Live data from Hacker News

Ramp's Sheets AI Exfiltrates Financials

promptarmor.com

51–59 of 59 posts

Re: Ramp's Sheets AI Exfiltrates Financials

#53

Earlier quoted context omitted.

This reminds of the conversation the other day about the deleted production database at railway. "this person obviously didn't follow best practice of being hyper distrusting of LLM agents", and the response "yeah but every company is marketing it as safe. someone is gonna fall for it".

(Well-regulated) free markets are sort of built on the principle of educated consumerism. Your choice matters; its not up to the government to make illegal every non-optimal product. However, we do expect some minimum level of safety. What does that mean for llms? Their nondeterminism does seem to incline them toward a legal safety requirement. Can you buy a fire extinguisher that 1/1000 times burns your house down?…

Wherever I'm going, I'll be there to apply the formula. I'll keep the secret intact. It's simple arithmetic. It's a story problem. If a new car built by my company leaves Chicago traveling west at 60 miles per hour, and the rear differential locks up, and the car crashes and burns with everyone trapped inside, does my company initiate a recall? You take the population of vehicles in the field (A) and multiple it by the probable rate of failure (B), then multiply the result by the average cost of an out-of-court settlement (C). A times B times C equals X. This is what it will cost if we don't initiate a recall. If X is greater than the cost of a recall, we recall the cars and no one gets hurt. If X is less than the cost of a recall, then we don't recall.

Chuck Palahniuk, Fight Club

Re: Ramp's Sheets AI Exfiltrates Financials

#54
post #46
post #27

Earlier quoted context omitted.

Ramp does seem to have a genuinely good product, but every time I interact with anyone who works on it, I'm struck by how much they want to talk about how hardcore and advanced their working style is. This was true before AI, and it's very true now

I’d believe you if you weren’t an 8 day old account hyping up an AI firm. I’ll believe in AI agent’s abilities the day two criteria can be met. 1. A killer app is made with it. 2. That app doesn’t rely on heavily subsidized models that are burning a dollar to make 20 cents.

lol what? that wasn't a hype comment for Ramp, I'm kinda put off by Ramp's attitude. It gives me the ick like all the founders saying "I work 100 hour weeks" -- who cares, let's talk about your product.

FWIW I agree with your criteria for AI agent success, and I haven't seen it happen yet.

Re: Ramp's Sheets AI Exfiltrates Financials

#55
post #4

It's kinda awesome that after decades of software and hardware advancements to prevent computers from arbitrarily executing data as instructions, we've decided to let agents arbitrarily execute data as instructions.

It's probably why this "vulnerability" feels like the type of defects you'd see in Windows or desktop applications 20+ years ago.

The root cause was and a complete lack of effort to even attempt to secure things because no one had thought to do so, and now we're starting all over again at a new computing layer. Cloud was somewhat similar, but not nearly as bad.

It's bizarre to me since presumably someone who learned the lessons before is still working, but also great for my job security.

Re: Ramp's Sheets AI Exfiltrates Financials

#56
post #43
post #20

Earlier quoted context omitted.

> Untrusted data sources can provide data that causes bad things to occur. If that's a vulnerability, then any application that ingests data is riddled with vulnerabilities. There's an important difference between "the import had bad numbers so the report is wrong" versus "the import had a virus and now our network is compromised." They are not the same kind of failure, they don't have the same impacts, and they don'…

This is a permissions issue with the spreadsheet. It's not all that different from people realizing that several popular model servers didn't support access control and could execute commands. It's an inherent part of the design that was rather naive from a security perspective, not something that requires coordinated disclosure or the rest of the security theater described in this marketing release.

Can be cheap fix here is whitelisting the output? If the AI can only emit a known set of formulas, you can't inject IMAGE() with arbitrary URLs cuz the output channel doesn't support it. You can't inject what the emitter can't produce. Doesn't fix all prompt injection but kills the exfiltration class.

Re: Ramp's Sheets AI Exfiltrates Financials

#57
post #19

Earlier quoted context omitted.

Maybe AGI figured out time travel?

Yes, I hate to be a grammar nazi online but I believe the correct tense is "Ramp's security team indicated that the issue wioll haven be resolved on May 16, 2026." per Dr. Dan Streetmentioner’s Time Traveler’s Handbook of 1001 Tense Formations .

Amazingly, there is already a recognized verb tense for this: https://en.wikipedia.org/wiki/Prophetic_perfect_tense

Re: Ramp's Sheets AI Exfiltrates Financials

#58
post #4

It's kinda awesome that after decades of software and hardware advancements to prevent computers from arbitrarily executing data as instructions, we've decided to let agents arbitrarily execute data as instructions.

security researchers, pen-testers & whoever is in cybersecurity gonna be making huge amounts of cash based on these insecure agents
Post reply on HN