frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

https://alexschapiro.com/security/vulnerability/2025/12/02/filevine-api-100k
80•bearsyankees•45m ago

Comments

observationist•20m ago
I think this class of problems can be protected against.

It's become clear that the first and most important and most valuable agent, or team of agents, to build is the one that responsibly and diligently lays out the opsec framework for whatever other system you're trying to automate.

A meta-security AI framework, cursor for opsec, would be the best, most valuable general purpose AI tool any company could build, imo. Everything from journalism to law to coding would immediately benefit, and it'd provide invaluable data for post training, reducing the overall problematic behaviors in the underlying models.

Move fast and break things is a lot more valuable if you have a red team mechanism that scales with the product. Who knows how many facepalm level failures like this are out there?

canopi•18m ago
The first thing that comes to my mind is SOC2 HIPAA and the whole security theater.

I am one of the engineers that had to suffer through countless screenshots and forms to get these because they show that you are compliant and safe. While the real impactful things are ignored

quapster•18m ago
This is the collision between two cultures that were never meant to share the same data: "move fast and duct-tape APIs together" startup engineering, and "if this leaks we ruin people's lives" legal/medical confidentiality.

What's wild is that nothing here is exotic: subdomain enumeration, unauthenticated API, over-privileged token, minified JS leaking internals. This is a 2010-level bug pattern wrapped in 2025 AI hype. The only truly "AI" part is that centralizing all documents for model training drastically raises the blast radius when you screw up.

The economic incentive is obvious: if your pitch deck is "we'll ingest everything your firm has ever touched and make it searchable/AI-ready", you win deals by saying yes to data access and integrations, not by saying no. Least privilege, token scoping, and proper isolation are friction in the sales process, so they get bolted on later, if at all.

The scary bit is that lawyers are being sold "AI assistant" but what they're actually buying is "unvetted third party root access to your institutional memory". At that point, the interesting question isn't whether there are more bugs like this, it's how many of these systems would survive a serious red-team exercise by anyone more motivated than a curious blogger.

electric_muse•15m ago
While true this comment seems AI written. I did a fair bit of exploration around AI responses to HN threads and this fits the pattern.
snapcaster•11m ago
What makes you think that? it would need some prompt engineering if so since ChatGPT won't write like that (bad capitalization, lazy quoting) unless you ask it to
simonw•5m ago
That comment didn't read like AI generated content to me.
j45•11m ago
It's a little hilarious.

First, as an organization, do all this cybersecurity theatre, and then create an MCP/LLM wormhole that bypasses it all.

All because non-technical folks wave their hands about AI and not understanding the most fundamental reality about LLM software being fundamentally so different than all the software before it that it becomes an unavoidable black hole.

I'm also a little pleased I used two space analogies, something I can't expect LLMs to do because they have to go large with their language or go home.

kylecazar•13m ago
If they have a billion dollar valuation, this fairly basic (and irresponsible) vulnerability could have cost them a billion dollars. If someone with malice had been in your shoes, in that industry, this probably wouldn't have been recoverable. Imagine a firm's entire client communications and discovery posted online.

They should have given you some money.

chunk1000•10m ago
Thank you bearsyankees for keeping us informed.
jacquesm•6m ago
That doesn't surprise me one bit. Just think about all the confidential information that people post into their Chatgpt and Claude sessions. You could probably keep the legal system busy for the next century on a couple of days of that.
icyfox•4m ago
I'm always a bit surprised how long it can take to triage and fix these pretty glaring security vulnerabilities. This was (what I imagine to be) a <1hr fix plus the time for QA testing to make sure it didn't break anything.

Is the issue that people aren't checking their security@ email addresses? People are on holiday? These emails get so much spam it's really hard to separate the noise from the legit signal? I'm genuinely curious.

Steam Deck lead reveals Valve is funding ARM compatibility of Windows games

https://frvr.com/blog/news/steam-deck-lead-reveals-valve-is-funding-arm-compatibility-of-windows-...
160•OsrsNeedsf2P•1h ago•75 comments

Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

https://alexschapiro.com/security/vulnerability/2025/12/02/filevine-api-100k
88•bearsyankees•45m ago•14 comments

1D Conway's Life glider found, 3.7B cells long

https://conwaylife.com/forums/viewtopic.php?&p=222136#p222136
89•nooks•1h ago•19 comments

MinIO is now in maintenance-mode

https://github.com/minio/minio/commit/27742d469462e1561c776f88ca7a1f26816d69e2
201•hajtom•2h ago•122 comments

Launch HN: Phind 3 (YC S22) – Every answer is a mini-app

19•rushingcreek•42m ago•14 comments

RCE Vulnerability in React and Next.js

https://github.com/vercel/next.js/security/advisories/GHSA-9qr9-h5gf-34mp
120•rayhaanj•2h ago•32 comments

How to Synthesize a House Loop

https://loopmaster.xyz/tutorials/how-to-synthesize-a-house-loop
85•stagas•5d ago•21 comments

Stop Talking

https://gurkan.in/2025/12/stop-talking/
10•npstr•19m ago•2 comments

Rocketable (YC W25) is hiring a founding engineer to automate software companies

https://www.ycombinator.com/companies/rocketable/jobs/CArgzmX-founding-engineer-automation-platform
1•alanwells•1h ago

Congressional lawmakers 47% pts better at picking stocks

https://www.nber.org/papers/w34524
655•mhb•4h ago•397 comments

You Can't Fool the Optimizer

https://xania.org/202512/03-more-adding-integers
179•HeliumHydride•6h ago•104 comments

GSWT: Gaussian Splatting Wang Tiles

https://yunfan.zone/gswt_webpage/
50•klaussilveira•3h ago•12 comments

Shrinking While Linking

https://www.tweag.io/blog/2025-11-27-shrinking-static-libs/
11•ingve•3d ago•1 comments

A Look at Rust from 2012

https://purplesyringa.moe/blog/a-look-at-rust-from-2012/
120•todsacerdoti•1w ago•31 comments

Are we repeating the telecoms crash with AI datacenters?

https://martinalderson.com/posts/are-we-really-repeating-the-telecoms-crash-with-ai-datacenters/
85•davedx•7h ago•42 comments

Prompt Injection via Poetry

https://www.wired.com/story/poems-can-trick-ai-into-helping-you-make-a-nuclear-weapon/
7•bumbailiff•28m ago•3 comments

Zig quits GitHub, says Microsoft's AI obsession has ruined the service

https://www.theregister.com/2025/12/02/zig_quits_github_microsoft_ai_obsession/
789•Brajeshwar•10h ago•441 comments

Why are my headphones buzzing whenever I run my game?

https://alexene.dev/2025/12/03/Why-do-my-headphones-buzz-when-i-run-my-game.html
73•pacificat0r•2h ago•67 comments

Show HN: Fresh – A new terminal editor built in Rust

https://sinelaw.github.io/fresh/
9•_sinelaw_•3h ago•7 comments

Interview with RollerCoaster Tycoon's Creator, Chris Sawyer (2024)

https://medium.com/atari-club/interview-with-rollercoaster-tycoons-creator-chris-sawyer-684a0efb0f13
235•areoform•13h ago•42 comments

Helldivers 2 devs slash install size from 154GB to 23GB

https://www.tomshardware.com/video-games/pc-gaming/helldivers-2-install-size-slashed-from-154gb-t...
278•doener•5h ago•202 comments

Super fast aggregations in PostgreSQL 19

https://www.cybertec-postgresql.com/en/super-fast-aggregations-in-postgresql-19/
190•jnord•1w ago•18 comments

universal-tbxi-patchset: Mac OS New World ROM patchset to boot System 7.5

https://github.com/Wack0/universal-tbxi-patchset
27•classichasclass•4d ago•2 comments

VA staff flag dangerous errors in Oracle-built electronic health record

https://www.washingtonpost.com/investigations/2025/12/03/veterans-administration-va-hospitals-hea...
60•ksenzee•2h ago•7 comments

Anthropic reportedly preparing for $300B IPO

https://vechron.com/2025/12/anthropic-hires-wilson-sonsini-ipo-2026-openai-race/
158•GeorgeWoff25•8h ago•120 comments

Anthropic acquires Bun

https://bun.com/blog/bun-joins-anthropic
2079•ryanvogel•1d ago•998 comments

Paged Out

https://pagedout.institute
539•varjag•22h ago•57 comments

Researchers Find Microbe Capable of Producing Oxygen from Martian Soil

https://scienceclock.com/microbe-that-could-turn-martian-dust-into-oxygen/
84•ashishgupta2209•11h ago•32 comments

The Writing Is on the Wall for Handwriting Recognition

https://newsletter.dancohen.org/archive/the-writing-is-on-the-wall-for-handwriting-recognition/
149•speckx•1w ago•84 comments

The "Mad Men" in 4K on HBO Max Debacle

http://fxrant.blogspot.com/2025/12/the-mad-men-in-4k-on-hbo-max-debacle.html
323•tosh•6h ago•143 comments