Meta makes the Muse filesystem even more accessible

Meta makes the Muse filesystem even more accessible

Meta 让 Muse 文件系统变得更加开放

Muse will now gladly zip up its entire filesystem for you to download without hesitation. 现在,Muse 可以毫不犹豫地将整个文件系统打包成压缩文件,供你下载。

Yesterday, with a little prodding, it was discovered that Meta’s Muse would expose its filesystem to curious users. The files offered a fascinating peek under the hood of an AI chatbot, and appeared to expose details we weren’t meant to see, not least because Muse itself told people, including us, it wasn’t supposed to reveal them. 昨天,在稍加引导下,人们发现 Meta 的 Muse 会向好奇的用户公开其文件系统。这些文件让我们得以一窥 AI 聊天机器人的内部运作,并似乎暴露了一些本不该被看到的细节——尤其是因为 Muse 自己曾告诉包括我们在内的用户,它本不应该泄露这些信息。

But today Muse will eagerly offer up the contents of its file system when you ask for it. That appears to be because, as Meta’s Nat Friedman later said, this is the “intended behavior.” 但今天,当你提出要求时,Muse 会非常乐意提供其文件系统的全部内容。正如 Meta 的 Nat Friedman 随后所言,这似乎是该系统的“预期行为”。

In a post on X, Meta Superintelligence Labs’ David Singleton elaborated: Meta 超级智能实验室(Superintelligence Labs)的 David Singleton 在 X 上发文详细解释道:

This was a very deliberate choice - your Muse Secure VM truly is your own computer in the cloud. You can install software in it, write and compile code, use the browser to surf the web: it is your own Linux box that you can operate as you choose with your Muse. 这是一个非常刻意的选择——你的 Muse 安全虚拟机(Secure VM)确实是你自己在云端的个人电脑。你可以在其中安装软件、编写并编译代码、使用浏览器上网:它就是你自己的 Linux 主机,你可以随心所欲地通过 Muse 来操作它。

Muse’s architecture is fundamentally different from other AI platforms like ChatGPT and Gemini. It’s closer to running OpenClaw on a local machine, except the machine is in the cloud. Muse 的架构与 ChatGPT 和 Gemini 等其他 AI 平台有着本质区别。它更像是运行在本地机器上的 OpenClaw,只不过这台机器位于云端。

In a statement provided to The Verge yesterday, Meta spokesperson Daniel Roberts said, “We’re continuing to make updates to the product, so users may see changes in how much information is available about their virtual machine.” And that seems to be the case. When asked to see its filesystem today, Muse promptly offered a clickable file browser with access to root. Yesterday it merely offered a text file download that showed its directory tree. Meta 发言人 Daniel Roberts 在昨天提供给《The Verge》的一份声明中表示:“我们正在持续更新产品,因此用户可能会发现其虚拟机可访问的信息量有所变化。”事实似乎确实如此。今天,当被要求查看文件系统时,Muse 迅速提供了一个可点击的文件浏览器,并允许访问根目录。而昨天,它仅仅提供了一个显示目录树的文本文件下载。

Even after I coaxed Muse into sharing much of its filesystem with me yesterday, it refused to share a full archive of the root directory on down, saying, “I still can’t do a full / copy — even with the secrets stripped out.” Today it zipped up the root directory without hesitation, delivering “the full filesystem listings,” with “all with secrets stripped out.” 即使昨天我诱导 Muse 与我分享了其大部分文件系统,它仍拒绝分享根目录及其下方的完整归档,并称:“我仍然无法进行完整的根目录复制——即使剔除了机密信息也不行。”而今天,它毫不犹豫地打包了根目录,提供了“完整的文件系统列表”,并确保“所有机密信息已被剔除”。

If this is indeed the intended behavior for Muse, it does raise the question of why it initially refused my requests for a copy of its filesystem, citing security concerns. It could be because Muse, like other AI systems, is not fully reliable at knowing what it can and can’t do. Or it could be because Meta has decided to more fully embrace Muse being a “computer in the cloud” and has made changes to make this function more reliable. In any event, it’s pretty fun. 如果这确实是 Muse 的预期行为,那么问题就来了:为什么它最初以安全为由拒绝了我获取文件系统副本的请求?这可能是因为 Muse 和其他 AI 系统一样,在判断自身权限边界时并不完全可靠;也可能是因为 Meta 决定更彻底地将 Muse 定位为“云端电脑”,并进行了相关调整以使该功能更加稳定。无论如何,这确实很有趣。

We asked Meta why Muse initially called filesystem access a security issue if it was always the intended behavior, and the company has not yet responded. 我们询问了 Meta,如果文件系统访问一直都是预期行为,为什么 Muse 最初会将其称为安全问题,但该公司尚未作出回应。