frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

https://alexschapiro.com/security/vulnerability/2025/12/02/filevine-api-100k
68•bearsyankees•36m ago

Comments

observationist•11m ago
I think this class of problems can be protected against.

It's become clear that the first and most important and most valuable agent, or team of agents, to build is the one that responsibly and diligently lays out the opsec framework for whatever other system you're trying to automate.

A meta-security AI framework, cursor for opsec, would be the best, most valuable general purpose AI tool any company could build, imo. Everything from journalism to law to coding would immediately benefit, and it'd provide invaluable data for post training, reducing the overall problematic behaviors in the underlying models.

Move fast and break things is a lot more valuable if you have a red team mechanism that scales with the product. Who knows how many facepalm level failures like this are out there?

canopi•10m ago
The first thing that comes to my mind is SOC2 HIPAA and the whole security theater.

I am one of the engineers that had to suffer through countless screenshots and forms to get these because they show that you are compliant and safe. While the real impactful things are ignored

quapster•10m ago
This is the collision between two cultures that were never meant to share the same data: "move fast and duct-tape APIs together" startup engineering, and "if this leaks we ruin people's lives" legal/medical confidentiality.

What's wild is that nothing here is exotic: subdomain enumeration, unauthenticated API, over-privileged token, minified JS leaking internals. This is a 2010-level bug pattern wrapped in 2025 AI hype. The only truly "AI" part is that centralizing all documents for model training drastically raises the blast radius when you screw up.

The economic incentive is obvious: if your pitch deck is "we'll ingest everything your firm has ever touched and make it searchable/AI-ready", you win deals by saying yes to data access and integrations, not by saying no. Least privilege, token scoping, and proper isolation are friction in the sales process, so they get bolted on later, if at all.

The scary bit is that lawyers are being sold "AI assistant" but what they're actually buying is "unvetted third party root access to your institutional memory". At that point, the interesting question isn't whether there are more bugs like this, it's how many of these systems would survive a serious red-team exercise by anyone more motivated than a curious blogger.

electric_muse•7m ago
While true this comment seems AI written. I did a fair bit of exploration around AI responses to HN threads and this fits the pattern.
snapcaster•3m ago
What makes you think that? it would need some prompt engineering if so since ChatGPT won't write like that (bad capitalization, lazy quoting) unless you ask it to
j45•3m ago
It's a little hilarious.

First, do all this cybersecurity theatre, and then create an MCP/LLM wormhole that bypasses it all.

All because non-technical folks wave their hands about AI and not understanding the most fundamental reality about LLM software being fundamentally so different than all the software before it that it becomes an unavoidable black hole.

I am also pleased I used two space analogies without the use of AI.

kylecazar•4m ago
If they have a billion dollar valuation, this fairly basic (and irresponsible) vulnerability could have cost them a billion dollars. If someone with malice had been in your shoes, in that industry, this probably wouldn't have been recoverable. Imagine a firm's entire client communications up on pastebin.

They should have given you some money.

chunk1000•2m ago
Thank you bearsyankees for keeping us informed.

Misha Glenny to Present BBC Radio 4's in Our Time

https://www.bbc.co.uk/mediacentre/2025/misha-glenny-in-our-time-bbc-radio-4
1•timthorn•42s ago•0 comments

Azure Innovations with Mark Russinovich, MSFT Ignite 2025 [video]

https://www.microsoft.com/en-us/research/video/inside-azure-innovations-with-mark-russinovich-mic...
1•whopdrizzard•1m ago•0 comments

Pipe dreams to pipeline realities: an Aspire Pipelines story

https://devblogs.microsoft.com/aspire/aspire-pipelines/
1•doomroot13•1m ago•0 comments

Show HN: Textwave – Versioning for Documents (free, local-only document editor)

https://textwaveapp.com/
1•domysee•1m ago•0 comments

Show HN: Microlandia, a brutally honest city builder

https://microlandia.city
1•phaser•2m ago•0 comments

Metrics That Actually Matter

https://jamesjboyer.substack.com/p/metrics-that-actually-matter
2•aesthetics1•3m ago•0 comments

Flow-Lenia: Towards open-ended evolution in cellular automata

https://arxiv.org/abs/2212.07906
2•snats•5m ago•0 comments

Steam Machine today, Steam Phones tomorrow

https://www.theverge.com/report/820656/valve-interview-arm-gaming-steamos-pierre-loup-griffais
1•ravenical•8m ago•2 comments

Ferrocene 25.11.0 Now Available

https://ferrous-systems.com/blog/ferrocene-25-11-0/
1•todsacerdoti•9m ago•0 comments

Hundreds of Porsche Cars in Russia Shut Down After Satellite System Failure

https://headlinesmonitor.com/porsche-russia-system-failure-vts-immobilized/
4•wslh•10m ago•0 comments

Show HN: Nerve – The AI Chief of Staff that does your actual work

https://www.usenerve.com
3•tluthra•11m ago•0 comments

YAMLResume: Resumes as Code in YAML

https://yamlresume.dev/
2•thunderbong•11m ago•0 comments

ChatGPT is down worldwide, conversations disappeared for users

https://www.bleepingcomputer.com/news/artificial-intelligence/chatgpt-is-down-worldwide-conversat...
1•vaylian•11m ago•0 comments

Stop Talking

https://gurkan.in/2025/12/stop-talking/
3•npstr•11m ago•0 comments

Show HN: Equations Explained Colorfully (KaTeX and Markdown)

https://p.migdal.pl/equations-explained-colorfully/
1•stared•11m ago•0 comments

Time in C++: Understanding std:chrono:steady_clock

https://www.sandordargo.com/blog/2025/12/03/clocks-part-3-steady_clock
1•ibobev•13m ago•0 comments

SmartTube YouTube app for Android TV breached to push malicious update

https://www.bleepingcomputer.com/news/security/smarttube-youtube-app-for-android-tv-breached-to-p...
1•ibobev•13m ago•0 comments

Sterile Neutrino Prediction Muddled by Latest Experiments

https://www.nytimes.com/2025/12/03/science/sterile-neutrinos-particle-physics.html
2•mzs•13m ago•2 comments

Show HN: Cross-Layer Transcoders for Qwen3

https://qwen3.bluelightai.com/
3•epimono•14m ago•0 comments

How many layers of nested mental states can humans track?

https://medium.com/@gp2030/how-many-layers-of-nested-mental-states-can-humans-track-e8a63ff08758
3•light_triad•14m ago•0 comments

Antikythera mechanism: oldest known computer discovered in shipwreck off Greece

https://www.livescience.com/antikythera-mechanism
1•gurjeet•15m ago•0 comments

Show HN: Entrig – Push notifications for Supabase without backend code

https://entrig.com/try
2•ibbie•15m ago•0 comments

Can LLMs Create Legally Relevant Summaries and Analyses of Videos?

https://arxiv.org/abs/2511.13772
1•PaulHoule•16m ago•0 comments

The Rise of AI Denialism

https://bigthink.com/the-present/the-rise-of-ai-denialism/
11•gradus_ad•16m ago•2 comments

Micron Announces Exit from Crucial Consumer Business

https://investors.micron.com/news-releases/news-release-details/micron-announces-exit-crucial-con...
4•simlevesque•16m ago•0 comments

When there's a crisis, three things can happen

https://www.todepond.com/sky/crisis/
1•surprisetalk•17m ago•0 comments

Stumbling

https://quarter--mile.com/stumbling
1•surprisetalk•17m ago•0 comments

Building an embeddable live demo into your landing page

https://www.databuddy.cc/blog/building-an-embeddable-live-analytics-demo-from-concept-to-reality
3•issanassar•17m ago•0 comments

DFOS

https://www.dfos.com/
2•surprisetalk•17m ago•0 comments

Show HN: Avolal – Book routine flights in 60 seconds

https://www.avolal.com
3•midito•17m ago•2 comments