> More critically, the exposure allowed for full database control and potential privilege escalation within the DeepSeek environment, without any authentication or defense mechanism to the outside world. Not only that, this was a "production-grade" database with millions of users using it and the app was #1 on the app store and ALL text sent there in the prompts was logged in plain-text? Unbelievable.
I agree this is really bad but far from unbelievable. I am only 23 and already my SSN and even my freaking DNA have both been leaked by major publicly traded companies.
Exposed DeepSeek database leaking sensitive information, including chat history
11–20 of 499 posts
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#12This doesn't look like a responsible disclosure, at all. ed: I was wrong!
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#13So much effort in trying to tarnish DeepSeek the last 24hrs
You can fault them for disclosure practices though :-)
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#14So much effort in trying to tarnish DeepSeek the last 24hrs
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#15This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle. Seems like the kind of mistake you would make if you are not used to deploying external client facing applications.
> This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle Can we stop with this nonsense ? The list of author of the paper is public, you can just go look it up. There are ~130 people on the ML team, they have regular ML background just like you would find at any other large ML labs. Their infra cost multiple millions of dollar per month to run, and the salary of such a big team is somew…
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#16The direct disclosure of urls and ports is insane. Wonder if they would be as irresponsible if it was MSFT, OpenAI, Anthropic, etc.
PS: Not defending DeepSeek for bad practices, but still. Nothing irresponsible here.
PS2: It is marked as resolved, I went directly to the vulns due to the title of the post.
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#17So much effort in trying to tarnish DeepSeek the last 24hrs
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#18So much effort in trying to tarnish DeepSeek the last 24hrs
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#19So much effort in trying to tarnish DeepSeek the last 24hrs
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#20[edit: Nevermind, see below] The direct disclosure of urls and ports is insane. Wonder if they would be as irresponsible if it was MSFT, OpenAI, Anthropic, etc. PS: Not defending DeepSeek for bad practices, but still. Nothing irresponsible here. PS2: It is marked as resolved, I went directly to the vulns due to the title of the post.