Exposed DeepSeek database leaking sensitive information, including chat history
1–10 of 499 posts
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#2Re: Exposed DeepSeek database leaking sensitive information, including chat history
#3Not only that, this was a "production-grade" database with millions of users using it and the app was #1 on the app store and ALL text sent there in the prompts was logged in plain-text?
Unbelievable.
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#4> More critically, the exposure allowed for full database control and potential privilege escalation within the DeepSeek environment, without any authentication or defense mechanism to the outside world. Not only that, this was a "production-grade" database with millions of users using it and the app was #1 on the app store and ALL text sent there in the prompts was logged in plain-text? Unbelievable.
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#5Seems like the kind of mistake you would make if you are not used to deploying external client facing applications.
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#6Re: Exposed DeepSeek database leaking sensitive information, including chat history
#7ed: I was wrong!
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#8So much effort in trying to tarnish DeepSeek the last 24hrs
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#9So much effort in trying to tarnish DeepSeek the last 24hrs
Kinda like how your comment was grey within 1 minute, despite stating an objective truth.
Sure, this is to be expected given the billions and billions of dollars at stake but like - that money is gone lol. DeepSeek isn't going back in the bottle, nor is open source AI in general.
Re: Exposed DeepSeek database leaking sensitive information, including chat history
#10This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle. Seems like the kind of mistake you would make if you are not used to deploying external client facing applications.
Can we stop with this nonsense ?
The list of author of the paper is public, you can just go look it up. There are ~130 people on the ML team, they have regular ML background just like you would find at any other large ML labs.
Their infra cost multiple millions of dollar per month to run, and the salary of such a big team is somewhere in the $20-50M per year (not very au fait of the market rate in china hence the spread).
This is not a sideproject.
Edit: Apparently my comment is confusing some people. Am not arguing that ML people are good at security. Just that DS is not the side project of a bunch of quant bros.