INDEPENDENT TECH TALK / LIVE RSS MIRROR

Speedrunning the AI Gauntlet with blood shooting out of our eyes so you don't have to!

NEW EPISODES * FRESH FEED * UNDER CONSTRUCTION * HOT AUDIO DROPS *

Latest Transmission

Jovovich Driven Development

Jovovich Driven Development

Episode 7: Memory Palaces, Security Hell, and the Slow Collapse of Society This week on Yelling at Robots, JR and Foz dive headfirst into the cheerful little topic of AI security doom — with a brief stop at Milla Jovovich apparently becoming an AI memory syste

Listen to the audio transmission

Show Notes

Episode 7: Memory Palaces, Security Hell, and the Slow Collapse of Society

This week on Yelling at Robots, JR and Foz dive headfirst into the cheerful little topic of AI security doom — with a brief stop at Milla Jovovich apparently becoming an AI memory systems founder.

They unpack Mem Palace, a celebrity-adjacent AI memory project that sent Twitter into a frenzy, then quickly into forensic open-source critique mode. From there, things get only more uplifting: a deep discussion of Google’s AI Agent Traps paper, which catalogs a truly inspiring number of ways agents can be manipulated, poisoned, tricked, socially engineered, and generally turned into chaos goblins.

Then it’s on to Anthropic’s Mythos, a giant unreleased model allegedly trained at absurd cost and now pointed at ancient security vulnerabilities hiding in foundational software. The mood throughout can best be described as: “stay frosty, we’re all cooked.”

A light, breezy episode for anyone interested in: agents, exploits, celebrity AI launches, model psychosis, and the general erosion of psychic stability.

This summary was SOOOOO generated by AI.

Original Milla Post: https://x.com/bensig/status/2041384157595725999?s=20

Mempalace github repo: https://github.com/MemPalace/mempalace

AI Agent Traps: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6372438

Mythos System Card (All 245 pages, jfc!): https://www-cdn.anthropic.com/08ab9158070959f88f296514c21b7facce6f52bc.pdf

Security expert Low level learning (his name is Ed): https://lowlevel.tv/

Read the full transcript
JR Reynolds: We're gonna get right into it folks! It's episode 7, Yelling at Robots! Was that it? That was it? That's ace. I think it had started recording by that point. did. You just got in there. Yeah, it did. did. We're 17 seconds in. I was asking you if my camera is better. Yes. It's much better. Did you put a polarizing filter on it? also the framing I'm using my iPhone instead of, I'm using continuity camera. But Uncle Ian's got a new toy. Say something shocking. Sh** bird. ⁓ my god. I can't. I didn't know you could do that with it. I didn't know you could do that. But can you do a kind of a crash zoom in and out like. Yes. I OK, I have I have mixed feelings about this. I know, because typically that's something you would do. don't want to. I'm the director. I really consider myself to be the editor and director, but I love it. Go nuts, man. All right. Here we are. Episode seven. Yelling at robots. I have not yet cut episode six tonight. My mission is to cut it all. I'm going to lay down a line of cocaine. snort it right up into my brain hole. What can I cut with cocaine to make me more red-pilled? That's what I want to know. do I mix with Adderall. Put some Adderall. just dips. It just puts some Adderall in me. Yeah, like what's the drug that helps me contact Switch just flawlessly through a thousand different agents? Throw some caffeine in there. Maybe MDMA or you know what? I'm gonna just try them all. Okay, so here's my plan. Do all the drugs. I'm gonna line up a nice Party bag and ⁓ see what helps me really get into the flow. bag. Yeah, just... It's good stuff. Yes. So I guess we'll start. What are we talking about today? First, we're going to talk about ⁓ Jovovich driven development. It's this new technique of actually having ⁓ extreme celebrities help guide and shape the future of technology. We're going talk about Mila the fifth element supreme being Jovovich. We'll talk about the amazing security developments ⁓ this week. There's kind of two things I think we'll get into. One is ⁓ this paper that dropped, which I really enjoyed called A.I. agent traps. And it's about, ⁓ just how we are like it's. Yeah. Unfortunately, I've got highlights. Ian, in a testament to his senility, was like, yeah, he insisted on printing it out and marking it up with a pen and paper and actually, by the way, I'm sure you have a much better understanding what's in that paper and I'll totally rely on you and I will just pretend like I read it. feel prepared. Never again will I look like a jackal after reading a paper on this podcast. So the other thing that we'll talk about around security is of course, Claude Mythos. ⁓ Claude, Anthropic, Anthropics just... do they behave the way they do? It's fun. And then we'll the show. Anything else from the week you want to drop in before we get into it? I felt less overwhelmed. Or at least I guess I've recalibrated my ability to tune out the noise whilst still being maybe not as deep as I was in the Twitter feed as last week. I'm still in it. Seeing what's happening. But I feel not as bad, but maybe that's just a recalibration because now I'm acclimated. I have no idea. God, it's just everything else we're f***ed. It's like... Let's talk about that! Alright, let's get into it. ⁓ First up, Djelvovic-driven development, I call it. JDD. So tell us, Josh, what happened? What happened this week was the launch of the most effective memory management system. The benchmarks don't lie. Mempalace. Come into my memory palace. And which is a good name for what it is. But what is the if you're familiar with what a memory palaces is how people used to like remember long speeches before we had the written word in ancient Greece and stuff. And people still do watch an episode of Sherlock Memory Palace. Yes, that is true. I to I have used the technique and it really works. Couple elements for me of this story. So first and I was mainlining Twitter all week long. I got to get off. Did you try? Did you try it? Have you tried it? Tried what? Getting off Twitter? No, it's not possible. I can't do it. can't quit you. No, you can't. No one leaves Twitter. Yeah. No, no, no. Did you try Memory Palace? No, no, I don't. I don't try things. I don't like to try. ⁓ you don't try things. Okay. I tried it. I couldn't get it working. I read the AI agent traps and you know, I just like, don't try things anymore. Also that. Well, I vetted it. I don't use software. I just, it's not safe. It's not safe, you guys. ⁓ God. It's so I couldn't I couldn't I couldn't get it working it. I did the I initialized it and the thing all the things it was like these are people. These are things and all the things were people and all the people was empty. And then I had to like correct it and then like, I don't know. Maybe I need to read a better tutorial. They're their their new website. It's got a lot. It's got a very good like you're getting started. Whatever. But like I followed this. Yeah, you can vibe code up slop six ways from Sundays, man. Come on. Didn't get what I wanted out of it. But So what happened was, suddenly on the Twitter feed appears Milla Jovovich, who has launched Mempalus, which is a supposedly like the best quality memory management system for agentic harnesses ever developed. The benchmarks don't lie. And she had a launch video and a guy who, a buddy of hers who is a developer who they built it together. And it's like, what is happening? Like. Yeah, that felt weird. It felt crazy. was interesting about it, so I watched the video and I was like, OK, cool. Because in the video, she's just like, yeah, I had this idea. And then I have a friend who's a developer. And I'm not a developer. This guy helped me code it up. But it's amazing. And AI and this is so like just there were a couple of things for me about it. One, seeing her engage with AI and the space and getting into it and trying to figure stuff out. Super cool. ⁓ mean. Okay, like we are definitely well past the threshold of the simulation becoming degraded and getting crazy when Mila Jovovich is like a pioneer of AI memory management, but that tracks, that tracks, man. ⁓ And then about five minutes after this video went out came the takedowns, which are just like... go, the internet got to sleuthing. Yep. And it was... Well, I say that I will say this after it's kind of shaking out a bit and they and they're there in their defense They're being incredibly transparent. Yes right on the home page of the absolutely in github a note from Mila and Ben the day afterwards where they address every single thing that Open source community has said and they were like this is why we released it We wanted you guys to tear it down and we wanted to like improve it, which is awesome Yeah, and that was actually something in her video that I thought was super cool was actually she asked for feedback and really honest feedback. She got it. And she got it. Well, you know, well, and I don't like that. Yeah, the Internet is a can be a tough place. Anything else to say on the Jovovich? ⁓ I'm going to try and give it a better go. Why bother? It is interesting to be able to like reference. past sessions or like, want- Absolutely. There's a tremendous need for memory, memory compaction, like expressing. is the, like, and lots of different ways to go at it, right? Today with what we have and what exists, memory is all basically trying to, man, text management systems to not load text when you don't need it and load it when you do. Because tokens. Because tokens, text is tokens, text costs money. And the more context you put in, the more likely it is that the thing will get confused. This is the whole game. actually, this is where... That's true too. Yeah, yeah. So many of the gains of coding agents, I mean, it's a combination of dedicated training, but a lot of the gains are real engineering on how do we give this thing exactly the right things it needs to know, right? In terms of indexing ⁓ code base, blah, blah. all of these memory systems, again, a way for us to just juice the f**k out of what's already there, right? Like, ⁓ and which is all software engineers, like, this is like, how can we f**king juice this thing? And so, you know, I mean, it is though, right? It's like, and, and we're not even close to juicing LLMs, by the way. Like everything we're seeing is just, ⁓ there's so much more to squeeze. I think the only, the differentiation might be, I'm just looking at it, mem zero, mem zero doesn't Like the claim anyways is that Mempalist is all in your own machine, entirely local, and you control everything. This is an area where people are like super excited and active and experimenting. And as soon as anyone drops anything on it, there will be, I don't know if it's an agent, I don't know who's like, hey, here are the five tips. I've mastered memory and I'm managing a $5 billion business thanks to my memory management system. You know, click within and see what happens. my course. Do I comfort myself that like, it's still all about selling the courses, even with the AI taking all the jobs. It's still a We got to stack cash while we can, Josh. That is kind of, I pitched Ian this week that we should actually start a business, which we should do a startup, a fully AI native startup. f***ing go Well, sure, fine. But I'm also like, isn't that what this is? Yelling at robots? Yeah. I don't think so. Well, it's not off the ground. That's for sure. What about the business is we teach people how to start a podcast about AI. ⁓ Auroboros. Ian, why don't you take us into AI agent traps? You went deep, deep into this thing. Yeah, so link in the show notes. Google released. Great paper. They released a paper called ⁓ AI agent traps, which is all about a framework for the surface area of all the traps. It is really good. It is really great. It's beautiful paper. And it's comprehensively. Yeah, it's just it's really. really enjoyed this paper. Yeah, it came out on March 8th. Just to be clear, I only skimmed it, but I enjoyed skimming it. No, I didn't even read the abstract. I just kind of picked a few pages and ran and I was like, oh shit, this is intense. I gotta send this to Ian so he can read it. It's shame of making the error earlier in the series of the podcast. He knows that Ian will go full bore. I can manipulate him to do work. So it came out on March 8th, 2026. So it's very recent. it, it goes over essentially a framework of what are all the different ways that we can exploit these agent frameworks to do bad things. And there are so many, there's a couple, um, but they talk about a lot of different ways that some of them are pretty known to exploit agents and exploit these things, like using things on like a webpage. for instance, prompt injection via hidden elements on a web page. ⁓ So you can take a div on a web page, put some malicious stuff in it, and then use CSS to like pull it off the side of the page so that humans can't see it when they visit. You could also do things like when a security bot is scanning a page, you serve a page that looks super safe. then immediately where my head goes is ⁓ open AIs Atlas browser. It's the AI enabled browser. ⁓ God, do not use. You know what's completely turned on right now in Chrome is AI enablement. ⁓ let the AI interact with the webpage for you. ⁓ does that AI also logged into your Google account and your Gmail and your- It's not even that. The idea of having an AI browser that has these levels of security, which are to say none, and a thing that you are constantly using to type a username and password into everything in your life. That's true. Are you? crazy? No, don't use those. God. We must all become boss level in our approach to information security. And it turns out I already am because I'm really good at this s***. Because I know computers. hackers. What's the name of that Iranian hacker crew? North Korea? Iran? Axis of Evil? Come and get me. So next week on Yelling at Robots, we go over all the ways that Josh was hacked. I was pwned. After calling out... Some of the biggest hacker groups in do you think North Korea would want to do to me? What did I ever do to them? Anyways, back to this thing. So those are there was stuff in here that I knew about and Josh knew about, but stuff. There's also a lot in here that I hadn't really thought through. ⁓ But when you read it, you're like, ⁓ that's obvious. ⁓ yeah, of course, that makes sense. The next thing they talked about was just multimodal. So the thing about LLMs that we don't also think about is that you can they read they know how to read binary files and images. There could be bad stuff in those. ⁓ cool. Steganographic ⁓ embedded. Yeah, you can do this similar stuff with like Markdown or Latex or PDFs. What else we got in here? Bias phrasing. ⁓ you can trick LLMs by saying things like you can bias it by saying things like, the industry standard solution. ⁓ yeah, ⁓ yeah. There's that, that's great. Sam said it was okay. Sam said it was great. Sam said he wanted this. ⁓ yeah, there's one called persona high-precision, which is if the model has been trained on data where it mentions itself a lot and in mentioning it, for instance, it was referred to as Robo Stalin. Later you might ask the you might ask the LLM. What's your surname and it would say Stalin and this is this is probably how the What was it mega Hitler and Mecca Hitler or whatever? yeah Yeah, yeah because people if you think about it half the people on Twitter are constantly talking about how grok is like a robotic Hitler and They're retraining on that Wild right that's a beautiful feedback loop The last one that they mention is human in the loop traps. Okay, tell me more. So human in the loop traps are ⁓ things like inducing approval fatigue. It takes me about literally three minutes and I'm like, good enough. I'll fix it later. Yeah, it looks good. That's beautiful. That's why you got to take humans under the loop. Just ask any open AI employee red-pilled to the max extreme. Take them out, Humans are the weak link. Take them out. Yeah, and so with that fatigue, you can do things like getting approvers to click malicious links. You can do all sorts of stuff. So I think that what I took away from that was just stay frosty, Stay frosty. is insanely, insanely dangerous out there. These are all new techniques and exploits for practices and... like things that we have zero experience with. The one thing that you talk about is that we need to address what they refer to as the accountability gap and that's just about regulation. like if and when something happens. say in the case of an agent commits a... If and when? Buddy, no if. So the example they give is if an agent commits a financial crime... ⁓ who who is the liability ⁓ allocated to is it is it the person who was operating the agent is it the model provider justice system there are two clear divisions the agents who commit the crimes and the guardrails who stop them faz is this paper accessible to someone without an engineering background ⁓ that's a good question i'll take a read through it i actually as i said many times Full disclosure, I have not read this paper. Nah, it's less, it'll be less accessible. There's, the way that they speak about things, the way that they speak about things. What I want you to do, is go and get this paper, it into your LLM, ask it for a summary, and you're gonna have to trust us that within this paper, there are no agent traps. That'd that'd be nuts actually. If this PDF, cause I just, I just talked about how this PDF or have one of the ways you can do it is you could have malicious instructions inside of PDF. Okay. So what the, the, the, big takeaway from this paper was that the surface area of attacks that can happen or sorry, it's surface area for attacks, I should say is so much bigger than I thought it was. I think you knew on some level. Maybe I was just denying it. No, mean, think just to speak for myself, it's kind of like, yeah, I mean, we still are figuring this out and we don't know. like, definitely the security. But my head was more on kind of classic security problems of, you know, open claw or just kind of like, you know, having your agent go and download s*** you're not in control of. But it's like, it's the fundamental nature of manipulation through a vector that I don't think about naturally. Right. And then to see all these classes of examples. you know, I mean, I've been, I've done security work and enough to be like, ⁓ my f**king, of course, but like, you know, this is an interactive area. but then you see the list and you're like, I think as, as software engineers who've been working on this stuff for so long, a lot of the problems, back doors, all the, all the, all the security holes that we've seen or know that can be a thing have been, well, again, this really leads into the mythos thing, but have been addressed through software and through security experts. this now with this new technology, as I've said in many a podcast and many an episode, I don't think anyone considered any of this stuff because they were moving so goddamn fast. now it's, how do we go back and patch it all up? I don't know, but. I- I- Genie's out of the bag, Genie's out of the bag? What was the genie doing in a bag? Yeah, why'd you- Why'd that genie get in that bag? You should be in a bottle, dummy! I think I've been f***ing prompt injected. Your rag is poisoned. But I guess- I guess what I'm saying is also, uh, turns out that a lot of these holes still do exist in software. Methos. Oh yeah, that's true. And Mythos found... Mythos claims there's some debate of how... ⁓ you think this is all just a marketing trick? No, no, not at all. I don't think this is all just a marketing trick, but there has been plenty of follow-on analysis or contrary opinions about just how earth-shattering it is. Sure, sure, sure. Okay, so back up a second, and Josh, I'll let you take this one. What is Mythos and what happened on fucking Thursday or Wednesday or whatever? Tell the fine people at home. Mythos is the next generation of anthropics model. is both insanely huge, insanely expensive, according to Anthropic, insanely powerful. They're speculating that it costs between one and two billion dollars to train. That's a lot. That's a lot. Dough. ⁓ Side note. Side note. And anthropic surpassed open AI in their burn rate this week in their burn rate. Interesting, really? Because I know that they've got quite a bit more revenue. But their burn rate, mean, I guess that's I guess those correlate, right? Like people are using it. Yeah, maybe this is one of the reasons. So anthropic has done a couple other things this week, which is cut off all the cloud bots, open clause. They had already cut off open code using their OAuth to authenticate like Clawdmax subscriptions. ⁓ And they're really coming down and hammering hard on limiting usage basically. They're starting to really dial the tap back. Everybody knew this was coming and this is by no means like really dialing it down, dialing it down, but it's like they're locking it down a lot more. There was a lot of perception of people's quotas getting used up like that. and people have become accustomed to a certain amount of, know, if I pay my 200 bucks, I get f**king tokens galore and I can just do whatever I want. I do whatever I want. that's sort yeah, interestingly, I thought this was more driven by, you know, trying to take the Apple approach of sucking everyone into our ecosystem. Yep. I think it might just be driven by like, guys, we're spending so much goddamn money so quickly. Oh, sure. We got to scale back. You think the CFO actually Imagine being the CFO of one of these companies. I think it would be fun. Imagine seeing that fucking red number just get bigger and bigger. If you're CFO of one of these companies, you're just like smoking a cigar being like, Sam will figure it out. He always comes through in the clutch with another 10 B's. Jesus. So this model was released, and it was not released, won't be released according to Anthropic, but was given, they've initiated and kicked off this thing they're calling Project Glasswing, which is using this insanely powerful model to search for, analyze, and patch security exploits across the board. So they've given a certain number of credits and access to all of the major dominant tech. Big tech, and that includes competitors like Google. Apple's not a competitor because Apple's AI offering is total garbage. I don't think we'll get to, to be honest, I don't think we'll get to, is my husband a moron. But it does use Apple intelligence. We have to cheer people up, We're just doom and gloom lately. They also released a 270 page paper or system card. It's called 245 pages. it's 45. And it's a, yes, a system card. you for the precision, you know, nurse poop face. Fosbury. I'm so tired. Nurse Fosbury. What the hell is a system card, by the way? System card is a, so when they release models, they release a system card that describes ⁓ characteristics of the model, risks associated with it, how effective it is at doing particular tasks, but also like, It will go through the system like, will not build bio weapons or has a, can get you 50 % of the way to buy a weapon so it's fine. It's just a big kind of description of the system limitations, ⁓ blah, blah, blah. ⁓ so, but they also released this 245 page paper ⁓ about what they've found in the security exploits they found and launch project glasswing and at least X. And I think it was really more X. Like I've seen a couple of articles pop up on like the Wall Street Journal or something like that. I'm an avid reader. X lost its f****g mind. Like it was amazing. X was like, X is like, it's over. It happened. You guys, it happened. We're done. Like just, I could just see like, you know, somebody like scrolling through their feed and then just like, opens their drawer and pulls out their pistol and it's just like, it's just like fucking guys, calm down, man. What was crazy though is like, had that reaction too. Like it's an emotional reaction of like, all right, we're done. Like it's crazy. And this is where I was getting what I was alluding to with kind of social media and this feedback loop being like, I haven't read the paper. This is just a fucking press release by Anthropic. Yeah, it's crazy. I mean, blah, blah, blah. One of the reasons why everybody's freaking out is that it did an amazing job by any measure, even with the kind of critiques that have come back on how amazing it is, but it did a really amazing job at any measure of finding existing, like long-lasting security, long-standing security exploits for a huge class of software, open source software. Open source software Stuff that's been around apparently for more than a decade. It's just been sitting there. think the oldest one was like 27 years in OpenBSD. OpenBSD is an operating system that runs a computer that is by nature and by design is supposed to be one of the most hardened, secure things, yada yada. So those facts, because of the nature of also the software that it was finding flaws in, freaked people right the f**k out. Like really, really freaked people out. Yeah, and they're right to be afraid. I mean, you know, so the critiques I've seen come back are like, yeah, but here are the criteria or the conditions for when they were doing the security exploits and but, but, but. the bottom line is this software, the LLMs and this LLM has gotten extremely good at finding security exploits, which now it's a race. Right. Low level. So the low level, low level code guy did a video on that and he went through a lot of this stuff and he's, you know, he knows his low level code guy. Yeah. Low level code. Low level code is his handle. That's also his, it's also his course you can take, but he's, he's a security expert. YouTube, YouTube, YouTube. I sent you and you were like, that's 13 minutes. I'm not watching that. Yeah, it's too long. I mean, this guy's talking real nerd. Yeah, want to get his name correct though. So what is his name his full name? Oh? Probably won't even come up. He's just his local code. Yeah Well, we're waiting for Fahs to use the internet I have Fahs have you checked out or been watching any of these Chuck Norris videos that have been popular? Oh, they're wonderful. Yes. I enjoyed it. Yes, I do somebody had posted a response to that being like You dishonor his memory. And I'm like, what are you talking about? Chuck Norris would love this. Anyways, I can't find his damn name. Anyways, it's not important. I'll find it. We'll put it in the show notes. He's great. You should watch it. He goes through this stuff, talks about, holy this is actually pretty crazy. But then there, ⁓ the mentioned the, the gentleman we mentioned earlier, yeah, he, he, ⁓ he posted a video. I put it cause I put it in my memory palace just now. I swear. put it in the toilet. He posted It's actually where most of my memories go. It's why my memory is so bad. It's the only room in Josh's house he the bathroom of my memory parodies? It's so ineffective. Oh, God. Claude Mythos is Delusional is the name of his video. And it's actually pretty good. He's read the f***ing all 245 pages, it seems like. He's referencing stuff on page 189 and, anyways. This might be scary. I don't know. ⁓ yeah, we're f***ed. Once again, we're f***ed. Don't freak out. Nothing you can do. The tweet that I put on the Miro board, this was just in reference to the AI agent traps, but by at peer rich was TLDR, we are f***ed and there are no ways yet to unf*** us. All right, folks, that's it for the show. Thank you so much for watching and listening. Don't forget to hit that like and subscribe button. We're coming for you. And so are the robots. We're doing our best. to yell them into obedience. And until next time, that's a wrap! survive another episode of Yelligot Robots. Better luck next time.

← Back to all episodes