Live data from Hacker News

Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

alexschapiro.com

231–240 of 301 posts

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#231

Earlier quoted context omitted.

humans used open s3 buckets stuffed with text files of usernames, passwords, addresses, credit card numbers etc long before vibe coding was a thing.

Prediction: Vibe coding systems will be better at security in 2 years than 90% of devs.

Prediction: it won't.

You can't fit every security consideration into the context window.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#232
post #198
post #186

Earlier quoted context omitted.

http-only makes it also very easy to sniff for LE if they decide to. This allows them to get knowledge about cases. Like, they could be scanning it with their own AI tool for all we know. In a free country with proper LE, this would neither be legal nor happening. But I am not sure the USA is remaining one, given the leader is a convicted felon with very dubious moral standards. The problem here however is that they…

All the big tech companies are in the news every week. Everybody knows how bad they are. Their names are tarnished and yet everyone is still using their junk and they face zero repercussions when fucking up. I dont think things in the media would do any harm.

In the news, sure. But negatively? I consider myself included in 'everyone', and I am not using junk from all the big tech companies. More than once, I've successfully quit using certain ones, and Signal has become much more popular in my country ever since Trump II took office. Meta had to change the name of their company (Facebook) since it had such a bad name, and Zuck started a charm offensive.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#233

I am at a loss for words. This wasn't a sophisticated attack. I'd love to know who filevine uses for penetration testing (which they do, according to their website) because holy shit, how do you miss this? I mean, they list their bug bounty program under a pentesting heading, so I guess it's just nice internet people. It's inexcusable.

> I am at a loss for words. This wasn't a sophisticated attack.

To be fair, data security breaches seldom are.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#235
Hey I think I've just found a new marketing stunt for a new vibe-coding platform:

"Worried your vibe-coded app is about to be broadcast on the internet’s biggest billboard? Chill. ACME AI now wraps it in “NSA-grade” security armor."

I've never thought that there will be multiple billion-dollar-AI-features that fixes all the monkey patching problems that no one saw them coming from the older billion-dollar-AI-features that fixes all the monkey patching problems that no one saw them coming from...

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#236

Earlier quoted context omitted.

In 90% of the cases. And if you don't know how to spot that other 10%, you are still screwed, cause someone else will found that (and you don't even need to be an elite black hat to find it).

What’s to say a human would catch this 10% either?

Humans are pretty good at edge cases.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#237
post #12

I'm always a bit surprised how long it can take to triage and fix these pretty glaring security vulnerabilities. October 27, 2025 disclosure and November 4, 2025 email confirmation seems like a long time to have their entire client file system exposed. Sure the actual bug ended up being (what I imagine to be) a Is the issue that people aren't checking their security@ email addresses? People are on holiday? These emai…

In my experience, it comes down to project management and organizational structure problems. Companies hire a "security team" and put them behind the security@ email, then decide they'll figure out how to handle issues later. When an issue comes in, the security team tries to forward the security issue to the team that owns the project so it can be fixed. This is where complicated org charts and difficult incentive s…

Great comment. Very true.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#238

Earlier quoted context omitted.

Prediction: Vibe coding systems will be better at security in 2 years than 90% of devs.

Prediction: it won't. You can't fit every security consideration into the context window.

90% of human devs are not aware of every security consideration.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#239

So, 1) a public service, 2) with no authentication, 3) and no encryption? (http only??), 4) sent every single response with a token, 5) giving full admin access to every client's legal documents . This is like a law firm with an open back door, open back window, and all the confidential legal papers sprawled out on the floor. Imagine the potential impact. You're a single mother, fighting for custody of your kids. You…

Basically what happened in the Vastaamo case in Finland [1]. Except of course it wasn't individual phone calls – it was mass extortion of 30,000 people at once via email. [1] https://en.wikipedia.org/wiki/Vastaamo_data_breach

if I remember correctly the attacker got caught in such a silly way

he wanted to demonstrate that he indeed has the private data. But he fucked up the tar command and it ended up having his username in the directory names, a username he used in other places on the internet

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#240
post #206

Earlier quoted context omitted.

> it's almost as if there's more stuff we do than just write code.. Yes, but adding these common sense considerations is actually something LLMs can already do reasonably well.

If you explicitly request it which means you need to know about it.

Or you need to guess that it exists, or you need to scan for places it exists.
Post reply on HN