Live data from Hacker News

Potential session/cache leakage between workspace instances or consumer accounts

github.com

121–130 of 151 posts

Re: Potential session/cache leakage between workspace instances or consumer accounts

#121
post #2

Sounds like a hallucination unless proven otherwise, even the leading LLMs can do those from time to time, and they will always appear plausible like that. Also could be the session having a lot previous context, like 800K+, which (I think) makes hallucinations more likely. Relevant comment from the OP which makes a hallucination more likely: > There is one tool call result that includes a string that printed a pathn…

Exactly. If you've never had an LLM (all models) suddenly start spouting nonsense in a completely different language...you haven't been using LLMs that much. They will go absolutely insane some % of the time.

I've used LLMs quite a lot (Claude, GPT) and have never seen this behavior. You've got something else going on.

Re: Potential session/cache leakage between workspace instances or consumer accounts

#123

Earlier quoted context omitted.

I’ll be back next month with a load of fresh vectors in “Can AI Do Novel Security Research? Meet the HTTP Terminator” https://portswigger.net/research/talks?talkId=36 Maybe my last presentation on the topic! Possibly.

Why the reference to AI? This looks like standard security research.

If you follow the link, the presentation abstract should hopefully answer that question!

If that doesn’t help I guess you’ll need to wait for the whitepaper to land but I can assure you I didn’t just do my normal research then add AI to the title for clicks :)

Re: Potential session/cache leakage between workspace instances or consumer accounts

#124
post #115
post #110

Hi, it's Thariq from the Claude Code Team here. Thanks for the detailed report. We’re confident this is a hallucination but of course take these reports seriously and the team is looking into it. We’ll report back if anything turns up.

I know it's the weekend, so thanks for working hard. Just a suggestion from a user: I wish we could manage Claude Code's memory more easily. Right now, when I go into the .claude folder and change a project folder name or something, sometimes it can't pull up the memory properly. It'd be nice if there were an easier way to import or export it. Thanks!

Piggybacking onto a second/different "just a suggestion from a user":

The VS Code extension needs love. I'm sure you guys are aware but it feels like it is neglected.

GitHub Issues is a graveyard of 3-10 duplicates of really important issues with no activity getting closed. A few examples:

* Lots of /commands missing in between the CLI harness and the VS Code extension

* No way to monitor subagents/tasks/progress visually

* No status bar/line

Re: Potential session/cache leakage between workspace instances or consumer accounts

#125
post #80

I’ve been seeing this in Gemini in the past few days. Often during a prompt with a reasonably large input set, I’ll get answers that appear to belong to someone else. It may be trigger hallucination, but it seems like it may be cache collisions or something else. I’ve not seen anything to suggest private information is leaking, but it’s disconcerting to be researching something and then get what appears to be a math…

My whole company is doing mid year reviews and Gemini is the only allowed tool and its been flumoxing people with seemingly random unrelated responses. Often in different languages. That is when it bothers to respond instead of just sending back an 1099 error code

This is a HUGE clue that someone at Google should probably see…………

Re: Potential session/cache leakage between workspace instances or consumer accounts

#126
post #105

Using a throwaway account for obvious reasons, but I’m very involved in this space using LLMs from multiple providers. I’m aware of at least two instances in which the intermediate infrastructure “swapped” responses, once impacting Claude models and once impacting GPT models, from two different providers. One gave us a proper postmortem in which their API gateway was incorrectly handling HTTP 100 status codes, puttin…

Actually, it’s not obvious why you’re using a throwaway account… Every emergent behavior from these actors - whose claim to positive moral values is barely plausible - should be reported, discussed, dissected and critiqued early and often .

Your points don’t reference each other.

Yes, the discussion should be had constantly.

But: Should this person potentially have their life messed up because they pointed out the emperor has no clothes?

Re: Potential session/cache leakage between workspace instances or consumer accounts

#127

Earlier quoted context omitted.

CLAUDE.md, Anthropic is too exclusive and next level to use a standard idiomatic pattern like AGENTS.md

echo “read @AGENTS.md” > CLAUDE.md

Just @AGENTS.md should be enough, as @s is CLAUDE.md are inlined (and !`ls` are executed)

Re: Potential session/cache leakage between workspace instances or consumer accounts

#128

Earlier quoted context omitted.

Curious why you feel that way about Dario?

HN thinks the safety crowd is dumb, and has never seriously engaged with the AI safety space. HN doesn't believe superintelligence will be a thing; while the AI safety crowd believes they are building it. So the decisionmaking of the safety crowd is incomprehensible to HN.

What is the AI safety crowd exactly?

Dont we have a thread here how the model allegedly leaks responses what is "normal" safety? (Not "agi will become skynet" safety - what is mostly a rehash of terminator 2 story)

Re: Potential session/cache leakage between workspace instances or consumer accounts

#130
post #105

Using a throwaway account for obvious reasons, but I’m very involved in this space using LLMs from multiple providers. I’m aware of at least two instances in which the intermediate infrastructure “swapped” responses, once impacting Claude models and once impacting GPT models, from two different providers. One gave us a proper postmortem in which their API gateway was incorrectly handling HTTP 100 status codes, puttin…

Actually, it’s not obvious why you’re using a throwaway account… Every emergent behavior from these actors - whose claim to positive moral values is barely plausible - should be reported, discussed, dissected and critiqued early and often .

>should be reported, discussed, dissected and critiqued early and often.

And why does anonymity detract from any of that?

Post reply on HN