Live data from Hacker News

xAI dev leaks API key for private SpaceX, Tesla LLMs

krebsonsecurity.com

11–20 of 83 posts

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#13

[flagged]

Turns out it's a different Krebs. This is by Brian Krebs, vs Chris Krebs was the one targeted by the administration.

Wow, I have been following the Chris Krebs saga quite closely AND been an avid consumer of Krebs on Security and for whatever reason always assumed they were one and the same. I even know his name is Brian Krebs! It's humbling when you're confronted with your blinders and stupidity, and they are the same as those you rail against for being so blindly stupid...

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#14

What absolute incompetence. Not just on this dev, but any org with API keys ought to be scanning for leaked keys constantly. Failure of one and failure of many. Of course Elon hires only based on 'merit'...

How would you scan for your api keys on repos outside of your organization? I assumed this was a dev’s personal repo.

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#15

What absolute incompetence. Not just on this dev, but any org with API keys ought to be scanning for leaked keys constantly. Failure of one and failure of many. Of course Elon hires only based on 'merit'...

How would you scan for your api keys on repos outside of your organization? I assumed this was a dev’s personal repo.

https://docs.github.com/en/code-security/secret-scanning/sec... is one option

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#17
> Fourrier found GitGuardian had alerted the xAI employee about the exposed API key nearly two months ago — on March 2. But as of April 30, when GitGuardian directly alerted xAI’s security team to the exposure, the key was still valid and usable. xAI told GitGuardian to report the matter through its bug bounty program at HackerOne, but just a few hours later the repository containing the API key was removed from GitHub.

Having the security team redirect the report to the HackerOne program is wild.

At least someone had enough thought to eventually forward it to someone who could fix it.

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#20
post #3

Musk has been talking about integrating Grok into Tesla cars and also adding a lot of space and rocketry specific training. It is completely possible that these models were trained on data that would logically be public at some point. It is also possible that the author's guess is right and that these were to contain sensitive data. Noone really knows, but honestly, these kinds of mistakes are happening all the time.…

I only use private repos, so that when my .ssh and .env leaks the public doesn’t see it. Probably. Maybe. Well…
Post reply on HN