Live data from Hacker News

Atlassian Rovo Exfiltrates Data, Bypassing Controls

promptarmor.com

71–80 of 147 posts

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#71
post #63

I find it difficult to be impressed by "prompt injection" attacks that require the victim to enter the malicious prompt themselves --- like, really? If you tell Rovo to exfiltrate your data, it'll do it? Obviously, there should be URL protection rules to control what it can access, but this requires a very specific and unlikely set of circumstances to exploit.

Are people so obsessed with AI that they can't find it reasonable that it won't do obviously bad things if asked? Not even with a confirmation or warning? We trust AI to literally build products and fix our most critical bugs, but we can't expect it to tell when it's being asked to do something malicious? Imagine if we felt this way about QA when trying DROP TABLES; in search bars. "Oh, well of course it broke the database, the user asked it to!"

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#72
post #67

Earlier quoted context omitted.

> Really what you're thinking here is this something that can be 'simply fixed'. It is not. The only way it's truly fixed I think this is binary categorical thinking. In the real world, safety systems (even in domains like aviation or nuclear power) are never foolproof-the point is you reduce the probability of failure to an acceptable level given the costs of doing so and the potential consequences of that failure A…

The issue is with the nature of agentic systems and how often they run, a .001 failure is still huge. Attackers monitor their attack chances and use the most successful attacks so the actual success on the attackers side is much closer to 1 than .001. This is the problem, this isn't a 'failure' mode where something randomly goes wrong, like a person accidentally sticking their hand in a machine. This is war where you…

> This is war where you are under active attack and the attackers adapt quickly.

It all depends on what the use case is.

For example, consider a system which takes English questions from business users, translates them to SQL, then runs it (as the business user) against a reporting database

How does the attacker get access to it? And even if they somehow do, what harm can they actually do to it? The only tool it has is one to run SELECT against a DB, and it can only SELECT data the user already has access to, and we have timeouts/etc to protect against overly expensive queries

If your design involves lots of general purpose do-anything agents with very generic tools, the risk profile is very different from narrowly scoped purpose-specific AI services

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#74
The writing is rather low quality, but seems to be consistent with their other posts.

Maybe to give credit they are being purposefully vague about details to avoid giving away the bait but still seem like you could give me details without literally copy and pasting the attack.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#75
I read it as an intentional exfiltration.

It's incredibly hard to block all rovo on Atlassian pages. I tried adblock, it failed, I settled for the custom chrome plugin. And yet, every once a while a new way to disturb my peace shows it ugly head.

So why intentional, again? Because it's impossible to disable it until you have a very certain, very expensive plan.

Nonconsensual data exfiltration.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#76
post #3

Atlassian has gone from a trusted enterprise-partner to a complete shit-show in just 18 months. This surprises nobody. There will be classes taught in how to fuck up a good business and Atlassian will be the prime example. Regards, /someone who migrated 3500 users from Atlassians products recently due to their "cloud only"-bullshit.

Trusted enterprise partner? lol, lmao even.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#77
I hate working with Atlassian, years and years ago moved to youtrack instead of Jira mainly because it handles teams who work on multiple projects way better. But confluence remains, just need to spend some time re-evaluating other wikis (there's always been some blocking reason why the alternatives aren't a good fit, but they've all improved a lot)

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#78
post #67

Earlier quoted context omitted.

The issue is with the nature of agentic systems and how often they run, a .001 failure is still huge. Attackers monitor their attack chances and use the most successful attacks so the actual success on the attackers side is much closer to 1 than .001. This is the problem, this isn't a 'failure' mode where something randomly goes wrong, like a person accidentally sticking their hand in a machine. This is war where you…

> This is war where you are under active attack and the attackers adapt quickly. It all depends on what the use case is. For example, consider a system which takes English questions from business users, translates them to SQL, then runs it (as the business user) against a reporting database How does the attacker get access to it? And even if they somehow do, what harm can they actually do to it? The only tool it has…

I mean, yeah, consider a system that takes English questions and does nothing with them, it’s very secure. What’s your point? It doesn’t really refute what the commenter above you was saying.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#79
post #16

I feel like prompt armor writes the exact same blog post for every agentic tool because they all suffer from the ignore previous instructions prompt injections. https://www.promptarmor.com/resources/claude-cowork-exfiltra... https://www.promptarmor.com/resources/google-antigravity-exf... https://promptarmor.substack.com/p/data-exfiltration-from-sl... https://www.promptarmor.com/resources/gpt-for-google-sheets-... htt…

> ignore previous instructions prompt injections. I wonder if anyone has tried to build an LLM that has actual built-in types of prompts: system prompt, user prompt, and data prompt.

It’s not really possible with the way that the context works.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#80
post #5

I can’t get over how bad “Rovo” is. Somehow more aggressive and useless than Microsoft putting “Copilot” everywhere. It’s objectively worse than using something like Cowork + MCP, AND they injected it into every single page on JIRA and Confluent which has made web browsing way slower while all the junk is loading.

Have you seen the markdown agent instructions they provide in their new agentic `twg` cli? 70k tokens one average, there are more than one... Rovo is the worse Ai I have used, I suggested they stop trying and let us have model choice. Save money and don't do things out of their skill sets

Don’t use it? You don’t have to
Post reply on HN