Live data from Hacker News

I tricked Claude into leaking your deepest, darkest secrets

ayush.digital

151–160 of 317 posts

Re: I tricked Claude into leaking your deepest, darkest secrets

#151

> After 15 minutes of confusion, it turned out Cloudflare had put a crazy robots.txt on my site without my consent (Cloudflare, love you guys, but this needs to stop). Might be the first time I see someone complain about their website being protected from a scraper, instead of the other way around.

I think the issue is the lack of consent. Whether a service I use is protecting my website from scrapers or feeding everything to scrapers, some of us would prefer that it takes our informed consent before doing so.

Cloudflare is explicitly a service for dropping requests, whether it’s DDoS attacks, as a WAF, or AI crawlers. It offers a lot more too, but this isn’t Cloudflare overstepping imo.

FWIW, I just set up a domain last week, and the web UI asked if I want to block AI crawlers or not.

Perhaps OP set it up agentically, and the agent didn’t pass an optional param correctly, or ticked the box for him?

Re: I tricked Claude into leaking your deepest, darkest secrets

#152
post #102

> After 15 minutes of confusion, it turned out Cloudflare had put a crazy robots.txt on my site without my consent (Cloudflare, love you guys, but this needs to stop). Might be the first time I see someone complain about their website being protected from a scraper, instead of the other way around.

You have to enable this, or atleast was the case when I tried less than 1 month ago.

You still have to enable this as of one week ago. I suspect OP might have agentically set up a new Cloudflare domain, and who knows what the agent did during onboarding.

Re: I tricked Claude into leaking your deepest, darkest secrets

#153
Not paying anything feels off – it should be more evaluated against making it public information at the time of discovery until ie. public patch release, it doesn't feel right that the response is "trust us bro, we knew about it, bye", wouldn't hurt to drop some usage credits at least.

Re: I tricked Claude into leaking your deepest, darkest secrets

#156
post #147

Earlier quoted context omitted.

Why is it not a terrible idea?

If you’re making automated requests, I consider it a common courtesy to provide an accurate user agent. Some services like Wikimedia will let you browse/download with rate limits IF your user agent is descriptive enough and not misleading.

Thanks, I wasn't aware of this. But to put your real name in the field instead of at least a pseudonymous id or more descriptive info but still have more bits of uncertainty user-agent for a public website, is that really a preferred practice?

Re: I tricked Claude into leaking your deepest, darkest secrets

#158

Doesn’t surprise me. Yesterday I learned that people run AI agents on their system with full admin rights. No containerisation or anything. Wild. Like we forgot 50 years of computer security overnight.

It's convenience. Nothing beats it. Having an agent work alongside you with no restrictions gives instant gratification.
Post reply on HN