Discussion about this post

User's avatar
GH's avatar

Security with LLMs is a category error.

Cyril Simonnet's avatar

The "Open Sesame" framing nails it. Browser agents don't break authentication, they sidestep it entirely by riding on sessions users already opened. That's the core problem most security teams haven't internalized yet: the threat model changed the moment we gave an AI full DOM access inside an authenticated context. I wrote about this exact blind spot in "We Put AI in the Browser Before We Secured It," arguing that the industry shipped agent capabilities first and is now retrofitting security as an afterthought. The session inheritance risk you describe is one of the clearest examples of why that ordering was a mistake.

https://cyrilsimonnet.substack.com/p/we-put-ai-in-the-browser-before-we

No posts

Ready for more?