Live data from Hacker News

Exposed DeepSeek database leaking sensitive information, including chat history

wiz.io

391–400 of 499 posts

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#391
post #62

This is probably an incredibly stupid, off-topic question, but why are their database schemas and logs in English? Like, when a DeepSeek dev uses these systems as intended, would they also be seeing the columns, keys, etc. in English? Is there usually a translation step involved? Or do devs around the world just have to bite the bullet and learn enough English to be able to use the majority of tools? I'm realizing no…

I'm from Sweden (okay not same thing as China due to english being more common here) but I always code in english. Even if it is a script just for myself I will use english for variable names etc

I do that as well and also in almost all my personal documents on most (but not all) topics. All the books and most online forums I read are in English. I rather have documents uniformly in Swedish English (en-SE?) than some Swenglish mess of Swedish mixed with English words.

It also helps on the rare occasions some random notes evolve into a proper project that will have to be in English eventually anyway. There is no need for an extra translation step between initial idea and final product. All my vague hobby gamedev ideas are in English for instance.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#392

Earlier quoted context omitted.

I have DeepSeek-R1 1.5b running on a Raspberry Pi 5. I have DS-R1 14b Q6 running on my old AM4 Ryzen with a AMD GPU, without issues. My primary workstation is running 32B Q8 and without issues. And it's simple!

That's not the DeepSeek R1 model that they're offering via the API on these servers. That's a Qwen model that's been fine-tuned on output from the big R1 model.

Source?

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#393

Earlier quoted context omitted.

Not literally required, because languages typically support UTF-8 source files, but it would be difficult to use most popular software libraries without being able to at least read English.

Now I want to program in Mandarin and be l33t

https://mariusbancila.ro/blog/2019/05/16/cpp-is-fun/

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#394

Does DeepSeek have a bug bounty program I'm not aware of with a clearly defined scope? It appears that Wiz took it upon themselves to probe and access DeepSeek's systems without permission and then write about it. If you do this and the company you're conducting your "research" on hasn't given you permission in some form, you can get yourself in a lot of hot water under the CFAA in the USA and other laws around the w…

I agree to your comment, but also there's probably an unspoken gentleman's agreement that DeepSeek fixed the issue and won't pursue legal action against Wiz, since they were helpful and didn't do anything malicious.

I did the same a while ago, an education platform startup had their web server misconfigured, I could clone their repo locally because .git was accessible. I immediately sent them an email from a throwaway account in case they wanted to get me in trouble and informed them about the configuration issues. They thanked me for the warning and suggestions, and even said they could get me a job at their company.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#395
post #299

Earlier quoted context omitted.

It still doesn't make sense to me. If the money for training is still there, wouldn't companies that can afford it use the efficiency gains and also scale up models? Unless AI is a bubble, and it pops, I can't see the demand for compute going down.

I think AI is a bubble. The amount of compute for inference is vastly overestimated, because a lot of caching is coming. It's driven by maniacal statements like Sam Altman's insistence that we must spend Trillions on compute, to achieve AGI, and it's more important than anything else. Project Stargate is some large fraction of that, and of course Softbank is no stranger to losing money on overestimating demand (for e…

Which is great for us, we'll have loads of cheap compute and hopefully a bunch more carbon free energy supply, assuming that the AI stuff all ends in tears (for now).

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#396
post #353

Earlier quoted context omitted.

I think the difference in your comment is that China is doing this to their own citizens. Israel is oppressing their enemy, who have voted for Hamas to be the leader of their government, which stated intent is to destroy Israel... Big difference.

> voted for Hamas I needed to remind myself of how many times they did that (once). It is incredible that Palestine hasn't had an election since 2006. Ref: https://en.wikipedia.org/wiki/2006_Palestinian_legislative_e...

Yup, and as soon as Hamas were elected, the liberal world refused to deal with them. Never mind how convenient Hamas have been for Likud over the past few decades.

It looks incredibly hypocritical to much of the world, and I can see why.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#397

Earlier quoted context omitted.

The stock market does all sorts of silly things. If the stocks recover in 2 weeks to where they were, will that be deep seek erasing $1T and tech re-earning $1T? Or deep seek doing nothing?

> The stock market does all sorts of silly things. For sure. This one was pretty clear though. It's exactly what you'd expect when a moat evaporates overnight. Even if tech stocks recover in 2 weeks (doubt) an open source model comparable to o1 with a 50x efficiency gain is still not just another app. Which means there will be bad actors with a special interest in spreading narratives on every relevant forum...

>Which means there will be bad actors with a special interest in spreading narratives on every relevant forum

Which brings us neatly to OpenAI

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#398
post #6

So much effort in trying to tarnish DeepSeek the last 24hrs

Are you saying this report was falsified, or that the press should keep things like this secret?

It would be very nice if the press didn't just fall over itself trying to be a free PR agency for OpenAI.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#399
post #62

This is probably an incredibly stupid, off-topic question, but why are their database schemas and logs in English? Like, when a DeepSeek dev uses these systems as intended, would they also be seeing the columns, keys, etc. in English? Is there usually a translation step involved? Or do devs around the world just have to bite the bullet and learn enough English to be able to use the majority of tools? I'm realizing no…

Not only that, DeepSeek "thinks" in English!

When I interact with it by asking it a question in Spanish, the parts between the ... are in English before it goes on to answer in Spanish.

Give it a try in your favourite language.

I went on to ask it if it "thinks" in English, Spanish or Chinese but it just gives the pat answer that, being an LLM, it doesn't think in any language.

Re: Exposed DeepSeek database leaking sensitive information, including chat history

#400

Earlier quoted context omitted.

It might seem less credible to encounter English in a place where it’s less expected, but think of it this way: would a Yandex-developed ClickHouse database be adopted by Chinese devs if everything in it were written in Russian? There is some merit in asking your question, for there’s an unspoken rule (and a source of endless frustration) that business-/domain-related terms should remain in the language of their orig…

In the wild I've seen a company returning a JSON key "ankunftTime" in one of their APIs

In my experience, Germany is the most common exception to the "programming is done in English" rule.

In general, these things happen, and are not restricted to pre-Internet times - in fact, I most often see it in random webshit SaaS developed in Europe - things like, say, food delivery - Pyszne.pl and pizzaportal.pl (defunct) come to my mind. Those sites tend to be well-localized, so they seem like local businesses targeting the national market. But then you accidentally look at an URL deep in ordering form, or the ordering form breaks and you pull up dev tools to fix it, and suddenly you realize the SaaS operator is actually German or Swedish or Dutch, and they're just deploying the same platform across the EU, with a really good localization polish.

Post reply on HN