Earlier quoted context omitted.
Every other headline and conversation having ai is super annoying. But also, its super annoying to sift through people saying "the word critical was used, this is obviously ai!". not to mention it really fucking sucks when you're the person who wrote something and people start chanting "ai slop! ai slop!". like, how am i going to prove is not AI? I can't wait until ai gets good enough that no one can tell the differe…
Cultural acceptance of conversation with AI should've come because of actual AI that are indistinguishable from humans, being forced to swallow recognizable if not blatant LLM slop and turn a blind eye feels unfair
Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files
71–80 of 301 posts
Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files
#72Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files
#73And... Margolis allowed this open demo environment to connect to their ENTIRE Box drive of millions of super sensitive documents?
HUH???!
Before you get to the terrible security practices of the vendor, you have to place a massive amount of blame on the IT team of Margolis for allowing the above.
No amount of AI hype excuses that kind of professional misjudgement.
Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files
#74> ... after looking through minified code, which SUCKS to do ... AI tends to be good at un-minifying code.
Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files
#75Earlier quoted context omitted.
> I think this class of problems can be protected against. Of course, it’s called proper software development
And jail time for executives who are responsible for data leaks.
Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files
#76I work for a finance firm and everyone is wondering why we can store reams of client data with SaaS Company X, but not upload a trust document or tax return to AI SaaS Company Y. My argument is we're in the Wild West with AI and this stuff is being built so fast with so many evolving tools that corners are being cut even when they don't realize it. This article demonstrates that, but it does sort of beg the question…
Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files
#77I'm always a bit surprised how long it can take to triage and fix these pretty glaring security vulnerabilities. October 27, 2025 disclosure and November 4, 2025 email confirmation seems like a long time to have their entire client file system exposed. Sure the actual bug ended up being (what I imagine to be) a Is the issue that people aren't checking their security@ email addresses? People are on holiday? These emai…
A lot of the time it’s less “nobody checked the security inbox” and more “the one person who understands that part of the system is juggling twelve other fires.” Security fixes are often a one-hour patch wrapped in two weeks of internal routing, approvals, and “who even owns this code?” archaeology. Holiday schedules and spam filters don’t help, but organizational entropy is usually the real culprit.
And of course nobody remembered the setup, and logging was only accessible by the same person, so figuring out also took weeks.
Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files
#78I worked at Google and then at Meta. Man, the amount of "nonsense" of the ACL system was insane. I write nonsense in quotes because for sure from a security point of view it all made a lot of sense. But there is exactly zero chance that such a system can be used in a less technical company. It took me 4 years to understand how it worked...
So I'll take this as another data point to create a startup that simplifies security... Seems a lot more complicated than AI
Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files
#79Earlier quoted context omitted.
security@ emails do get a lot of spam. It doesn't get talked about very much unless you're monitoring one yourself, but there's a fairly constant stream of people begging for bug bounty money for things like the Secure flag not being set on a cookie. That said, in my experience this spam is still a few emails a day at the most, I don't think there's any excuse for not immediately patching something like that. I guess…
This. There is so much spam from random people about meaningless issues in our docs. AI has made the problem worse. Determining the meaningful from the meaningless is a full time job.
The other half was people demanding payment.
Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files
#80Earlier quoted context omitted.
That comment didn't read like AI generated content to me. It made useful points and explained them well. I would not expect even the best of the current batch of LLMs to produce an argument that coherent. This sentence in particular seems outside of what an LLM that was fed the linked article might produce: > What's wild is that nothing here is exotic: subdomain enumeration, unauthenticated API, over-privileged token…
The users' comment history does read like generic LLM output. Look at the first lines of different comments: > Interesting point about Cranelift! I've been following its development for a while, and it seems like there's always something new popping up. > Interesting point about the color analysis! It kinda reminds me of how album art used to be such a significant part of music culture. > Interesting point about the…
Yes, if this is LLM then it definitely wouldn't be zero-shot. I'm still on the fence myself as I've seen similar writing patterns with Asperger's (specifically what used to be called Asperger's; not general autism spectrum) but those comments don't appear to show any of the other tells to me, so I'm not particularly confident one way or the other.