Live data from Hacker News

Exposed DeepSeek database leaking sensitive information, including chat history

wiz.io

21–30 of 499 posts

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#21

[edit: Nevermind, see below] The direct disclosure of urls and ports is insane. Wonder if they would be as irresponsible if it was MSFT, OpenAI, Anthropic, etc. PS: Not defending DeepSeek for bad practices, but still. Nothing irresponsible here. PS2: It is marked as resolved, I went directly to the vulns due to the title of the post.

Why is ClickHouse exposing unauthenticated database access at port 9000 to the public? Is this the default behavior or did DeepSeek open it up for dev purposes?

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#22

[edit: Nevermind, see below] The direct disclosure of urls and ports is insane. Wonder if they would be as irresponsible if it was MSFT, OpenAI, Anthropic, etc. PS: Not defending DeepSeek for bad practices, but still. Nothing irresponsible here. PS2: It is marked as resolved, I went directly to the vulns due to the title of the post.

I'm not sure "irresponsible" is the word. Shouldn't this be, like, punishable by law?

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#23
post #11

Earlier quoted context omitted.

I agree this is really bad but far from unbelievable. I am only 23 and already my SSN and even my freaking DNA have both been leaked by major publicly traded companies.

Plus Volkswagen and Subaru in the last few weeks ...

Plus Volkswagen and Subaru in the last few weeks

Both Volkswagen and Subaru have leaked his DNA in the last few weeks? Dude gets around.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#24
post #6

So much effort in trying to tarnish DeepSeek the last 24hrs

Yep. Kinda like how your comment was grey within 1 minute, despite stating an objective truth. Sure, this is to be expected given the billions and billions of dollars at stake but like - that money is gone lol. DeepSeek isn't going back in the bottle, nor is open source AI in general.

The comment isn't wrong, but the implication is at deep seek is somehow special and is getting undue attention from hackers. Any app that skyrockets from nowhere to number one in the app store overnight will have the attention of probably hundreds of thousands of hackers.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#25
post #17
post #6

So much effort in trying to tarnish DeepSeek the last 24hrs

I'm not sure why you think why this discovery has to be some sort of "effort in trying to tarnish DeepSeek". Deepseek is the #1 downloaded app and and the media can't stop talking about it. That means a lot more people are looking into the app and possibly finding vulnerabilities, no conspiracy needed.

edit: snip, misinfo, I'm illiterate. Sorry!

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#26
post #5

This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle. Seems like the kind of mistake you would make if you are not used to deploying external client facing applications.

> This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle Can we stop with this nonsense ? The list of author of the paper is public, you can just go look it up. There are ~130 people on the ML team, they have regular ML background just like you would find at any other large ML labs. Their infra cost multiple millions of dollar per month to run, and the salary of such a big team is somew…

A bunch of ML researchers who were initially hired to do quant work published their first ever user facing project.

So maybe not a side project, but if you have ever worked with ML researchers before, lack of engineering/security chops shouldn't be that surprising to you.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#27
post #3

> More critically, the exposure allowed for full database control and potential privilege escalation within the DeepSeek environment, without any authentication or defense mechanism to the outside world. Not only that, this was a "production-grade" database with millions of users using it and the app was #1 on the app store and ALL text sent there in the prompts was logged in plain-text? Unbelievable.

Did they ever make promises as to confidentiality? What if providing all chat logs with users is just part of their open source / shānzhài attitude ? :)

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#28
post #6

So much effort in trying to tarnish DeepSeek the last 24hrs

Maybe, but having dev services outside of VPN is pretty nuts, not much effort needed to find that. Wouldn't expect a company with such budgets be that careless, I'm sure it's only the tip of the iceberg.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#30
post #14
post #6

So much effort in trying to tarnish DeepSeek the last 24hrs

I, for one, think this is a valuable piece of information and somewhat interesting analysis. You can take the cynical point of view that this was released just to tarnish their reputation or you can assume that it's security researchers publishing an important discovery just like they've always done whether it's for OpenAI, Microsoft Copilot, or any other AI or non AI product.

>https://news.ycombinator.com/item?id=42871371#42872454

We all agree this kind of leak should be disclosed. However normally security researchers don't just leaks specific URL and etc. This may be what the parent is referring to.

Post reply on HN