Live data from Hacker News

Exposed DeepSeek database leaking sensitive information, including chat history

wiz.io

11–20 of 499 posts

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#11
post #3

> More critically, the exposure allowed for full database control and potential privilege escalation within the DeepSeek environment, without any authentication or defense mechanism to the outside world. Not only that, this was a "production-grade" database with millions of users using it and the app was #1 on the app store and ALL text sent there in the prompts was logged in plain-text? Unbelievable.

I agree this is really bad but far from unbelievable. I am only 23 and already my SSN and even my freaking DNA have both been leaked by major publicly traded companies.

Plus Volkswagen and Subaru in the last few weeks ...

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#13
post #6

So much effort in trying to tarnish DeepSeek the last 24hrs

Can't fault hackers for taking a look at a website that goes from "virtually unknown" to "extremely popular and headline news globally" practically over night. If nothing else, the probability of low-hanging fruit in something that is barely battle-tested is high.

You can fault them for disclosure practices though :-)

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#14
post #6

So much effort in trying to tarnish DeepSeek the last 24hrs

I, for one, think this is a valuable piece of information and somewhat interesting analysis. You can take the cynical point of view that this was released just to tarnish their reputation or you can assume that it's security researchers publishing an important discovery just like they've always done whether it's for OpenAI, Microsoft Copilot, or any other AI or non AI product.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#15
post #5

This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle. Seems like the kind of mistake you would make if you are not used to deploying external client facing applications.

> This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle Can we stop with this nonsense ? The list of author of the paper is public, you can just go look it up. There are ~130 people on the ML team, they have regular ML background just like you would find at any other large ML labs. Their infra cost multiple millions of dollar per month to run, and the salary of such a big team is somew…

None of that has anything to do with "deploying external client facing applications"

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#16
[edit: Nevermind, see below]

The direct disclosure of urls and ports is insane. Wonder if they would be as irresponsible if it was MSFT, OpenAI, Anthropic, etc.

PS: Not defending DeepSeek for bad practices, but still. Nothing irresponsible here.

PS2: It is marked as resolved, I went directly to the vulns due to the title of the post.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#17
post #6

So much effort in trying to tarnish DeepSeek the last 24hrs

I'm not sure why you think why this discovery has to be some sort of "effort in trying to tarnish DeepSeek". Deepseek is the #1 downloaded app and and the media can't stop talking about it. That means a lot more people are looking into the app and possibly finding vulnerabilities, no conspiracy needed.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#19
post #6

So much effort in trying to tarnish DeepSeek the last 24hrs

you're absolute right, so much garbage propaganda in many languages. For Apple we have tv news that usually promotes new Apple or OpenAI products (wtf!!) that are trying to tarnish DeepSeek on the privacy level... No words about all those garbage software siphoning off the web (without respecting neither copyright nor privacy)

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#20

[edit: Nevermind, see below] The direct disclosure of urls and ports is insane. Wonder if they would be as irresponsible if it was MSFT, OpenAI, Anthropic, etc. PS: Not defending DeepSeek for bad practices, but still. Nothing irresponsible here. PS2: It is marked as resolved, I went directly to the vulns due to the title of the post.

It’s been disclosed and resolved. What’s the concern here?
Post reply on HN