SN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist
Security Now (Audio)August 26, 2026
1093
2:48:10154.23 MB

SN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist

Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are.

  • Understanding the controversy surrounding "AI Model Distillation"
  • Anthropic moves to make their most powerful Mythos 5 model more widely available.
  • Bitwarden's "Secrets Manager" offering prevents agentic and prompt injection abuse.
  • The astounding and disturbing truth about the way conversation AI actually works

Show Notes - https://www.grc.com/sn/SN-1093-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:

Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are.

  • Understanding the controversy surrounding "AI Model Distillation"
  • Anthropic moves to make their most powerful Mythos 5 model more widely available.
  • Bitwarden's "Secrets Manager" offering prevents agentic and prompt injection abuse.
  • The astounding and disturbing truth about the way conversation AI actually works

Show Notes - https://www.grc.com/sn/SN-1093-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:

AI security, large language models, prompt injection, role confusion, LLM vulnerabilities, neural networks, AI distillation, model training, Anthropic Claude Mythos 5, Bitwarden Secrets Manager, open source security, system prompt tags,