade and secure and maybe has some of these capabilities, but maybe we'll have some, you know, split here from that may be arguably long and for Duke Plus potential, I think that's kind of what I was was describing as having a a separate enterprise version with different features. My experience with products that are ified as enterprise is they're just not very good and users are used to having the latest interesting tools in their consumer activity.
The consumerization of enterprise and the, as you get access to all of these interesting tools in your personal life, then you wanna be able to use 'em at work as well because they have a lot of benefits and they're easier to use and they have a lot interesting features. And so keeping those and kind of up to date and par, the features, the user experience is the real challenge If you want to add on the necessary enterprise restrictions. And the ultimate version is just your laptop is just a, a dumb machine that is connected to a virtual desktop somewhere and everything is self-contained inside a a, a actually secure environment.
But anyone who's ever used any of those tools knows that they're slow, they're clunky, they're really annoying to use, you can't do basic things like copy and paste or like drag files to your desktop just becomes really annoying. And that's hopefully not the future that we're going towards. We of course have been living with shadow IT issues for as long as anybody can remember, but um, now we have I guess what we'll call shadow AI issues on top of that, but are the level of risk higher in the AI age than they were in the previous era of shadow it?
I think that's a good question. I dunno whether the risks are higher. I think the potential ease of which data can be lost is, is, is higher.
But the risk of very similar to what we've seen before is just data going into untrusted systems or systems taking actions that we, we don't know. And in on the consumer side of things, the these example is a, an agent that's buying something for you. It's taking your payment information and is putting it into make your purchase.
And as a consumer you can see the risk areas pretty easily. You can see that your, your payment data is being taken, see if something's taken in action, which hopefully to ask your permission but may making decisions on your behalf and if someone can trick it into making other decisions like buying other items you didn't want and sending them to where you didn't want 'em to be delivered, uh, becomes a problem. And so what we're seeing is the development of protocols from the likes of Stripe to build these kind of protections into the system so that an agent can take certain actions but then it requests approval from the human.
And having this human in the loop component is important. Being able to identify whether the action is being taken by a trusted agent, a trusted AI with that channel identity that's linked to a real person is the ultimate challenge. And dealing with bots as has been an issue as long as the internet has been around and fraud with transactions has being an issue and you never really win, but you just get a little better every time.
And hopefully with these new protocols that will make that easier. Um, but it's still gonna be a challenge and users are gonna have to really take responsibility for themselves and make sure they're using the features in a way that is recommended where they can. And then on the flip side, the developers of these tools are gonna have to build in security.
So that is easy for users to take advantage of it. Do you think that the malicious actors out there are kind of having a good chuckle at our expense? 'cause they probably look at all this stuff and they say, well, what else can you do to make my life easier?
Absolutely. Yeah. The ability just to do simple prompt injections, which an AI b browser just by having hidden text that is the same color as the background or hidden an image, it's trivial right now.
Um, this will get more sophisticated over time, but the, the latest update to, um, Apple's Safari browser, Macs and iPhone OS as five security vulnerabilities that were discovered by Google's AI bug hunting tool. So we're already seeing critical vulnerabilities being discovered by ai, uh, just so having that Google discovered it, disclosed it to Apple, they are white hackers, uh, um, making sure things are secure. But you could imagine that those similar tools could be made available to malicious actors who don't disclose the vulnerability and then have has a zero day available to them or can exploit certain certain scenarios.
Uh, so we're, we're just gonna see more and more of this. Um, and I think that's where the interesting thing's gonna be from the security perspective, but it's gonna be concerning from a user perspective. Well folks, you're hearing and here we live in interesting times and we almost guarantee that something bad's gonna happen in the not too distant future.
Hopefully it doesn't happen to you. And as they used to say on that television show back in the day, be careful out there. Hey David, thanks being on the show.
Thanks a lot. All right, and back to you guys in the studio.