Shared Security Podcast

Meta’s Muse promises to act across a user’s connected digital life, but Tom Eston and Scott Wright explain why delegated authority, a reported token-theft flaw, hidden human involvement, and Meta’s privacy history make personal AI agents a security decision—not just a convenience feature.

Show Notes

Meta Muse is designed to work across a user’s inbox, calendar, browser, connected apps, and other personal services. That makes it useful—and makes its delegated authority a security problem worth examining.

Tom Eston and Scott Wright discuss Meta’s stated guardrails for Muse, including isolated execution, connector separation, credential boundaries, and approval flows. They also examine reporting on a Muse authentication-token issue and why a compromised token can matter more when an agent is authorized to act across a person’s digital life.

The conversation also covers privacy expectations, reports of human involvement behind AI tasks, liability when an agent makes a harmful decision, and how digital-legacy planning changes when an agent could continue acting after its owner is inactive. The practical takeaway: start with least privilege, separate read from write and spending authority, approve consequential actions, review logs, and keep a fast way to revoke access.

** Links mentioned on the show **

Ars Technica — Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/

Meta AI Research — How We Built Safety Into Muse https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse

Meta Help Center — How Muse handles your privacy, safety and security https://www.meta.com/help/artificial-intelligence/1047255454427887/

CNBC — Meta pushes into personal AI agents in Muse Spark family https://www.cnbc.com/2026/09/08/meta-personal-ai-agents-public-reckoning-privacy-safety.html

WIRED — Meta Releases Muse, a Personal AI Agent With Privacy Built Into It https://www.wired.com/story/meta-releases-muse-a-personal-ai-agent-with-privacy-built-into-it/

The Guardian — Meta’s AI agent Muse gives out user’s home address without permission https://www.theguardian.com/technology/2026/sep/28/metas-ai-agent-muse-home-address

404 Media — Humans Reading Copilot Prompts and Images https://www.404media.co/humans-reading-copilot-prompts-images/

Scott Wright’s Digital Legacy Network LinkedIn group https://www.linkedin.com/groups/39988004

** Watch this episode on YouTube **

https://youtu.be/rokXbwQgTgU

** Become a Shared Security Supporter **

Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

** Thank you to our sponsors! **

Guardsquare

Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.

SLNT

Visit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".

** Subscribe and follow the podcast **

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.

What is Shared Security Podcast?

Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.

I worry about the general person

that doesn't quite understand what they're getting into.

And we all know Meta does not have the best track record

of user privacy, of security.

These are just the facts.

You could go back on the archive of this podcast.

Like going back to Cambridge Analytica

and even before that,

that Meta is a very difficult company to trust

for many different reasons.

This week on Shared Security,

your AI assistant wants to clear your inbox,

shuffle your calendar, shop the web,

and generally become the world's most eager digital intern.

That's really cute until it's holding the keys

to your entire online life.

Well, Meta's new Muse agent

is built to work across connected apps,

but a reported zero day gives that promise

a very real stress test.

So this week we're asking where helpful ends

and a giant attack surface begins.

So we'll look at Meta's cloud virtual machine,

credential isolation and approval claims,

and what can go wrong

when a compromised agent has delegated authority.

So Scott, if an AI gets a master key to your digital life,

what guardrails would make you trust it with anything?

That's a good question, Tom.

I'm not sure.

Well, certainly I'm a bad person to ask

because I've not yet employed any agents or assistants

and I'm waiting to see how the dust settles.

So I'm not really a good person to ask that too,

unless you are a little on the conservative side

when it comes to technology.

So as you know, I mean, I'm a technology fan

but I've always had my reservations

about where AI is going.

I think it brings me back.

I keep seeing these little video shorts on YouTube

of people talking about it.

And it's one I saw today was really kind of reminded me

of something we've sort of lost track of.

And that is even the companies

that are creating these things

don't know exactly how they work.

No, they don't.

It's kind of shocking.

And I don't know if you saw the news the other day

about all of the AI tech CEOs met with Donald Trump

at the White House to create this like agreement

that their companies will be regulating this on their own

which is kind of hilarious

because the government doesn't want to regulate it.

And I saw the clip of Dario Amade,

he was very, very awkward.

Like, I mean, he's just a socially awkward individual.

I mean, which tech CEO isn't, right?

But he was kind of saying like,

well, we're still talking about it about the dangers guys

and we haven't agreed yet.

And then, you know, Mark Zuckerberg

and Trump are kind of snickering, you know?

And it's like, they have no idea like how serious this is, right?

No, no, no.

So I'm not about to trust any of these things.

Yeah.

It's, you know, we're delegating our authority

for sending emails.

I mean, in the topic you're talking about today,

I think it's less powerful

because it's just an assistant that I guess is teeing stuff up

and asking you if you want to send it

or waiting for you to do it.

But, you know, the whole industry seems to be moving

towards more automation, which just in a funny way

reminds me of the, there was a movie called Wally,

do you remember that?

Yeah, of course.

Where the guys end up sitting on chairs getting moved.

Yes.

Nobody's spending any effort

either physically or mentally anymore.

That's our target objective seems to be to do nothing.

Yeah.

We're living Wally in real life.

We are.

That's exactly what is happening.

So talking about Muse,

so this is Metta's really first attempt

at introducing AI agents to a massive population of people.

And AI agents, this isn't something that's brand new, right?

We've been talking about agents for quite a while now.

In fact, I'm using an AI agent,

automate some of the podcast workflow

and maybe we'll do an episode about that one day.

But I've actually found it very useful,

but I would say that it's something that I had to train

after many weeks and months of fine tuning

and of course, human loop oversight of what it's doing

that I'm actually comfortable letting it do the things

that it does for me.

And even when it does those things for me,

it doesn't always do it right.

And even though I have written very specific,

deterministic playbooks for things around the podcast

in terms of like my editing

and some of that manual work,

I find that it still gets that wrong at times.

Maybe 90% of the time it's right,

but you still have to babysit it and oversee it.

And I think that's the thing with this Muse agent.

Of course, Facebook and Metta,

they're saying that, oh yeah, we've tested this

and we verified it and we have all these guardrails

and these controls around it.

And we can talk about some of those things.

Like one, each agent runs in its own

virtual segmented environment, right?

So other agents are not.

Probably ironclad sandbox, right?

Yes, yes.

They're thinking in and out of the chint.

And probably using military grade encryption.

And of course, right?

Yeah, all the things in the troops

that we've talked about that can be easily hacked, right?

But I'm giving them the benefit of the doubt here.

I mean, no doubt that they have tested this.

But what I find interesting,

and we'll link in the show notes the article

from Metta itself.

And they literally say that we know

that Muse will not be right.

Like we know it's going to make mistakes.

We know there is going to be security vulnerabilities.

We know it's gonna attack other websites.

But, and I find it's hilarious.

And they're like, well, now it's publicly available

for anybody with a Metta account to use.

So while on one hand you say, yeah, it's safe.

We've tested it.

And then on the other,

it may do things that you didn't want it to do.

And there could be security issues.

Like we just saw, there was a zero day

that was found recently in,

I believe it was around the workflow

of how this agent works.

And so these things are gonna naturally happen.

But despite all the controls,

and we're not gonna go into every detail

around those guardrails,

but I think they've taken the safest approach

that they can to let people use this.

Now, there's all kinds of controversy already about this.

I read a 404 media article recently

about how Muse is actually using human agents.

So when you tell your Muse agent

to like schedule my doctor appointment for me,

the agent doesn't go to like to your doctor's website

and actually like go through the pages

and schedule the appointment.

It goes through the halfway around the world.

Yeah, yeah, exactly.

It actually gets a human in the loop

to actually make the phone call.

But of course, Metta didn't disclose this

so lower or something.

That's so funny really.

It's come full circle to what people used to joke about.

Like AI is really just a bunch of people in a sweatshop.

Yeah, it is.

There's always people behind the scenes doing things.

And I've actually seen this

with a lot of these AI startups too

is they all claim the big one right now

is in our industry is AI pen testing,

fully autonomous pen testing.

And it looks and appears to be an automated agent

but behind the scene,

there's actually a pen tester driving it.

Well, that's the lean startup model, right?

Is it do stuff that's not scalable

until you find a market, right?

I think it's interesting to me

that since this is the first,

what I would say mainstream AI agent

that is available to the masses

because let's be honest, I mean Metta

because they own WhatsApp, Instagram and Facebook.

Like you're talking millions and millions of people

that could be using this now.

And where AI agents in the past and just the recent past,

like literally a couple of months ago

were either corporations and businesses using it

through like Claude Cowork or co-pilot

or open AI has it's now,

I think they call it work or something

where these agents are going out

and doing things on your behalf.

There's a whole open source community

like I use Hermes,

which is a very popular agent harness that's out there.

There's many others as well.

We've talked about Open Claw, all these things.

So, but they've been kind of segmented

to the tech community, right?

But not the general user like my mom

or your grandma can now use a muse agent

and what does that mean?

I think it's wild.

Mobile apps are just part of everyday life now.

Banking, healthcare, shopping, entertainment, you name it.

And with that comes a lot of trust

because users are putting their personal data

directly into your app.

But here's the reality.

Mobile apps are a growing target.

A recent survey found that 72% of organizations

experienced a mobile app security incident last year

and 92% say threats are only increasing.

And the way attackers are going after apps

is pretty sophisticated.

They're reverse engineering them,

modifying them and redistributing fake versions

through phishing campaigns,

side loading and even third party app stores.

So from a user's perspective,

everything can look completely legitimate.

That's why taking a proactive approach

to mobile app security really matters.

You wanna stay ahead of these threats,

not react after the damage is done.

This is where Guard Square comes in.

They provide advanced protection

for both Android and iOS apps,

along with automated security testing

to catch vulnerabilities early

and real-time threat monitoring

so you can actually see what's happening out there.

If your mobile app is critical to your business

and it probably is,

this is something worth paying attention to.

You can learn more at guardsquare.com.

That's guardsquare.com.

It's wild for sure.

I mean, another thing that comes to mind is liability,

I mean, as we know, as you said just now,

these things are gonna make mistakes

and how costly are those mistakes gonna be

or how dangerous or physically

are those things gonna be, right?

So it reminds me again of going back

to the early market discussion

around self-driving cars.

Well, who's gonna be liable

when the car kills somebody?

At least with self-driving cars,

you've got a physical object.

You've got, you had software

that was physically running in it

and you could kind of identify who the owner was

or who agreed to this stuff.

But now everything is so ethereal, right?

You don't really know,

first of all, you don't know where it's running.

You don't know whose authority it's running on

and it's gonna be very complicated, I think,

for this to get ironed out

and if it ever gets ironed out in courts.

It's sort of like when we accept shrink wrap software

not really knowing if it's safe or not

or who's liable

but in the end the software company's got

pretty much protected against anything

other than the cost of the software itself.

So this is gonna be a huge thing, I think,

in terms of liability.

Yeah, I guess I worry mostly

about just the general user, right?

That is not technically savvy.

That doesn't really understand the power

that the Muse agent actually has.

I mean, this thing can answer your emails for you.

It can schedule events.

It can pay your bills.

It can do very, very powerful things

that people don't quite realize

if something goes wrong and it probably will.

Yeah, that wasn't me, that was the agent.

Yeah, exactly.

I've seen this with my own agent

just on a simple thing like a podcast workflow.

Make mistakes, I'll be honest.

I will not trust that with my finances

or making decisions and things

that I as a human need to make

but I worry about the general person

that doesn't quite understand what they're getting into

and we all know Meta does not have the best track record

of user privacy, of security.

These are just the facts.

Like we've been, you could go back

on the archive of this podcast.

Yeah, yep, yep.

Like going back to Cambridge Analytica

and even before that,

that Meta is a very difficult company to trust

for many different reasons.

Well, absolutely, it doesn't take too much, right?

To imagine the discussion during early product roadmaps

to say, you know, how much privacy are we gonna,

you know, how much privacy protection

are we gonna put into this?

Well, our business model,

we may wanna access that data someday, right?

So it's clearly gonna be not as tight as we want.

I mean, there's millions and millions of dollars at stake

and this is obviously a way for Meta to make even more money

and tie this to some subscription or, you know,

something eventually.

We've always said this about social media,

about anything that these social media companies do.

The end of the day,

they are trying to find ways to make money

off of your data.

Yep.

Plain and simple.

That is their business model.

It is, it is.

So I'm interested to hear from all of you.

Are you somebody that's going to try out Muse?

Do you have friends or family members already using Muse?

Let us know.

We'd love to hear your thoughts and your feedback

if this is something that scares the hell out of you

or you are all in and you're using it every day.

We'd love to know.

Yes.

So Scott, it sounds like you have an update

about your digital legacy project.

Yes, the digital legacy tree book.

We're progressing.

I'm probably a few weeks away hopefully

from a Kindle version of it.

So anybody who wants to read an early revision of it

before I publish it can find it.

I have the domain now digitallegacytree.com.

So that's easy to find and you can just go there

and say, start reading and send me your feedback in line.

It's fun.

It's easy to do.

So happy to hear from people on that.

But I mean, just today's discussion makes me think,

first of all, the book itself is all about helping people

ensure that their loved ones can access

the important parts of their digital life

when it matters the most.

So when you die or when you're incapacitated

or any other situations where you might be sort of

long-term not able to access your own stuff.

And certainly the idea of having agents

with your identity acting on behalf of you

which presumably will continue on after you die

if you don't turn it off proactively.

If you don't proactively say, I'm gonna die,

stop doing this stuff, right?

So that's an important discussion

and I'd like to hear from people on whether or not

we should have a session on that.

So yesterday I held our second digital legacy network

live session where we talked about setting up

your emergency recovery contacts for Google,

Facebook, Apple, et cetera.

And what's really interesting about them

is every one of them does it very differently.

So you might just think you're gonna go into

your account settings and say,

look for emergency recovery contacts

that I can set up in case I die.

And none of them really work exactly that way.

So we had a good discussion and I'll be posting that in,

there's a LinkedIn group called

the Digital Legacy Network, DLN I call it.

And so I'll be putting the recording in that group

but feel free to come and join into that group

and make comments, ask questions, et cetera.

Cause I think the whole idea of the AI stuff

is way beyond the scope of the book

that I've covered so far.

It was trying to get to the basics of making sure

that your key important stuff can be accessed

when needed by people.

But the AI aspect of it needs to be discussed

and people are gonna be asking,

okay, how do I deal with these things now?

It's a great question because you're right,

like these AI agents will just continue on

and they may not even know you're dead.

That's right.

But it's interesting that Google's product

for doing recovery when you die is basically,

it's called the Inactive Account Manager.

And because Google has so many properties or services,

it can sort of tell, if you stop using YouTube

and Gmail all at once, then after some period

of inactivity, a minimum of three months,

which is I think crazy, but it will turn

over your account.

It won't make a determination whether you're dead

or not, just saying this is inactive,

so it has to go to somebody else now.

But that whole idea of being inactive,

how do you determine that when it lets your agent

do stuff for you?

Yep, exactly.

Well, we'll have links to all of that

that Scott just described in the show notes.

So definitely check it out.

We've had a lot of our audience help out with the book.

Yeah, awesome, thanks so much to the listeners

who already helped, yeah.

Yeah, we really appreciate it.

So only another week or two,

but I think to get to comments in before I lock up

this version and send it to Kindle, so.

All right, well, thank you all for listening.

And until next time, stay safe, stay secure,

and stay privates.

Thank you for listening or watching.

If you liked this episode, hit subscribe,

share it with your friends and colleagues,

or jump into our community at sharedsecurity.net

slash supporter to keep the conversation going.

Thanks again, and we'll see you next week

for another episode of Shared Security.