Zenitizer Exclusively for Club MacStories members, we have 20 1-year Zenitizer subscriptions to give away today from developer Manuel Kehl, the excellent meditation app that John recently reviewed. Enter your email address for a chance to win, but if you don’t, the first 500 people to use this link can still get 25% off an...
In This Issue
An announcement about AppStories and Beta Beat, an update on John’s RSS, bookmarking, read-later, and article highlighting workflows, a Zenitizer giveaway, how to frame iPhone screen recordings, plus the usual Links, App Debuts, the latest happenings in the Club MacStories+ Discord community, and a recap of MacStories articles....
Stupid Companies Make AI Promises. Smart Companies Have AI Policies. [Sponsor]
It seems like every company is scrambling to stake their claim in the AI goldrush–check out the CEO of Kroger promising to bring LLMs into the dairy aisle. And front line workers are following suit–experimenting with AI so they can work faster and do more.
In the few short months since ChatGPT debuted, hundreds of AI-powered tools have come on the market. But while AI-based tools have genuinely helpful applications, they also pose profound security risks. Unfortunately, most companies still haven’t come up with policies to manage those risks. In the absence of clear guidance around responsible AI use, employees are blithely handing over sensitive data to untrustworthy tools.
AI-based browser extensions offer the clearest illustration of this phenomenon. The Chrome store is overflowing with extensions that (claim to) harness ChatGPT to do all manner of tasks: punching up emails, designing graphics, transcribing meetings, and writing code. But these tools are prone to at least three types of risk.
- Malware: Security researchers keep uncovering AI-based extensions that steal user data. These extensions play on users’ trust of the big tech platforms (“it can’t be dangerous if Google lets it on the Chrome store!”) and they often appear to work, by hooking up to ChatGPT et al’s APIs.
- Data Governance: Companies including Apple and Verizon have banned their employees from using LLMs because these products rarely offer a guarantee that a user’s inputs won’t be used as training data.
- Prompt Injection Attacks: In this little known but potentially unsolvable attack, hidden text on a webpage directs an AI tool to perform malicious actions–such as exfiltrate data and then delete the records.
Up until now, most companies have been caught flat-footed by AI, but these risks are too serious to ignore.
At Kolide, we’re taking a two-part approach to governing AI use.
- Draft AI policies as a team. We don’t want to totally ban our team from using AI, we just want to use it safely. So our first step is meeting with representatives from multiple teams to figure out what they’re getting out of AI-based tools, and how we can provide them with secure options that don’t expose critical data or infrastructure.
- Use Kolide to block malicious tools. Kolide lets IT and security teams write Checks that detect device compliance issues, and we’ve already started creating Checks for malicious (or dubious) AI-based tools. Now if an employee accidentally downloads malware, they’ll be prevented from logging into our cloud apps until they’ve removed it.
Every company will have to craft policies based on their unique needs and concerns, but the important thing is to start now. There’s still time to seize the reins of AI, before it gallops away with your company’s data.
To learn more about how Kolide enforces device compliance for companies with Okta, click here to watch an on-demand demo.
Our thank to Kolide for sponsoring MacStories this week.
Interesting Links
Engadget tests modeling microphones that use software to emulate a variety of microphone types and styles. (Link) Moment announced that it’s releasing a refreshed lineup of add-on camera lenses for the iPhone, which is the first time the company has done so since the iPhone 7. (Link) Netflix posted to its company blog that I...
In This Issue
Jonathan hacks an iPhone mount for use with FaceTime on his AppleTV, Federico is concerned about the bugs in iOS and iPadOS 17, John on fresh starts and applying a restructuring outlook to workflows, plus the usual Links, App Debuts, the latest happenings in the Club MacStories+ Discord community, a recap of MacStories articles, and...
Previously, On MacStories
Stories Mercury Weather: A Crystal Clear Design for Every Apple Device Zenitizer: An Simple, Elegant Way to Practice and Track Meditation Sessions The Verge Marks the iMac’s Silver Anniversary Finalist: A Notepad-Inspired Task Manager Game On: Papers, Please Milestones, Netflix Eyes TV Gaming, Vampire Survivors and Rolando News, Plus an RPG for the Weekend Podcasts...
Up Next on AppStories
Next week on AppStories, Federico and John have a special summertime gadget show and tell highlighting their latest purchases and experiments....
Previously, On MacStories
Stories Söka: An AI Assisted App to Track Your Bucket Lists Apple Music Gains New Algorithmic ‘Discovery Station’ Callsheet Provides Movie and TV Details with an Uncluttered Native Interface Podcasts AppStories, Episode 346 – Why The Way Apps Are Made Has Changed MacStories Unwind: AV Club Edition: Silo, on Apple TV+...
In This Issue
A Tailscale Shortcuts tip, the benefits of a travel WiFi router, why you should do nothing more often, plus the usual Links, App Debuts, the latest happenings in the Club MacStories+ Discord community, a recap of MacStories articles, and a preview of next week’s episode of AppStories....

