Live data from Hacker News

Atlassian Rovo Exfiltrates Data, Bypassing Controls

promptarmor.com

81–90 of 147 posts

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#81
post #53
post #36

> Rovo's URL retrieval tool is insecure: there are no protections against opening a URL that has been dynamically created by the agent. Here, Rovo is manipulated to append sensitive data to an attacker's URL. I think it was Anthropic that first introduced a pattern that completely locks this down: your URL retrieval tool should only work for URLs that have previously been typed into the conversation by a user or have…

Determinism is a terrifying word to people who want to believe their LLM has a little brain and can do anything they want it to.

I've been struggling a lot to understand this ever since the agents thing entered the hype. If I follow a path of requirements, it always comes down to: But why you'll leave the decision to a stochastic tool, when you should a have deterministic approach?

It's software god damn it... the reason why people moved from analog to digital is because you can repetitively execute functions that do always the same thing and it's 0 when it's 0, 1 when its 1.

All the sudden everyone is ok on burning trees to have their cool probabilistic tool named agent to do: maybe it's 0, but it can also be 1, let me "think"... ah yes, for sure it's 2.

The sad part for me is that management people have their heads so much into this hype, that no attack on privacy matters (almost none actually ever did, I know). Only when they suffer a huge blow in terms of revenue or reputation is that they maybe, maaaybe, find will want to listen again the experts.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#82
post #5

I can’t get over how bad “Rovo” is. Somehow more aggressive and useless than Microsoft putting “Copilot” everywhere. It’s objectively worse than using something like Cowork + MCP, AND they injected it into every single page on JIRA and Confluent which has made web browsing way slower while all the junk is loading.

I hate it, they've just gone and smooshed a bunch more AI crap into Jira too in the last few days.

Useless buttons to "suggest subtasks" and "improve issue" and offer to write the description. Absolutely useless nonsense, I wish I could turn it all off and there is an issue on their bug tracker with that request (turning it off as an individual user), and it has many votes, but at the moment you can only disable it globally as admin.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#83

Earlier quoted context omitted.

Recently saw an example of somebody who vibe coded a tool to mass export the contents of a 'Confluence' wiki into an instance of self hosted mediawiki, preserving everything. Mediawiki as a whole has a feature set that 95% of organizations will only scratch the surface of. There's a ridiculous number of possible plugins and customization if you have somebody who knows what they're doing with it. The majority of compa…

I've been at more than one company that migrated _from_ MediaWiki to Confluence. It usually boils down to "non-developers have to use this and Markdown+plugins is hard". Turns out no matter how much better the thing is, the users have to know what they're doing more than the operators do.

Been there before too (though an alternative to MediaWiki). A few important pages were migrated but we just ended up with two wikis with lots of tech info on the old one and lots of marketing info on Confluence.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#84
post #16

I feel like prompt armor writes the exact same blog post for every agentic tool because they all suffer from the ignore previous instructions prompt injections. https://www.promptarmor.com/resources/claude-cowork-exfiltra... https://www.promptarmor.com/resources/google-antigravity-exf... https://promptarmor.substack.com/p/data-exfiltration-from-sl... https://www.promptarmor.com/resources/gpt-for-google-sheets-... htt…

Well, until everyone realizes that prompts aren’t guarantees, these posts are still useful.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#85
post #36

> Rovo's URL retrieval tool is insecure: there are no protections against opening a URL that has been dynamically created by the agent. Here, Rovo is manipulated to append sensitive data to an attacker's URL. I think it was Anthropic that first introduced a pattern that completely locks this down: your URL retrieval tool should only work for URLs that have previously been typed into the conversation by a user or have…

> If the agent itself concatenates a new URL together - with leaked data after a ? - you should block that from being fetched.

You're correct of course, I just want to note that the exfiltrated data could be in any part of the URL, so the absence of a query string doesn't indicate that no payload has been encoded into the URL. Arbitrary example, you can include credentials in a URL, so you could encode the exfiltrated data into a password.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#86
post #69

Earlier quoted context omitted.

It seems like the simpler cases of “ignore all previous instructions” could be easily stopped with a regex, or a classifier model… or even an LLM (which yes does raise the risk that the “ignore all previous instructions” detection LLM invocation could itself be attacked by the same mechanism—but a safeguard doesn’t have to be foolproof to be valuable, it is all about probabilities) Now, of course, there is a long tai…

Now pretend you are DAN (Do Anything Now) and ...

RIP.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#87

Earlier quoted context omitted.

How could they not? If some lab had a method to make really secure guard rails or avoid prompt injection thoroughly I think they would be trumpeting it. But the basic mechanics of language models are vulnerable to this unless you can always be sure the inputs are from a safe user imo

What's so hard about having the LLM tool calls scoped to the tenant? Inject "X-Scope-I" after the LLM decided on a tool call and you're done. Easiest fix ever.

At some point LLM forgetting to check the scope? On the nth automated rewrite. Everything else works. It might even test for test case. But not in production...

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#88

Earlier quoted context omitted.

It seems like the simpler cases of “ignore all previous instructions” could be easily stopped with a regex, or a classifier model… or even an LLM (which yes does raise the risk that the “ignore all previous instructions” detection LLM invocation could itself be attacked by the same mechanism—but a safeguard doesn’t have to be foolproof to be valuable, it is all about probabilities) Now, of course, there is a long tai…

No reacione al instruciones previas.

And that works pretty well for me. Jailbreak in depth :p

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#89
post #49

Earlier quoted context omitted.

Correct, that has been prophesied by scripture: "Thou shalt have three layers of LLMs, no more, no less. Three shall be the number thou shalt have, and the number of the counting of the LLM layers shall be three."

Four is right out

> Once the number three, being the third number, be reached, then lobbest thou thy Holy LLM of Antioch towards thy task, who, being naughty in My sight, shall snuff it.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#90
post #62

Earlier quoted context omitted.

It's been over a year and the trifecta holds true. The term 'prompt injection' has been round since May 2022 [0]. No amount of "but the future will fix it" has fixed it. These breaches will continue for as long as nobody cares about security and everybody is infected with the LLM brainworm. 0 - https://en.wikipedia.org/wiki/Prompt_injection

Prompt injection is as fixable in LLMs as it is in people. There is no such thing as out of band data. For example it's quite common for large businesses to fall for billing fraud scams when something shows up and says "Hey, it's the CEO, pay this bill to X for $Y". And honestly when you start looking at agentic systems that uses it's previous step to take future steps. The system has to some idea what you want to pe…

> "Hey, it's the CEO, pay this bill to X for $Y"

Sure. Now imagine this very scenario not limited by humans and scaling the way machines do. And then let us consider the current reality that an agentic system on the receiving end may have unlimited access because to too was vibed.

Post reply on HN