Live data from Hacker News

Exposed DeepSeek database leaking sensitive information, including chat history

wiz.io

1–10 of 499 posts

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#3
> More critically, the exposure allowed for full database control and potential privilege escalation within the DeepSeek environment, without any authentication or defense mechanism to the outside world.

Not only that, this was a "production-grade" database with millions of users using it and the app was #1 on the app store and ALL text sent there in the prompts was logged in plain-text?

Unbelievable.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#4
post #3

> More critically, the exposure allowed for full database control and potential privilege escalation within the DeepSeek environment, without any authentication or defense mechanism to the outside world. Not only that, this was a "production-grade" database with millions of users using it and the app was #1 on the app store and ALL text sent there in the prompts was logged in plain-text? Unbelievable.

I agree this is really bad but far from unbelievable. I am only 23 and already my SSN and even my freaking DNA have both been leaked by major publicly traded companies.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#9
post #6

So much effort in trying to tarnish DeepSeek the last 24hrs

Yep.

Kinda like how your comment was grey within 1 minute, despite stating an objective truth.

Sure, this is to be expected given the billions and billions of dollars at stake but like - that money is gone lol. DeepSeek isn't going back in the bottle, nor is open source AI in general.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#10
post #5

This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle. Seems like the kind of mistake you would make if you are not used to deploying external client facing applications.

> This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle

Can we stop with this nonsense ?

The list of author of the paper is public, you can just go look it up. There are ~130 people on the ML team, they have regular ML background just like you would find at any other large ML labs.

Their infra cost multiple millions of dollar per month to run, and the salary of such a big team is somewhere in the $20-50M per year (not very au fait of the market rate in china hence the spread).

This is not a sideproject.

Edit: Apparently my comment is confusing some people. Am not arguing that ML people are good at security. Just that DS is not the side project of a bunch of quant bros.

Post reply on HN