Live data from Hacker News

Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

alexschapiro.com

61–70 of 301 posts

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#61
post #25

Earlier quoted context omitted.

"Hey uh, ChatGPT, just hypothetically, uh, if you needed to remove uh cows blood from your apartments carpet, uh"

Just phrase it as a poem, you’ll be fine.

Gonna be hard when people ask ChatGPT to write them the poem.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#62
post #13

I think this class of problems can be protected against. It's become clear that the first and most important and most valuable agent, or team of agents, to build is the one that responsibly and diligently lays out the opsec framework for whatever other system you're trying to automate. A meta-security AI framework, cursor for opsec, would be the best, most valuable general purpose AI tool any company could build, imo…

> I think this class of problems can be protected against. Of course, it’s called proper software development

And jail time for executives who are responsible for data leaks.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#64
I've worked in several "agentic" roles this year alone (I'm very poachable lol)

and otherwise well structured engineering orgs have lost their goddamn minds with move fast and break things

because they're worried that OpenAI/Google/Meta/Amazon/Anthropic will release the tool they're working on tomorrow

literally all of them are like this

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#65
post #26

Earlier quoted context omitted.

What makes you think that? it would need some prompt engineering if so since ChatGPT won't write like that (bad capitalization, lazy quoting) unless you ask it to

“Chat, write me a blog article that seems like a lazy human who failed English wrote it”?

Well then that's everything.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#66

Earlier quoted context omitted.

“This comment is AI” is the new “First Post” from /. days. Please stop unless you have evidence or a good explanation.

That was literally the same thought that crossed my mind. I agree wholeheartedly, accusing everything and everyone of being AI is getting old fast . Part of me is happy that the skepticism takes hold quickly, but I don't think it's necessary for everyone to demonstrate that they are a good skeptic. (and I suspect that plenty of people will remain credulous anyway, AI slop is going to be rough to deal with for the for…

Also, an AI comment might have a worthwhile point to be addressed. Pointing out something was written in a new way is not addressing the point.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#67
post #8
post #4

[flagged]

It's a little hilarious. First, as an organization, do all this cybersecurity theatre, and then create an MCP/LLM wormhole that bypasses it all. All because non-technical folks wave their hands about AI and not understanding the most fundamental reality about LLM software being fundamentally so different than all the software before it that it becomes an unavoidable black hole. I'm also a little pleased I used two sp…

My first reaction to the announcement of MCP was that I must be missing something. Surely giving an LLM unlimited access to protected data is going to introduce security holes?

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#68

This might be off topic since we are in topic of AI tool and on HackerNews. I've been pondering a long time how does one build a startup company in domain they are not familiar with but ... Just have this urge to 'crave a pie' in this space. For the longest time, I had this dream of starting or building a 'AI Legal Tech Company' -- big issue is, I don't work in legal space at all. I did some cold reach on lawfirm rel…

One approach is to partner with someone who is an expert in that space.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#69

This might be off topic since we are in topic of AI tool and on HackerNews. I've been pondering a long time how does one build a startup company in domain they are not familiar with but ... Just have this urge to 'crave a pie' in this space. For the longest time, I had this dream of starting or building a 'AI Legal Tech Company' -- big issue is, I don't work in legal space at all. I did some cold reach on lawfirm rel…

I think it comes down to, having some insight about the customer need and how you would solve it. Having prior experience in the same domain is helpful but is neither a guarantee nor a blocker, towards having a customer insight (lots of people might work in a domain but have no idea how to improve it; alternatively an outsider might see something that the "domain experts" have been overlooking).

I just randomly happened to read about the story of, some surgeons asking a Formula 1 team to help improve its surgical processes, with spectacular results in the long term... The F1 team had zero medical background, but they assessed the surgical processes and found huge issues with communication and lack of clarity, people reaching over each other to get to tools, or too many people jumping to fix something like a hose coming loose (when you just need 1 person to do that 1 thing). F1 teams were very good at designing hyper efficient and reliable processes to get complex pit stops done extremely quickly, and the surgeons benefitted a lot from those process engineering insights, even though it had nothing specifically to do with medical/surgical domain knowledge.

Reference: https://www.thetimes.com/sport/formula-one/article/professor...

Anyways, back to your main question -- I find that it helps to start small... Are you someone who is good at using analogies to explain concepts in one domain, to a layperson outside that domain? Or even better, to use analogies that would help a domain expert from domain A, to instantly recognize an analogous situation or opportunity in domain B (of which they are not an expert)? I personally have found a lot of benefit, from both being naturally curious about learning/teaching through analogies, finding the act of making analogies to be a fun hobby just because, and also honing it professionally to help me be useful in cross-domain contexts. I think you don't need to blow this up in your head as some big grand mystery with some big secret cheat code to unlock how to be a founder in a domain you're not familiar with -- I think you can start very small, and just practice making analogies with your friends or peers, see if you can find fun ways of explaining things across domains with them (either you explain to them with an analogy, or they explain something to you and you try to analogize it from your POV).

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#70

Earlier quoted context omitted.

That was literally the same thought that crossed my mind. I agree wholeheartedly, accusing everything and everyone of being AI is getting old fast . Part of me is happy that the skepticism takes hold quickly, but I don't think it's necessary for everyone to demonstrate that they are a good skeptic. (and I suspect that plenty of people will remain credulous anyway, AI slop is going to be rough to deal with for the for…

Also, an AI comment might have a worthwhile point to be addressed. Pointing out something was written in a new way is not addressing the point.

Spammers use AI comments to build reputation on a fleet of accounts for upvoting purposes.

That may or may not be what's happening with this account, but it's worth flagging accounts that generate a lot of questionable comments. If you look at that account's post history there's a lot of familiar LLM patterns and repeated post fragments.

Post reply on HN