Live data from Hacker News

Atlassian Rovo Exfiltrates Data, Bypassing Controls

promptarmor.com

101–110 of 148 posts

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#101
post #5

I can’t get over how bad “Rovo” is. Somehow more aggressive and useless than Microsoft putting “Copilot” everywhere. It’s objectively worse than using something like Cowork + MCP, AND they injected it into every single page on JIRA and Confluent which has made web browsing way slower while all the junk is loading.

Have you seen the markdown agent instructions they provide in their new agentic `twg` cli? 70k tokens one average, there are more than one... Rovo is the worse Ai I have used, I suggested they stop trying and let us have model choice. Save money and don't do things out of their skill sets

The rovo CLI is beating Claude Code in some benchmarks. It works pretty well for me.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#102
post #71
post #63

I find it difficult to be impressed by "prompt injection" attacks that require the victim to enter the malicious prompt themselves --- like, really? If you tell Rovo to exfiltrate your data, it'll do it? Obviously, there should be URL protection rules to control what it can access, but this requires a very specific and unlikely set of circumstances to exploit.

Are people so obsessed with AI that they can't find it reasonable that it won't do obviously bad things if asked? Not even with a confirmation or warning? We trust AI to literally build products and fix our most critical bugs, but we can't expect it to tell when it's being asked to do something malicious? Imagine if we felt this way about QA when trying DROP TABLES; in search bars. "Oh, well of course it broke the da…

You’re asking for AI censorship ( that’s the term used for when you patch the AI to not do obviously bad things according to the owners, which as with any censorship, may be widely different from what you consider bad things).

You may be happy to learn frontier LLM are heavily censored! Try an uncensored local LLM for a comparison. It will literally do everything you ask it to, no matter how devious.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#103

Worth reminding everyone of previous discussion when Atlassian opted-in all customers by default for their data to be used for model training. https://news.ycombinator.com/item?id=47833247 This goes live on August 17. If you haven't switched it off your company IP will be used to train their future models.

So they will harvest trade secrets from 10000s of companies and there have been no panic mass flight about this?

How companies entrust SaaSs with their data is beyond insane to me. Especially since FOSS alternatives are readily available.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#104

Worth reminding everyone of previous discussion when Atlassian opted-in all customers by default for their data to be used for model training. https://news.ycombinator.com/item?id=47833247 This goes live on August 17. If you haven't switched it off your company IP will be used to train their future models.

So they will harvest trade secrets from 10000s of companies and there have been no panic mass flight about this? How companies entrust SaaSs with their data is beyond insane to me. Especially since FOSS alternatives are readily available.

Who cares?

The employee, just looking to make rent? The CEO, all in on the dream of the AI powered future? Legal, looking forward to litigation and well-competition retainers? Atlassian itself, when it’s just one of the many companies training models on private intellectual property, and whose T&C clearly state they will be doing so? Competitors, when there will be no reasonable way to prove their code has been generated from yours?

The truth is that one gives a damn about trade secrets being used to train AI models.

The entire copyright system for software is dead and no one really seems to care or even talk about it.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#105
post #104

Earlier quoted context omitted.

So they will harvest trade secrets from 10000s of companies and there have been no panic mass flight about this? How companies entrust SaaSs with their data is beyond insane to me. Especially since FOSS alternatives are readily available.

Who cares? The employee, just looking to make rent? The CEO, all in on the dream of the AI powered future? Legal, looking forward to litigation and well-competition retainers? Atlassian itself, when it’s just one of the many companies training models on private intellectual property, and whose T&C clearly state they will be doing so? Competitors, when there will be no reasonable way to prove their code has been gener…

The truth is that most software companies don't have any secrets worth hiding.

The saas industry is all about sales and deals. The market runs on access, not intelligence.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#106
post #85
post #36

> Rovo's URL retrieval tool is insecure: there are no protections against opening a URL that has been dynamically created by the agent. Here, Rovo is manipulated to append sensitive data to an attacker's URL. I think it was Anthropic that first introduced a pattern that completely locks this down: your URL retrieval tool should only work for URLs that have previously been typed into the conversation by a user or have…

> If the agent itself concatenates a new URL together - with leaked data after a ? - you should block that from being fetched. You're correct of course, I just want to note that the exfiltrated data could be in any part of the URL, so the absence of a query string doesn't indicate that no payload has been encoded into the URL. Arbitrary example, you can include credentials in a URL, so you could encode the exfiltrate…

Right, I should have been more clear. It's not about the ?, it's about not being able to dynamically construct a URL at all.

Otherwise you could set up wildcard DNS and extract data to base64encodedstolendata.evil.com

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#108
post #104

Earlier quoted context omitted.

Who cares? The employee, just looking to make rent? The CEO, all in on the dream of the AI powered future? Legal, looking forward to litigation and well-competition retainers? Atlassian itself, when it’s just one of the many companies training models on private intellectual property, and whose T&C clearly state they will be doing so? Competitors, when there will be no reasonable way to prove their code has been gener…

The truth is that most software companies don't have any secrets worth hiding. The saas industry is all about sales and deals. The market runs on access, not intelligence.

[deleted]

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#109
post #5

I can’t get over how bad “Rovo” is. Somehow more aggressive and useless than Microsoft putting “Copilot” everywhere. It’s objectively worse than using something like Cowork + MCP, AND they injected it into every single page on JIRA and Confluent which has made web browsing way slower while all the junk is loading.

Rovo makes for an INCREDIBLE time reading jira tickets and confluence pages. Someone wrote YES in all caps in a page ? Rovo will helpfully tell you (after loading for 5 seconds) that YES stands for Yassified Entertainment Setting, a new option added to the app in January 2024.

Whenever I feel like I'm bad at software development, I look at Atlassian and I feel good.

Re: Atlassian Rovo Exfiltrates Data, Bypassing Controls

#110

Worth reminding everyone of previous discussion when Atlassian opted-in all customers by default for their data to be used for model training. https://news.ycombinator.com/item?id=47833247 This goes live on August 17. If you haven't switched it off your company IP will be used to train their future models.

Our company dumped Atlassian. No-one misses it, it’s universally considered a good decision.
Post reply on HN