Live data from Hacker News

Exposed DeepSeek database leaking sensitive information, including chat history

wiz.io

181–190 of 499 posts

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#181
post #6

So much effort in trying to tarnish DeepSeek the last 24hrs

Are you saying this report was falsified, or that the press should keep things like this secret?

Probably they are rather suggesting that there are a lot of unscrupulous western companies with a lot to lose who might have an interest in convincing certain people to skip responsible disclosure

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#182

Earlier quoted context omitted.

Software is unfortunately a side-project for most auto makers :)

With the amount of complexity found in modern car's pre-packaged software I'd not be so sure.

Having been in automotive software development and testing for over a decade now, I assure you, it's so very much worse than even that.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#183

[edit: Nevermind, see below] The direct disclosure of urls and ports is insane. Wonder if they would be as irresponsible if it was MSFT, OpenAI, Anthropic, etc. PS: Not defending DeepSeek for bad practices, but still. Nothing irresponsible here. PS2: It is marked as resolved, I went directly to the vulns due to the title of the post.

Why is ClickHouse exposing unauthenticated database access at port 9000 to the public? Is this the default behavior or did DeepSeek open it up for dev purposes?

I suspect this is a docker container hijacking host firewall rules which is a common pitfall. Of course there should be an ingress and others, but it is also common to roll out a VPS in a hurry. No bad intentions from any side, just lack of practice.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#185
Does DeepSeek have a bug bounty program I'm not aware of with a clearly defined scope? It appears that Wiz took it upon themselves to probe and access DeepSeek's systems without permission and then write about it.

If you do this and the company you're conducting your "research" on hasn't given you permission in some form, you can get yourself in a lot of hot water under the CFAA in the USA and other laws around the world.

Please don't follow this example. Sign up for a bug bounty program or work directly with a company to get permission before you probe and access their systems, and don't exceed the access granted.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#186
post #14
post #6

So much effort in trying to tarnish DeepSeek the last 24hrs

I, for one, think this is a valuable piece of information and somewhat interesting analysis. You can take the cynical point of view that this was released just to tarnish their reputation or you can assume that it's security researchers publishing an important discovery just like they've always done whether it's for OpenAI, Microsoft Copilot, or any other AI or non AI product.

I think that was a shameless self promotion. A lot of PR and free traffic by taking a low hanging fruit. Nothing else. But they did some good though.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#187

Earlier quoted context omitted.

Someone who worked on a non-English environment years ago here: sometimes you do use the local language in some contexts, but, more often than not, you end up using English for the majority of stuff since it's a bit off-putting to mix another language with the English of programming languages and APIs.

Dumb question, but it would then seem that you have to know English to program??

Kinda. Some of them know all the English words in the programming language they code in, and not much else.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#188
post #26

Earlier quoted context omitted.

A bunch of ML researchers who were initially hired to do quant work published their first ever user facing project. So maybe not a side project, but if you have ever worked with ML researchers before, lack of engineering/security chops shouldn't be that surprising to you.

> A bunch of ML researchers who were initially hired to do quant work Very interesting! I'm sure you have a source for this claim? This myth of DS being a side project literally started from one tweet. DeepSeek the company is funded by a company whose main business is being a hedge fund, but DeepSeek itself from day 1 has been all about building LLM to reach AGI, completely independent. This is like saying SpaceX is…

See this earlier interview from 2020.

https://www.pekingnology.com/p/ceo-of-deepseeks-parent-high-...

TDLR Highflyer started very much as exclusive ML/AI focused quant investment firm, with a lot of compute for finance AI and mining. Then CCP cracked down on mining... then finance, so Liang probably decided to pivot to LLM/AGI, which likely started as side project, but probably not anymore now the DeepSeek has taken off and Liang just met with PRC premiere a few days ago. DeepSeek being independent company doesn't mean DeepSeek isn't Liang's side project using compute bought with hedge fund money that is primarily used for hedgefund work, cushioned/allowed to get by with low margins by hedgefund profits.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#189

Earlier quoted context omitted.

Software is unfortunately a side-project for most auto makers :)

With the amount of complexity found in modern car's pre-packaged software I'd not be so sure.

The complexity is a symptom of it being a side-project, not evidence that it isn't. As a reminder, today's cars are still vulnerable to remote takeover via malformed songs on the radio because of shitty can-bus practices combined with buffer overflows in those side projects.

Safety-critical firmware is scrutinized fairly well (not because it's not a side project, but because of regulatory constraints combined with the small scope allowing the car manufacturers to treat it as a fungible good), but other software is not, even broken feedback loops interacting with that firmware.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#190

Does DeepSeek have a bug bounty program I'm not aware of with a clearly defined scope? It appears that Wiz took it upon themselves to probe and access DeepSeek's systems without permission and then write about it. If you do this and the company you're conducting your "research" on hasn't given you permission in some form, you can get yourself in a lot of hot water under the CFAA in the USA and other laws around the w…

They left open a publicly exposed database... I'm sure they informed the company about this before publishing their post. Why are you blaming Wiz for this?
Post reply on HN