Live data from Hacker News

xAI dev leaks API key for private SpaceX, Tesla LLMs

krebsonsecurity.com

41–50 of 83 posts

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#41
post #21

Earlier quoted context omitted.

I only use private repos, so that when my .ssh and .env leaks the public doesn’t see it. Probably. Maybe. Well…

Just remember to go through your commit history if you ever plan on making that repo public.

I commonly flatten repos (by copy and create) when I share them. Its rare that the other person needs the commit history.

I have often thought it would be nice to have a good tool to retroactively view and tidy them, but everything I've seen has not quite hit the nail on the head.

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#42
post #19
post #11

SpaceX data LLM being exposed is likely a recipe for a huge ITAR violation

Is ITAR like other compliance sort of fields where you have to store data only in compliant places, or is it just based on actual leaks etc.,?

ITAR (International Trafficking in Arms Regulation) is paranoid. Every single specific person that knows even dual-use information, such as composite wing design, must be individually authorized. I’ve been asked to leave the room when my girlfriend, who works for a passenger aircraft manufacturer, was designing a repair for a plane I have literally flew on.

It doesn’t matter how the person got access to dual-use info, like basically everything to do with large rockets, it’s 100% forbidden.

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#44
post #19

Earlier quoted context omitted.

Is ITAR like other compliance sort of fields where you have to store data only in compliant places, or is it just based on actual leaks etc.,?

ITAR (International Trafficking in Arms Regulation) is paranoid . Every single specific person that knows even dual-use information, such as composite wing design, must be individually authorized. I’ve been asked to leave the room when my girlfriend, who works for a passenger aircraft manufacturer, was designing a repair for a plane I have literally flew on. It doesn’t matter how the person got access to dual-use inf…

This seems like a company policy more than ITAR. Unless you are not a US citizen, then it could be ITAR.

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#45
post #38

Earlier quoted context omitted.

> Guess who's going to be fired by elon :D i know, you probably just meant it as a fun comment. but i don't get how this is funny. this person probably relies on income, might have a family to feed... and just made a mistake. a type of mistake, that is not uncommon. i mean i have seen corporate projects where senior engineers didn't even understand why committing secrets might be a bad idea. yes, of course, as a engi…

> if this person is actually good at their job and takes it seriously, it's certain: he or she is not going to leak a secret again If they were good at their job, they wouldn't have leaked the secret in the first place. The correct workflow is to: 1. Create commits that only change do one thing. Not possible to "forget" there were secrets added alongside another feature. 2. When adding secrets, make sure they're encr…

I'll do you one better. Start your .gitignore file with this line

  *

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#46

Guess who's going to be fired by elon :D

> Guess who's going to be fired by elon :D i know, you probably just meant it as a fun comment. but i don't get how this is funny. this person probably relies on income, might have a family to feed... and just made a mistake. a type of mistake, that is not uncommon. i mean i have seen corporate projects where senior engineers didn't even understand why committing secrets might be a bad idea. yes, of course, as a engi…

The real mistake is working for Elon

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#47
post #22
post #3

Musk has been talking about integrating Grok into Tesla cars and also adding a lot of space and rocketry specific training. It is completely possible that these models were trained on data that would logically be public at some point. It is also possible that the author's guess is right and that these were to contain sensitive data. Noone really knows, but honestly, these kinds of mistakes are happening all the time.…

How would you accidentally leak your .ssh dir on Github?

People with workflows like `git add .; git commit -m 'fix'` can push wondrous things to public repos.

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#48

Earlier quoted context omitted.

ITAR (International Trafficking in Arms Regulation) is paranoid . Every single specific person that knows even dual-use information, such as composite wing design, must be individually authorized. I’ve been asked to leave the room when my girlfriend, who works for a passenger aircraft manufacturer, was designing a repair for a plane I have literally flew on. It doesn’t matter how the person got access to dual-use inf…

This seems like a company policy more than ITAR. Unless you are not a US citizen, then it could be ITAR.

We’re in Canada, and I’m a US citizen, but she is not.

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#49
post #47
post #22

Earlier quoted context omitted.

How would you accidentally leak your .ssh dir on Github?

People with workflows like `git add .; git commit -m 'fix'` can push wondrous things to public repos.

Only if you're raw dogging git from your home directory...

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#50
post #36
post #32

Earlier quoted context omitted.

Or, since we're apparently playing the game of maybes in this thread, maybe the LLM was only trained on the teams grandmothers' spaghetti recipes, so that new hires can learn to make the best bolognese sauce.

This being Musk, it wouldn't surprise me. I mean, consider The Boring Company sell a "flamethrower" despite being theoretically about… boring.

Because Tesla is making.. coils?
Post reply on HN