this post was submitted on 30 Jan 2025
12 points (100.0% liked)

Technology

1012 readers
103 users here now

A tech news sub for communists

founded 2 years ago
MODERATORS
 

[...] a publicly accessible ClickHouse database linked to DeepSeek, completely open and unauthenticated, exposing sensitive data. It was hosted at oauth2callback.deepseek.com:9000 and dev.deepseek.com:9000.

This database contained a significant volume of chat history, backend data and sensitive information, including log streams, API Secrets, and operational details.

More critically, the exposure allowed for full database control and potential privilege escalation within the DeepSeek environment, without any authentication or defense mechanism to the outside world.

It seems that the Empire has decided to strike.

you are viewing a single comment's thread
view the rest of the comments
[โ€“] maodun@lemmygrad.ml 8 points 7 hours ago* (last edited 7 hours ago) (1 children)

internet-connected vulnerabilities seems relatively avoidable to the individual user if you're able to run it locally, which is a feature of deepseek that isn't available via competitor AI services. I thought that was one of the main reasons it's giving openai & chatgpt a run for their money? that you could download it yourself and with decent enough specs run it completely locally and without internet connection.

also, statistical models used by LLMs don't store data that could eg be used to steal someone's identity, so the headline/first few paragraphs of alarmist "security" concerns is misleading. because, at least from me just skimming it, they're crowing about accessing certain backends and ""highly sensititive information"" when it's like... chat log between the devs??? of course that's sensitive info and the devs themselves should care about securing it. but the framing is again, misleading, lowkey clickbait in trying to play it/ambiguous reading as "this program retains chat logs submitted to feed the learning datasets"... like the general public doesn't know how tech works, so much alarmism about "ai stealing my art/fanfic" because they dont understand none of that gets stored in the algorithm/model, so it's easy to make the headline read like that to people who already think that way. ergo, reads like an advert to scaremonger people who are relatively tech-illiterate

[โ€“] itsraining@lemmygrad.ml 4 points 7 hours ago

thank you for the analysis