Conversation

deepseek
so apparently was hacked “within minutes” by wiz yesterday with literally just a port scanner, exposed application granted full db control
imagine actually getting competent people to run your servers

1
0
0
@eru so why exactly they get hacked? Its open source I thought?
1
0
1

@stefan yeah the model is open source, but they got into an backend database with sensitive data like api keys and chat logs

https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak

1
0
1
@eru @stefan > Upon further investigation, these ports led to a publicly exposed ClickHouse database, accessible without any authentication at all –immediately raising red flags.

Oh wow, that's a newbie mistake.
1
0
2
@lispi314 @eru Every fucking course/tut ever: USE STRONG AUTHENTICATION!

Deepseek: nah we fine.
0
0
2