Dismissing the opportunity to learn because the person offering you knowledge is enthusiastic about his area of expertise is probably shortsighted.
I’m not intending to be dismissive, just noticing a pattern and advocating a bit of skepticism.
Hearing a programming legend weigh in on the latest programming tool seems entirely completely reasonable.
That's pretty negative! https://simonwillison.net/series/prompt-injection/
There's a whole section in the linked piece about how Cowork doesn't do enough here, including:
> I do not think it is fair to tell regular non-programmer users to watch out for “suspicious actions that may indicate prompt injection”
> This isn’t just an interesting academic trick: it’s a form of security exploit. I propose that the obvious name for this should be prompt injection.
I've written about it 142 times since then: https://simonwillison.net/tags/prompt-injection/
I'm credited for coining the term on Wikipedia and in several academic papers.
I don't claim to have discovered the vulnerability - I credited that to Riley Goodside, but we later learned it was independently discovered and first reported to OpenAI by Jonathan Cefalu of Preamble, see https://www.preamble.com/prompt-injection-a-critical-vulnera...
The people you should be skeptical of are the random Xitter handles who post about a robotic phlebotomists and say "THE FUTUE IS ALREADY HERE".
Example: The decade+ of people worshipping at Musk’s feet only for him to reveal himself as a malignant narcissist.