Live data from Hacker News

Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

alexschapiro.com

11–20 of 301 posts

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#11

[flagged]

That comment didn't read like AI generated content to me. It made useful points and explained them well. I would not expect even the best of the current batch of LLMs to produce an argument that coherent.

This sentence in particular seems outside of what an LLM that was fed the linked article might produce:

> What's wild is that nothing here is exotic: subdomain enumeration, unauthenticated API, over-privileged token, minified JS leaking internals.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#12
I'm always a bit surprised how long it can take to triage and fix these pretty glaring security vulnerabilities. October 27, 2025 disclosure and November 4, 2025 email confirmation seems like a long time to have their entire client file system exposed. Sure the actual bug ended up being (what I imagine to be) a Is the issue that people aren't checking their security@ email addresses? People are on holiday? These emails get so much spam it's really hard to separate the noise from the legit signal? I'm genuinely curious.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#13

I think this class of problems can be protected against. It's become clear that the first and most important and most valuable agent, or team of agents, to build is the one that responsibly and diligently lays out the opsec framework for whatever other system you're trying to automate. A meta-security AI framework, cursor for opsec, would be the best, most valuable general purpose AI tool any company could build, imo…

> I think this class of problems can be protected against.

Of course, it’s called proper software development

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#14

[flagged]

We finally have a blog that no one (yet) has accused of being ai generated, so obviously we just have to start accusing comments of being ai. Can't read for more than 2 seconds on this site without someone yelling "ai!".

For what it's worth, even if the parent comment was directly submitted by chatgpt themselves, your comment brought significantly less value to the conversation.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#16

That doesn't surprise me one bit. Just think about all the confidential information that people post into their Chatgpt and Claude sessions. You could probably keep the legal system busy for the next century on a couple of days of that.

"Hey uh, ChatGPT, just hypothetically, uh, if you needed to remove uh cows blood from your apartments carpet, uh"

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#18

If they have a billion dollar valuation, this fairly basic (and irresponsible) vulnerability could have cost them a billion dollars. If someone with malice had been in your shoes, in that industry, this probably wouldn't have been recoverable. Imagine a firm's entire client communications and discovery posted online. They should have given you some money.

They should have given him a LOT of money.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#19
I work for a finance firm and everyone is wondering why we can store reams of client data with SaaS Company X, but not upload a trust document or tax return to AI SaaS Company Y.

My argument is we're in the Wild West with AI and this stuff is being built so fast with so many evolving tools that corners are being cut even when they don't realize it.

This article demonstrates that, but it does sort of beg the question as to why not trust one vs the other when they both promise the same safeguards.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#20

I work for a finance firm and everyone is wondering why we can store reams of client data with SaaS Company X, but not upload a trust document or tax return to AI SaaS Company Y. My argument is we're in the Wild West with AI and this stuff is being built so fast with so many evolving tools that corners are being cut even when they don't realize it. This article demonstrates that, but it does sort of beg the question…

The question is what reason did you have to trust SaaS Company X in the first place?
Post reply on HN