Live data from Hacker News

Exposed DeepSeek database leaking sensitive information, including chat history

wiz.io

161–170 of 499 posts

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#161
post #117

Earlier quoted context omitted.

But like, you can’t program Java without English right? A for-loop has to be written in English?? I’m so confused haha

Yes, but you don't need to know what "for" and "while" mean in your language, you just need to know their behavior. The same way Arnold Schwarzenegger was acting without knowing much English - everything was phonetically spelled for him in early roles.

Or when Kennedy said in Berlin "ich bin ein Berliner" reading from a cue card that said "bear-leaner" :)

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#163

Earlier quoted context omitted.

No. I don’t think so. I think if you took many engineers and sat them at a computer and asked them to stand up a whole dev staging prod system they wouldn’t be able to do it. I certainly would not, or it would take me a significant amount of time to do properly. I have been a full stack dev for 10 years. Now take that one step further to someone whose only interaction with a development is numpy, pandas, julia, etc……

Depending on your perspective, that's either very concerning or a great business opportunity for this decade's Heroku to enter the fray.

This is definitely not something hosted on a P/SaaS.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#164
I don't get the discussions around side project and they're ML engineers, not security experts. Why are you excusing a company for a serious security leak.

If you're releasing a major project into the wild, expect serious attention and have the money, you get third parties involved to test for these things before you launch.

Now can we get back to discussing the real conspiracy theories. This is clearly a disinformation piece by BigAI to add FUD around the Chinese challenger :-)

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#165
post #121

[flagged]

As a Canadian, I don't particularly care what the Chinese government knows about me. They represent zero threat to me, and honestly I'm rational enough to know that they don't particularly care what I'm up to. US companies, on the other hand...did you miss where all of the tech oligarchs lined up in an obsequious little row to proselytize before the newly anointed king? When they all went on a spree in advance to sho…

1. I'm not American.

2. The choice is not between US and China.

3. Communism is just destructive. Trust me, you'll eventually figure this one out.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#166

Earlier quoted context omitted.

No. I don’t think so. I think if you took many engineers and sat them at a computer and asked them to stand up a whole dev staging prod system they wouldn’t be able to do it. I certainly would not, or it would take me a significant amount of time to do properly. I have been a full stack dev for 10 years. Now take that one step further to someone whose only interaction with a development is numpy, pandas, julia, etc……

> I think if you took many engineers and sat them at a computer and asked them to ... There are many in the software engineering field which could not satisfy a request of this nature, for any reasonable form of "asked them to".

I don’t understand this comment? Is it unusual to request something like this? OP’s comment was saying that all 1000 or so (and hundreds of thousands of others) of his colleagues would be able to do this if asked?

I don’t know if you are in agreement with me or not

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#167
post #111

Earlier quoted context omitted.

That's pretty much the same mistake as in VW recent "We know where you parked" hack. [0] So while I don't really want to say anything nice about VW, the mistake is no something that only happens to side projects. [0] https://www.spiegel.de/international/business/we-know-where-...

Software is unfortunately a side-project for most auto makers :)

With the amount of complexity found in modern car's pre-packaged software I'd not be so sure.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#168
post #5

This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle. Seems like the kind of mistake you would make if you are not used to deploying external client facing applications.

There are many examples of experienced teams doing stupid things like exposing databases that I don't really think this is a valid conclusion to draw.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#169
post #5

This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle. Seems like the kind of mistake you would make if you are not used to deploying external client facing applications.

There are many examples of experienced teams doing stupid things like exposing databases that I don't really think this is a valid conclusion to draw.

Clearly it could never be enough to draw that conclusion but it might be very weak evidence in one direction

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#170
post #5

This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle. Seems like the kind of mistake you would make if you are not used to deploying external client facing applications.

It doesn't say much.

Data breaches from unsecured or accidentally-public servers/databases are not unusual among much larger entities than DeepSeek.

Post reply on HN