Live data from Hacker News

Exposed DeepSeek database leaking sensitive information, including chat history

wiz.io

31–40 of 499 posts

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#31
post #22

[edit: Nevermind, see below] The direct disclosure of urls and ports is insane. Wonder if they would be as irresponsible if it was MSFT, OpenAI, Anthropic, etc. PS: Not defending DeepSeek for bad practices, but still. Nothing irresponsible here. PS2: It is marked as resolved, I went directly to the vulns due to the title of the post.

I'm not sure "irresponsible" is the word. Shouldn't this be, like, punishable by law?

The vulnerable services were presumably fixed by the time this was published. I don't see anything wrong with releasing the details now.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#32

This doesn't look like a responsible disclosure, at all. ed: I was wrong!

Who's going to go after them? Heck, they may get an award for this.

Uh, I don't know, but cannot DeepSeek do that, for starters? Being located in a different country than the service you are attacking doesn't really make you immune to being sued.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#34
post #17
post #6

So much effort in trying to tarnish DeepSeek the last 24hrs

I'm not sure why you think why this discovery has to be some sort of "effort in trying to tarnish DeepSeek". Deepseek is the #1 downloaded app and and the media can't stop talking about it. That means a lot more people are looking into the app and possibly finding vulnerabilities, no conspiracy needed.

Not to mention the same thing happened to OpenAI and basically the same effort went into shaming them: https://www.theverge.com/2024/7/3/24191636/openai-chatgpt-ma...

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#35

This doesn't look like a responsible disclosure, at all. ed: I was wrong!

From the article:

> The Wiz Research team immediately and responsibly disclosed the issue to DeepSeek, which promptly secured the exposure.

Assuming everything mentioned in the article was fixed before publication, I don’t see an issue with it.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#36

[edit: Nevermind, see below] The direct disclosure of urls and ports is insane. Wonder if they would be as irresponsible if it was MSFT, OpenAI, Anthropic, etc. PS: Not defending DeepSeek for bad practices, but still. Nothing irresponsible here. PS2: It is marked as resolved, I went directly to the vulns due to the title of the post.

Why is ClickHouse exposing unauthenticated database access at port 9000 to the public? Is this the default behavior or did DeepSeek open it up for dev purposes?

That used to be the default setup for Redis, too. Might still be. You aren’t supposed to have it on a public subnet.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#37
post #26

Earlier quoted context omitted.

> This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle Can we stop with this nonsense ? The list of author of the paper is public, you can just go look it up. There are ~130 people on the ML team, they have regular ML background just like you would find at any other large ML labs. Their infra cost multiple millions of dollar per month to run, and the salary of such a big team is somew…

A bunch of ML researchers who were initially hired to do quant work published their first ever user facing project. So maybe not a side project, but if you have ever worked with ML researchers before, lack of engineering/security chops shouldn't be that surprising to you.

First ever? Their math, coding, and other models have been making a splash since 2023.

The mythologizing around deepseek is just absurd.

"Deepseek is the tale of one lowly hedgefund manager overcoming the wicked American AI devils". Every day I hear variations of this, and the vast majority of it is based entirely in "vibes" emanating from some unknown place.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#38
post #5

This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle. Seems like the kind of mistake you would make if you are not used to deploying external client facing applications.

> This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle Can we stop with this nonsense ? The list of author of the paper is public, you can just go look it up. There are ~130 people on the ML team, they have regular ML background just like you would find at any other large ML labs. Their infra cost multiple millions of dollar per month to run, and the salary of such a big team is somew…

?? The point is, the ML researchers aren’t experts at deploying secure infrastructure.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#39
post #5

This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle. Seems like the kind of mistake you would make if you are not used to deploying external client facing applications.

> This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle Can we stop with this nonsense ? The list of author of the paper is public, you can just go look it up. There are ~130 people on the ML team, they have regular ML background just like you would find at any other large ML labs. Their infra cost multiple millions of dollar per month to run, and the salary of such a big team is somew…

> This is not a sideproject.

OP means to say public API and app being a side project, which likely it is, the skills required to do ML have little overlap to skills required to run large complex workloads securely and at scale for public facing app with presumably millions of users.

The latter role also typically requires experience not just knowledge to do well which is why experiences SREs have very good salaries.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#40
post #25
post #17

Earlier quoted context omitted.

I'm not sure why you think why this discovery has to be some sort of "effort in trying to tarnish DeepSeek". Deepseek is the #1 downloaded app and and the media can't stop talking about it. That means a lot more people are looking into the app and possibly finding vulnerabilities, no conspiracy needed.

edit: snip, misinfo, I'm illiterate. Sorry!

What are you talking about? They did follow responsible disclosure.
Post reply on HN