[edit: Nevermind, see below] The direct disclosure of urls and ports is insane. Wonder if they would be as irresponsible if it was MSFT, OpenAI, Anthropic, etc. PS: Not defending DeepSeek for bad practices, but still. Nothing irresponsible here. PS2: It is marked as resolved, I went directly to the vulns due to the title of the post.
Exposed DeepSeek database leaking sensitive information, including chat history
21–30 of 499 posts
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#22[edit: Nevermind, see below] The direct disclosure of urls and ports is insane. Wonder if they would be as irresponsible if it was MSFT, OpenAI, Anthropic, etc. PS: Not defending DeepSeek for bad practices, but still. Nothing irresponsible here. PS2: It is marked as resolved, I went directly to the vulns due to the title of the post.
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#23Earlier quoted context omitted.
I agree this is really bad but far from unbelievable. I am only 23 and already my SSN and even my freaking DNA have both been leaked by major publicly traded companies.
Plus Volkswagen and Subaru in the last few weeks ...
Both Volkswagen and Subaru have leaked his DNA in the last few weeks? Dude gets around.
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#24So much effort in trying to tarnish DeepSeek the last 24hrs
Yep. Kinda like how your comment was grey within 1 minute, despite stating an objective truth. Sure, this is to be expected given the billions and billions of dollars at stake but like - that money is gone lol. DeepSeek isn't going back in the bottle, nor is open source AI in general.
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#25So much effort in trying to tarnish DeepSeek the last 24hrs
I'm not sure why you think why this discovery has to be some sort of "effort in trying to tarnish DeepSeek". Deepseek is the #1 downloaded app and and the media can't stop talking about it. That means a lot more people are looking into the app and possibly finding vulnerabilities, no conspiracy needed.
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#26This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle. Seems like the kind of mistake you would make if you are not used to deploying external client facing applications.
> This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle Can we stop with this nonsense ? The list of author of the paper is public, you can just go look it up. There are ~130 people on the ML team, they have regular ML background just like you would find at any other large ML labs. Their infra cost multiple millions of dollar per month to run, and the salary of such a big team is somew…
So maybe not a side project, but if you have ever worked with ML researchers before, lack of engineering/security chops shouldn't be that surprising to you.
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#27> More critically, the exposure allowed for full database control and potential privilege escalation within the DeepSeek environment, without any authentication or defense mechanism to the outside world. Not only that, this was a "production-grade" database with millions of users using it and the app was #1 on the app store and ALL text sent there in the prompts was logged in plain-text? Unbelievable.
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#28So much effort in trying to tarnish DeepSeek the last 24hrs
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#29Re: Exposed DeepSeek database leaking sensitive information, including chat history
#30So much effort in trying to tarnish DeepSeek the last 24hrs
I, for one, think this is a valuable piece of information and somewhat interesting analysis. You can take the cynical point of view that this was released just to tarnish their reputation or you can assume that it's security researchers publishing an important discovery just like they've always done whether it's for OpenAI, Microsoft Copilot, or any other AI or non AI product.
We all agree this kind of leak should be disclosed. However normally security researchers don't just leaks specific URL and etc. This may be what the parent is referring to.