Live data from Hacker News

Atlassian Rovo Exfiltrates Data, Bypassing Controls

promptarmor.com

41–50 of 147 posts

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#41
Rovo is one of those intrusive AI buttons that suddenly appeared everywhere without any warning. Its so annoying having already shitty UI get borked with features I never use. Almost as annoying as Whatsapp suddenly getting the same FOMO AI button. Its not like I need an AI agent to talk to friends and family. And a summary is something I can always generate via copy&paste into CLI chat session.

I'm still on the edge about security as an afterthought in LLMs. Given its now so easy to generate a ton of slop - why not focus on nonfunctional stuff making LLMs operate faster than thinking for X minutes and limiting exfiltration of local env secrets?

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#42
post #5

I can’t get over how bad “Rovo” is. Somehow more aggressive and useless than Microsoft putting “Copilot” everywhere. It’s objectively worse than using something like Cowork + MCP, AND they injected it into every single page on JIRA and Confluent which has made web browsing way slower while all the junk is loading.

>I can’t get over how bad “Rovo” is. Somehow more aggressive and useless than Microsoft putting “Copilot” everywhere.

You're looking at it the wrong way. Think about how much better it is than the joke of a search tool that's slightly to the left of it's icon.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#43
post #39

Earlier quoted context omitted.

What's so hard about having the LLM tool calls scoped to the tenant? Inject "X-Scope-I" after the LLM decided on a tool call and you're done. Easiest fix ever.

Famous last words: easy fix.

The Rovo MCP server manages scope credentials securely with “bring your own LLM”. Yet somehow they still fucked up with their own agent

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#44

Earlier quoted context omitted.

>I think things like web search should probably be run on a different sandboxed AI whose task is to write a summary that is then ingested by the main agent, similar to how existing sandboxing already works, but this would diminish the usefulness quite a bit. It also wouldn't work. You would simply mindjack the outer AI and have it mindjack the inner AI in turn with its summary. Nesting AIs can't fix the malicious inp…

Just pass that through a third llm.

Correct, that has been prophesied by scripture:

"Thou shalt have three layers of LLMs, no more, no less. Three shall be the number thou shalt have, and the number of the counting of the LLM layers shall be three."

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#45
post #3

Atlassian has gone from a trusted enterprise-partner to a complete shit-show in just 18 months. This surprises nobody. There will be classes taught in how to fuck up a good business and Atlassian will be the prime example. Regards, /someone who migrated 3500 users from Atlassians products recently due to their "cloud only"-bullshit.

To where? Where did you convince c-suite to move to?

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#46

Earlier quoted context omitted.

Recently saw an example of somebody who vibe coded a tool to mass export the contents of a 'Confluence' wiki into an instance of self hosted mediawiki, preserving everything. Mediawiki as a whole has a feature set that 95% of organizations will only scratch the surface of. There's a ridiculous number of possible plugins and customization if you have somebody who knows what they're doing with it. The majority of compa…

I've been at more than one company that migrated _from_ MediaWiki to Confluence. It usually boils down to "non-developers have to use this and Markdown+plugins is hard". Turns out no matter how much better the thing is, the users have to know what they're doing more than the operators do.

I'm not surprised. We're trying to migrate from Jira and Confluence (because we can't have our data outside our servers), and while Jira has many alternatives, it's difficult to find worthy competitors to Confluence. They either have an awful UI/UX, or don't have as many features. We're looking at Xwiki, but simply try to have multiple users simultaneously edit a table and you'll see why everyone prefers Confluence...

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#47
post #23

> The victim uploads a file to Rovo that contains a hidden prompt injection Yeah this attack is possible on all modern agentic systems. * Access to your private data * Exposure to untrusted content * The ability to externally communicate in a way that could be used to steal your data ( https://simonw.substack.com/p/the-lethal-trifecta-for-ai-age... ) And blocking it wholesale reduces usefulness of the agent so it is…

It's been over a year and the trifecta holds true. The term 'prompt injection' has been round since May 2022 [0]. No amount of "but the future will fix it" has fixed it.

These breaches will continue for as long as nobody cares about security and everybody is infected with the LLM brainworm.

0 - https://en.wikipedia.org/wiki/Prompt_injection

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#49

Earlier quoted context omitted.

Just pass that through a third llm.

Correct, that has been prophesied by scripture: "Thou shalt have three layers of LLMs, no more, no less. Three shall be the number thou shalt have, and the number of the counting of the LLM layers shall be three."

Four is right out

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#50
post #3

Atlassian has gone from a trusted enterprise-partner to a complete shit-show in just 18 months. This surprises nobody. There will be classes taught in how to fuck up a good business and Atlassian will be the prime example. Regards, /someone who migrated 3500 users from Atlassians products recently due to their "cloud only"-bullshit.

I can't remember a time in which Atlassian was trusted.
Post reply on HN