Rabbit data breach: all r1 responses ever given can be downloaded
rabbitu.de
rabbitu.de
So this is the IT literacy of AI startups...
"please don't under estimate the effort and IQ level of our eng - its much more complicated than that."
I present no other commentary.
https://techcrunch.com/2024/06/15/ftc-chair-lina-khan-on-sta...
It’s not even accurate sometimes and I definitely did not manually tell it things about me. But it made some incorrect assumptions and now it’s out there whether it’s true or not.
[0]: https://www.adweek.com/media/openai-preferred-publisher-prog...
Remind me how many billions was this supposedly worth?
I even changed banks (after 20 years), because I was looking to link my account to a budget app and my old bank required a 3rd party service that cached login data. I went through and tried connecting about 2 dozen banks that seemed like contenders to find the 2 or 3 that allowed me to authenticate properly with a token I could revoke from the bank itself, and switched to one of those. I don't know who these people are that hand over things like bank creds based on trust alone. The R1 wasn't there yet, but I'm cure that was a future goal.
> the rabbit team is aware of this leaking of api keys and have chosen to ignore it. the api keys continue to be valid as of writing
That's just damning. Making the mistake is one thing, but, having it pointed out to you and refusing to fix it is unconscionable.
Anybody can string a couple of API calls together and write an "app". That is not programming, and this project is a massive undertaking for somebody of their skill. It should have never gone to market to begin with, regulations should have stopped it on its feet. The fact that they put more effort into their "key note" than the actual product was already a red flag. It's like some marketing guys got together and decided that they were going to "take the world by storm with AI".
> we have internal confirmation that the rabbit team is aware of this leaking of api keys and have chosen to ignore it. the api keys continue to be valid as of writing.
Yeah.
It is rather clear to me that yazzku is saying that the programming required to pull of what the R1 does falls well below what Rabbit promised their customers. That this is such a bullshit design that we can infer that the entire product is a scam, because if they were serious it wouldn't be so obvious that no work into actually making a useful product.
Yes it is. Simple as.
Please don't gatekeep something as casual as writing code. Good lord.
To me it has nothing to do with size or complexity. You can have a 20-line well-thought-out imperative Python script that is well-engineered. And you can have a 200,000 line Java app that leaks PII all over the place, loses user data twice a week, and is impossible to debug because it's a giant spaghetti rats nest.
When they rug-pulled GAMA (after selling a bunch of NFTs), as consolation prize they "open sourced"[0] a few things.
One of their many promises was that their space-station "metaverse" would have "Quantum Engine AI Integration" (letting you talk to NPCs, among other things). They released a lightly edited Unreal Engine game template (the "metaverse"), along side a file named `api.yml`[1] which documents an AsyncAPI[2] API (the "AI integration"). There is no actual integration, the API spec is just positioned adjacent to the Unreal project - there's a note in the README that amounts to "integrate it yourself".
The back-end component was never open-sourced, and they've long since shut down the API server, but based on the docs, the API used by the r1 is clearly a direct evolution of that design.
As for the R1's API, there is no documentation, but I partially reverse-engineered it and wrote some docs of my own[3], which is enough to see the similarities.
[0] https://github.com/gamaspacestation/
[1] https://github.com/gamaspacestation/gss_release/blob/main/ap...
[3] https://gist.github.com/DavidBuchanan314/aafce6ba7fc49b19206...
I wish there was a mechanism on HN to link related (but different) stories - beyond people in the comments I mean. I think it would be especially useful over time (eg I could relate these today because they’re both on front page at the same time, but if someone came across this in the future the relationship may have been lost)