Rabbit failed to properly reset keys: emails can be sent from rabbit.tech domain
Rabbit Inc. failed to reset all keys, leaving a fifth API key active, potentially exposing email history and user data. Despite investigations, no evidence of data breaches or system compromises found.
Read original articleThe company Rabbit Inc. failed to properly reset all keys, allowing emails to be sent from rabbit.tech domains. Despite an internal investigation, they did not revoke a fifth hardcoded API key related to SendGrid, which remains active. This key provides access to email history and user information on the r1.rabbit.tech subdomain. Rabbit initially revoked four keys, causing a temporary service outage, but missed one buried deeper in the code. Proof of access was demonstrated by sending sample emails from Rabbit domains to journalists. Rabbit responded to allegations of a data breach by stating they were investigating and had not found evidence of customer data leaks or system compromises. The article also mentions a correction made to clarify the extent of available email data after its initial publication.
Related
KrebsOnSecurity Threatened with Defamation Lawsuit over Fake Radaris CEO
KrebsOnSecurity faced a defamation lawsuit threat for exposing Radaris' true owners, the Lubarsky brothers, linked to questionable practices. Despite demands, KrebsOnSecurity stood by its reporting, revealing a complex web of interconnected businesses.
Leaking URLs to the Clown
The author describes leaking URLs during Mac app testing, with a unique URL receiving requests from a random "cloud" service every three hours. This raises privacy concerns and highlights potential risks for users.
Snowflake breach snowballs as more victims, perps, come forward
The Snowflake data breach expands to include Ticketek, Ticketmaster, and Advance Auto Parts. ShinyHunters claim involvement, Snowflake enforces security measures. CDK faces ransomware attack, Juniper and Apple vulnerabilities identified. Jetflicks operators convicted.
Rabbit data breach: all r1 responses ever given can be downloaded
A data breach at Rabbit Inc. exposed critical API keys for ElevenLabs, Azure, Yelp, and Google Maps, compromising personal information and enabling malicious actions. Rabbit Inc. has not addressed the issue, urging users to unlink Rabbithole connections.
South Korean ISP Infected 600,000 Torrenting Subscribers with Malware
South Korea's KT accused of distributing malware to 600,000 subscribers to block torrent traffic, sparking privacy concerns and legal scrutiny. Police investigate organized hacking attempt by KT. Concerns raised over network interference.
Anyway, I'm looking forward to giving it a try, and I'll almost certainly never use it once I've kind of pawed through it and seen what seems good and what seems bad. Similar for that humane pin which I think I paid for but never even received.
If you read a lot of sci-fi, authors have put an immense amount of time into thinking about what UI looks like as we have supercompute/AI access more broadly, and I think it's clear that a phone isn't the final state for these interactions. What's less clear to me is what sort of compelling mid-way points there are between what we have now and ubiquitous environment-aware AGI (e.g. Minds from Iain Banks). It's one reason I thought humane's projector was really interesting; we do a lot of visual interaction in daily life, so an audio-only earbud isn't likely to be the be-all/end-all.
Anyway, hardware startup guys, please make more of these, and figure out what's going to be compelling when we've scaled up bandwidth, scaled down latency and scaled up local compute. I'm looking forward to buying it.
Rabbit data breach: all r1 responses ever given can be downloaded - https://news.ycombinator.com/item?id=40792684 - June 2024 (32 comments)
https://www.xda-developers.com/rabbit-nft-company-past/
The claims they made about the R1s capabilities even echoed claims they had previously made about their defunct GAMA "Quantum Engine" Web3 buzzword soup.
> Later, in August 2023, the "Quantum Engine" became OS2, a personalized operating system that could do things for you like order groceries.
Doesn't accessing the hard coded api keys imply to intrude the server in the first place?
[0] https://www.404media.co/researchers-prove-rabbit-ai-breach-b...
Are there any details on that?
Maybe they can add some MIDI ports and make some sort of funky pocket instrument.
I knew they were overhyping things with their pre-launch promises, but the reality of their engineering was much worse than I could have ever imagined.
Given the other claims, I don't doubt that researchers can do this. I just haven't yet seen a strong verification of this claim.
[0]https://www.404media.co/researchers-prove-rabbit-ai-breach-b...
Related
KrebsOnSecurity Threatened with Defamation Lawsuit over Fake Radaris CEO
KrebsOnSecurity faced a defamation lawsuit threat for exposing Radaris' true owners, the Lubarsky brothers, linked to questionable practices. Despite demands, KrebsOnSecurity stood by its reporting, revealing a complex web of interconnected businesses.
Leaking URLs to the Clown
The author describes leaking URLs during Mac app testing, with a unique URL receiving requests from a random "cloud" service every three hours. This raises privacy concerns and highlights potential risks for users.
Snowflake breach snowballs as more victims, perps, come forward
The Snowflake data breach expands to include Ticketek, Ticketmaster, and Advance Auto Parts. ShinyHunters claim involvement, Snowflake enforces security measures. CDK faces ransomware attack, Juniper and Apple vulnerabilities identified. Jetflicks operators convicted.
Rabbit data breach: all r1 responses ever given can be downloaded
A data breach at Rabbit Inc. exposed critical API keys for ElevenLabs, Azure, Yelp, and Google Maps, compromising personal information and enabling malicious actions. Rabbit Inc. has not addressed the issue, urging users to unlink Rabbithole connections.
South Korean ISP Infected 600,000 Torrenting Subscribers with Malware
South Korea's KT accused of distributing malware to 600,000 subscribers to block torrent traffic, sparking privacy concerns and legal scrutiny. Police investigate organized hacking attempt by KT. Concerns raised over network interference.