Live data from Hacker News

Exposed DeepSeek database leaking sensitive information, including chat history

wiz.io

231–240 of 499 posts

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#232

Earlier quoted context omitted.

With the amount of complexity found in modern car's pre-packaged software I'd not be so sure.

No he is right, hardware manufacturers treat software as a line item and just part of the BOM. Typically just contracted out (although some are trying to change that) Thats why its typically mediocre from companies outside of SV. You need a software first agile mentality from the leadership of the company on downwards and these legacy companies just dont have it.

Agile workflow for making cars? No.

Agile workflow for frequently updating non-critical software in devices that happen to be cars? Sure.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#233

The amount of vitriol in these comments is the really surprising data. I've seen the same on Twitter. I can only put it down to the financial pain DeepSeek inflicted on many US retail investors by wiping almost $700 billion off NVidia's stock price. I think a lot of folks didn't see it coming and it hurt them right where it matters most: In the wallet. The anger out there is very real.

"The amount of vitriol in these comments is the really surprising data"

No it isn't (well it probably is too). This is the rather naff nation state bollocks in play.

You have either or both of "some bigger boys found a more efficient way of doing something I thought I was good at" and "I've wet myself".

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#234
post #62

This is probably an incredibly stupid, off-topic question, but why are their database schemas and logs in English? Like, when a DeepSeek dev uses these systems as intended, would they also be seeing the columns, keys, etc. in English? Is there usually a translation step involved? Or do devs around the world just have to bite the bullet and learn enough English to be able to use the majority of tools? I'm realizing no…

>Or do devs around the world just have to bite the bullet and learn enough English to be able to use the majority of tools?

Yes, coding in english is the standard.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#235

Earlier quoted context omitted.

I would consider it table stakes for an intermediate level engineer at a big company (which would have well defined processes for doing this safely) or a senior at any other company (on the assumption some of that infra has to be set up from scratch). If 10 years of experience hadn’t taught me this yet, I would personally be concerned how I’m spending my energy. I am roughly at the 10y mark, and I would estimate I ha…

HN is a bubble. The expectation that your colleagues are /experts like you/ is unrealistic. To stand something up like this, which is entirely on bare metal - this is a task many would find challenging if they are entirely honest with themselves and put their egos to the side. Your typical swe thinks that nothing is impossible. There was a recent comment which said along the lines of “I used to watch figure skating,…

everything you say is true, but I don't think any of it actually applies to being able to safely deploy user facing systems. I would certainly not trust myself to do all possible aspects of setting up a user facing system completely from scratch (ie nothing but a libc on linux or whatever) I would not trust myself to write correct crypto, for example. But I have a good sense of what I can trust myself to build relatively safely. And of course i'm not claiming that "knowledge of where to trust myself" is by any means flawless. But Even in college I made applications for people that were exposed to the public internet. But I was very aware of what I felt I could trust myself to do and what I needed to rely on some other system for. In my case I delegated auth to "sign in with google" and relied on several other services for data storage. There were features that I didn't ship because I didn't trust myself to build them safely, and I was working alone. Now I would not necessarily expect every CS student to be able to do this safely, but a healthy understanding of one's own current limitations and being willing to engineer around that as a constraint is pretty achievable, and can get you very far.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#236
post #141

Earlier quoted context omitted.

Well, thanks for not calling it open source! I did run it locally. It behaved as you would expect when asked about things the CCP cares about. https://hongkongfp.com/wp-content/uploads/2021/11/brave_udRs...

Well, it is technically open source, open weights, and closed training set, right? (My recollection is that the training code is MIT licensed.)

I don't see any training code in the GH repos. There is inference code for DeepSeek v3.

So "open weights" is accurate. We used to call this closed source...

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#237
post #3

> More critically, the exposure allowed for full database control and potential privilege escalation within the DeepSeek environment, without any authentication or defense mechanism to the outside world. Not only that, this was a "production-grade" database with millions of users using it and the app was #1 on the app store and ALL text sent there in the prompts was logged in plain-text? Unbelievable.

I agree this is really bad but far from unbelievable. I am only 23 and already my SSN and even my freaking DNA have both been leaked by major publicly traded companies.

You leaked your DNA on which companies?

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#238

Earlier quoted context omitted.

With the amount of complexity found in modern car's pre-packaged software I'd not be so sure.

No he is right, hardware manufacturers treat software as a line item and just part of the BOM. Typically just contracted out (although some are trying to change that) Thats why its typically mediocre from companies outside of SV. You need a software first agile mentality from the leadership of the company on downwards and these legacy companies just dont have it.

> software first agile mentality

I can release a website with a list of known bugs. Do any govt allow release of cars with known bugs?

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#239
post #5

This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle. Seems like the kind of mistake you would make if you are not used to deploying external client facing applications.

'DeepSeek is the side project of a bunch of quants'

I doubt it very much that it only was that and not massivly backed by the Chinese state in general.

As with OpenAI, much of this has to do with hype based speculation.

In the case of OpenAI they played with the speculations, that they might have AGI locked up in their labs already and fueled those speculations. The result, massive investment (now in danger).

And China and the US play a game of global hegemony. I just read articles with the essence of, see China is so great, that a small sideproject there can take down the leading players from the west! Come join them.

It is mere propaganda to me.

Now deepseek in the open is a good thing, but I believe the Chinese state is backing it up massivly to help with that success and to help shake the western world of dominance. I would also assume, the chinese intelligence services helped directly with Intel straight out of OpenAI and co labs.

This is about real power.

Many states are about to decide which side they should take, if they have to choose between West and East. Stuff like this heavily influences those decisions.

(But btw. most don't want to have to choose)

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#240

Earlier quoted context omitted.

With the amount of complexity found in modern car's pre-packaged software I'd not be so sure.

No he is right, hardware manufacturers treat software as a line item and just part of the BOM. Typically just contracted out (although some are trying to change that) Thats why its typically mediocre from companies outside of SV. You need a software first agile mentality from the leadership of the company on downwards and these legacy companies just dont have it.

VW realized that software was important years ago and founded a dedicated software-only company called Cariad to specialize in it. They went ham recruiting traditional software folks for high salaries (in European terms). I know a few people who moved Bay area -> Europe to work for them and they have a couple west coast offices where you'd expect for the people who don't want to move.

It's been an absolute disaster, with billions of dollars spent to produce delayed, buggy software.

Post reply on HN