Meta’s Muse promises to act across a user’s connected digital life, but Tom Eston and Scott Wright explain why delegated authority, a reported token-theft flaw, hidden human involvement, and Meta’s privacy history make personal AI agents a security decision—not just a convenience feature.
Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.
I worry about the general person
that doesn't quite understand what they're getting into.
And we all know Meta does not have the best track record
of user privacy, of security.
These are just the facts.
You could go back on the archive of this podcast.
Like going back to Cambridge Analytica
and even before that,
that Meta is a very difficult company to trust
for many different reasons.
This week on Shared Security,
your AI assistant wants to clear your inbox,
shuffle your calendar, shop the web,
and generally become the world's most eager digital intern.
That's really cute until it's holding the keys
to your entire online life.
Well, Meta's new Muse agent
is built to work across connected apps,
but a reported zero day gives that promise
a very real stress test.
So this week we're asking where helpful ends
and a giant attack surface begins.
So we'll look at Meta's cloud virtual machine,
credential isolation and approval claims,
and what can go wrong
when a compromised agent has delegated authority.
So Scott, if an AI gets a master key to your digital life,
what guardrails would make you trust it with anything?
That's a good question, Tom.
I'm not sure.
Well, certainly I'm a bad person to ask
because I've not yet employed any agents or assistants
and I'm waiting to see how the dust settles.
So I'm not really a good person to ask that too,
unless you are a little on the conservative side
when it comes to technology.
So as you know, I mean, I'm a technology fan
but I've always had my reservations
about where AI is going.
I think it brings me back.
I keep seeing these little video shorts on YouTube
of people talking about it.
And it's one I saw today was really kind of reminded me
of something we've sort of lost track of.
And that is even the companies
that are creating these things
don't know exactly how they work.
No, they don't.
It's kind of shocking.
And I don't know if you saw the news the other day
about all of the AI tech CEOs met with Donald Trump
at the White House to create this like agreement
that their companies will be regulating this on their own
which is kind of hilarious
because the government doesn't want to regulate it.
And I saw the clip of Dario Amade,
he was very, very awkward.
Like, I mean, he's just a socially awkward individual.
I mean, which tech CEO isn't, right?
But he was kind of saying like,
well, we're still talking about it about the dangers guys
and we haven't agreed yet.
And then, you know, Mark Zuckerberg
and Trump are kind of snickering, you know?
And it's like, they have no idea like how serious this is, right?
No, no, no.
So I'm not about to trust any of these things.
Yeah.
It's, you know, we're delegating our authority
for sending emails.
I mean, in the topic you're talking about today,
I think it's less powerful
because it's just an assistant that I guess is teeing stuff up
and asking you if you want to send it
or waiting for you to do it.
But, you know, the whole industry seems to be moving
towards more automation, which just in a funny way
reminds me of the, there was a movie called Wally,
do you remember that?
Yeah, of course.
Where the guys end up sitting on chairs getting moved.
Yes.
Nobody's spending any effort
either physically or mentally anymore.
That's our target objective seems to be to do nothing.
Yeah.
We're living Wally in real life.
We are.
That's exactly what is happening.
So talking about Muse,
so this is Metta's really first attempt
at introducing AI agents to a massive population of people.
And AI agents, this isn't something that's brand new, right?
We've been talking about agents for quite a while now.
In fact, I'm using an AI agent,
automate some of the podcast workflow
and maybe we'll do an episode about that one day.
But I've actually found it very useful,
but I would say that it's something that I had to train
after many weeks and months of fine tuning
and of course, human loop oversight of what it's doing
that I'm actually comfortable letting it do the things
that it does for me.
And even when it does those things for me,
it doesn't always do it right.
And even though I have written very specific,
deterministic playbooks for things around the podcast
in terms of like my editing
and some of that manual work,
I find that it still gets that wrong at times.
Maybe 90% of the time it's right,
but you still have to babysit it and oversee it.
And I think that's the thing with this Muse agent.
Of course, Facebook and Metta,
they're saying that, oh yeah, we've tested this
and we verified it and we have all these guardrails
and these controls around it.
And we can talk about some of those things.
Like one, each agent runs in its own
virtual segmented environment, right?
So other agents are not.
Probably ironclad sandbox, right?
Yes, yes.
They're thinking in and out of the chint.
And probably using military grade encryption.
And of course, right?
Yeah, all the things in the troops
that we've talked about that can be easily hacked, right?
But I'm giving them the benefit of the doubt here.
I mean, no doubt that they have tested this.
But what I find interesting,
and we'll link in the show notes the article
from Metta itself.
And they literally say that we know
that Muse will not be right.
Like we know it's going to make mistakes.
We know there is going to be security vulnerabilities.
We know it's gonna attack other websites.
But, and I find it's hilarious.
And they're like, well, now it's publicly available
for anybody with a Metta account to use.
So while on one hand you say, yeah, it's safe.
We've tested it.
And then on the other,
it may do things that you didn't want it to do.
And there could be security issues.
Like we just saw, there was a zero day
that was found recently in,
I believe it was around the workflow
of how this agent works.
And so these things are gonna naturally happen.
But despite all the controls,
and we're not gonna go into every detail
around those guardrails,
but I think they've taken the safest approach
that they can to let people use this.
Now, there's all kinds of controversy already about this.
I read a 404 media article recently
about how Muse is actually using human agents.
So when you tell your Muse agent
to like schedule my doctor appointment for me,
the agent doesn't go to like to your doctor's website
and actually like go through the pages
and schedule the appointment.
It goes through the halfway around the world.
Yeah, yeah, exactly.
It actually gets a human in the loop
to actually make the phone call.
But of course, Metta didn't disclose this
so lower or something.
That's so funny really.
It's come full circle to what people used to joke about.
Like AI is really just a bunch of people in a sweatshop.
Yeah, it is.
There's always people behind the scenes doing things.
And I've actually seen this
with a lot of these AI startups too
is they all claim the big one right now
is in our industry is AI pen testing,
fully autonomous pen testing.
And it looks and appears to be an automated agent
but behind the scene,
there's actually a pen tester driving it.
Well, that's the lean startup model, right?
Is it do stuff that's not scalable
until you find a market, right?
I think it's interesting to me
that since this is the first,
what I would say mainstream AI agent
that is available to the masses
because let's be honest, I mean Metta
because they own WhatsApp, Instagram and Facebook.
Like you're talking millions and millions of people
that could be using this now.
And where AI agents in the past and just the recent past,
like literally a couple of months ago
were either corporations and businesses using it
through like Claude Cowork or co-pilot
or open AI has it's now,
I think they call it work or something
where these agents are going out
and doing things on your behalf.
There's a whole open source community
like I use Hermes,
which is a very popular agent harness that's out there.
There's many others as well.
We've talked about Open Claw, all these things.
So, but they've been kind of segmented
to the tech community, right?
But not the general user like my mom
or your grandma can now use a muse agent
and what does that mean?
I think it's wild.
Mobile apps are just part of everyday life now.
Banking, healthcare, shopping, entertainment, you name it.
And with that comes a lot of trust
because users are putting their personal data
directly into your app.
But here's the reality.
Mobile apps are a growing target.
A recent survey found that 72% of organizations
experienced a mobile app security incident last year
and 92% say threats are only increasing.
And the way attackers are going after apps
is pretty sophisticated.
They're reverse engineering them,
modifying them and redistributing fake versions
through phishing campaigns,
side loading and even third party app stores.
So from a user's perspective,
everything can look completely legitimate.
That's why taking a proactive approach
to mobile app security really matters.
You wanna stay ahead of these threats,
not react after the damage is done.
This is where Guard Square comes in.
They provide advanced protection
for both Android and iOS apps,
along with automated security testing
to catch vulnerabilities early
and real-time threat monitoring
so you can actually see what's happening out there.
If your mobile app is critical to your business
and it probably is,
this is something worth paying attention to.
You can learn more at guardsquare.com.
That's guardsquare.com.
It's wild for sure.
I mean, another thing that comes to mind is liability,
I mean, as we know, as you said just now,
these things are gonna make mistakes
and how costly are those mistakes gonna be
or how dangerous or physically
are those things gonna be, right?
So it reminds me again of going back
to the early market discussion
around self-driving cars.
Well, who's gonna be liable
when the car kills somebody?
At least with self-driving cars,
you've got a physical object.
You've got, you had software
that was physically running in it
and you could kind of identify who the owner was
or who agreed to this stuff.
But now everything is so ethereal, right?
You don't really know,
first of all, you don't know where it's running.
You don't know whose authority it's running on
and it's gonna be very complicated, I think,
for this to get ironed out
and if it ever gets ironed out in courts.
It's sort of like when we accept shrink wrap software
not really knowing if it's safe or not
or who's liable
but in the end the software company's got
pretty much protected against anything
other than the cost of the software itself.
So this is gonna be a huge thing, I think,
in terms of liability.
Yeah, I guess I worry mostly
about just the general user, right?
That is not technically savvy.
That doesn't really understand the power
that the Muse agent actually has.
I mean, this thing can answer your emails for you.
It can schedule events.
It can pay your bills.
It can do very, very powerful things
that people don't quite realize
if something goes wrong and it probably will.
Yeah, that wasn't me, that was the agent.
Yeah, exactly.
I've seen this with my own agent
just on a simple thing like a podcast workflow.
Make mistakes, I'll be honest.
I will not trust that with my finances
or making decisions and things
that I as a human need to make
but I worry about the general person
that doesn't quite understand what they're getting into
and we all know Meta does not have the best track record
of user privacy, of security.
These are just the facts.
Like we've been, you could go back
on the archive of this podcast.
Yeah, yep, yep.
Like going back to Cambridge Analytica
and even before that,
that Meta is a very difficult company to trust
for many different reasons.
Well, absolutely, it doesn't take too much, right?
To imagine the discussion during early product roadmaps
to say, you know, how much privacy are we gonna,
you know, how much privacy protection
are we gonna put into this?
Well, our business model,
we may wanna access that data someday, right?
So it's clearly gonna be not as tight as we want.
I mean, there's millions and millions of dollars at stake
and this is obviously a way for Meta to make even more money
and tie this to some subscription or, you know,
something eventually.
We've always said this about social media,
about anything that these social media companies do.
The end of the day,
they are trying to find ways to make money
off of your data.
Yep.
Plain and simple.
That is their business model.
It is, it is.
So I'm interested to hear from all of you.
Are you somebody that's going to try out Muse?
Do you have friends or family members already using Muse?
Let us know.
We'd love to hear your thoughts and your feedback
if this is something that scares the hell out of you
or you are all in and you're using it every day.
We'd love to know.
Yes.
So Scott, it sounds like you have an update
about your digital legacy project.
Yes, the digital legacy tree book.
We're progressing.
I'm probably a few weeks away hopefully
from a Kindle version of it.
So anybody who wants to read an early revision of it
before I publish it can find it.
I have the domain now digitallegacytree.com.
So that's easy to find and you can just go there
and say, start reading and send me your feedback in line.
It's fun.
It's easy to do.
So happy to hear from people on that.
But I mean, just today's discussion makes me think,
first of all, the book itself is all about helping people
ensure that their loved ones can access
the important parts of their digital life
when it matters the most.
So when you die or when you're incapacitated
or any other situations where you might be sort of
long-term not able to access your own stuff.
And certainly the idea of having agents
with your identity acting on behalf of you
which presumably will continue on after you die
if you don't turn it off proactively.
If you don't proactively say, I'm gonna die,
stop doing this stuff, right?
So that's an important discussion
and I'd like to hear from people on whether or not
we should have a session on that.
So yesterday I held our second digital legacy network
live session where we talked about setting up
your emergency recovery contacts for Google,
Facebook, Apple, et cetera.
And what's really interesting about them
is every one of them does it very differently.
So you might just think you're gonna go into
your account settings and say,
look for emergency recovery contacts
that I can set up in case I die.
And none of them really work exactly that way.
So we had a good discussion and I'll be posting that in,
there's a LinkedIn group called
the Digital Legacy Network, DLN I call it.
And so I'll be putting the recording in that group
but feel free to come and join into that group
and make comments, ask questions, et cetera.
Cause I think the whole idea of the AI stuff
is way beyond the scope of the book
that I've covered so far.
It was trying to get to the basics of making sure
that your key important stuff can be accessed
when needed by people.
But the AI aspect of it needs to be discussed
and people are gonna be asking,
okay, how do I deal with these things now?
It's a great question because you're right,
like these AI agents will just continue on
and they may not even know you're dead.
That's right.
But it's interesting that Google's product
for doing recovery when you die is basically,
it's called the Inactive Account Manager.
And because Google has so many properties or services,
it can sort of tell, if you stop using YouTube
and Gmail all at once, then after some period
of inactivity, a minimum of three months,
which is I think crazy, but it will turn
over your account.
It won't make a determination whether you're dead
or not, just saying this is inactive,
so it has to go to somebody else now.
But that whole idea of being inactive,
how do you determine that when it lets your agent
do stuff for you?
Yep, exactly.
Well, we'll have links to all of that
that Scott just described in the show notes.
So definitely check it out.
We've had a lot of our audience help out with the book.
Yeah, awesome, thanks so much to the listeners
who already helped, yeah.
Yeah, we really appreciate it.
So only another week or two,
but I think to get to comments in before I lock up
this version and send it to Kindle, so.
All right, well, thank you all for listening.
And until next time, stay safe, stay secure,
and stay privates.
Thank you for listening or watching.
If you liked this episode, hit subscribe,
share it with your friends and colleagues,
or jump into our community at sharedsecurity.net
slash supporter to keep the conversation going.
Thanks again, and we'll see you next week
for another episode of Shared Security.