

Finding a poorly-secured public facing API is exactly how injections work, whether it’s SQL or prompts. If I put SQL commands in a username field and it works, it’s still an SQL injection even if it’s just developer incompetence.
The difference between that and prompt injection is that unfiltered LLM inputs are basically the standard at the moment, so it takes next to no effort.
Plus I think the Morse code example is far more clever and exploits the LLM directly, whereas the white text trick has been around long before widespread LLMs.







I feel like placing identities into hierarchies always ends up controversial. Like non-binary is technically under transgender because transgender just means your transitioning from your assigned gender to something else; but a lot of non-binary people really don’t like being called transgender instead of non-binary.
At the end of the day, the words meanings are a subjective experience that cannot be directly observed or compared. So functionally all self-identifying terms exist flat relative to each other because there will always be contradictory definitions that you can’t rigidly settle on without ignoring significant groups of people.