[HN Gopher] Exposed DeepSeek database leaking sensitive informat...
___________________________________________________________________
Exposed DeepSeek database leaking sensitive information, including
chat history
Author : talhof8
Score : 61 points
Date : 2025-01-29 21:25 UTC (1 hours ago)
(HTM) web link (www.wiz.io)
(TXT) w3m dump (www.wiz.io)
| NathanKP wrote:
| And that's why you run models locally. Or if you want a remote
| chat model, use something stateless like AWS Bedrock custom model
| import to avoid having stored chats on the server.
| rvz wrote:
| > More critically, the exposure allowed for full database control
| and potential privilege escalation within the DeepSeek
| environment, without any authentication or defense mechanism to
| the outside world.
|
| Not only that, this was a "production-grade" database with
| millions of users using it and the app was #1 on the app store
| and ALL text sent there in the prompts was logged in plain-text?
|
| Unbelievable.
| byearthithatius wrote:
| I agree this is really bad but far from unbelievable. I am only
| 23 and already my SSN and even my freaking DNA have both been
| leaked by major publicly traded companies.
| hdlothia wrote:
| This kinda does support the 'DeepSeek is the side project of a
| bunch of quants' angle.
|
| Seems like the kind of mistake you would make if you are not used
| to deploying external client facing applications.
| nico wrote:
| So much effort in trying to tarnish DeepSeek the last 24hrs
| mandmandam wrote:
| Yep.
|
| Kinda like how your comment was grey within 1 minute, despite
| stating an objective truth.
|
| Sure, this is to be expected given the billions and billions of
| dollars at stake but like - that money is gone lol. DeepSeek
| isn't going back in the bottle, nor is open source AI in
| general.
| tomlockwood wrote:
| This doesn't look like a responsible disclosure, at all.
___________________________________________________________________
(page generated 2025-01-29 23:00 UTC)