Rabbit R1 makes catastrophic rookie programming mistake

preview_player
Показать описание
A group of jailbreakers recently discovered that the Rabbit R1 codebase contains hardcoded API keys - giving them easy access to user data from their AI tech-to-speech service.

#programming #hacking #thecodereport

🔥 New Full Linux Course coming soon!

Use code LINUX30 for 30% off PRO access

💬 Chat with Me on Discord

🔗 Resources

🎨 My Editor Settings

- Atom One Dark
- vscode-icons
- Fira Code Font

🔖 Topics Covered

- Problems with Rabbit R1
- What to when sensitive data is leaked?
- Major mistakes made by programmers
- AI tools that have failed
- Hacking incidents of 2024
- API key safety tips
Рекомендации по теме
Комментарии
Автор

It's shocking how Rabbit R1 still manages to disappoint despite everyone having zero expectations

Requiem
Автор

its almost as if they tried to rush out a scam as fast as possible to sell to people before they vanished

awesomedavid
Автор

They could say the bricked models are in “paperweight mode” and just call it a feature.

derektata
Автор

Wow this thing is really the "I threw node modules together that I didn't really understand" of AI

snake
Автор

"half baked" is a very generous description of the Rabbit. That batter was still wet

dillbourne
Автор

everyone is scrambling to not be compared to rabbit-r1

JohnneyleeRollins
Автор

Tough times for a device that's obviously just a smartphone but worse.

tHebUm
Автор

1:19 "Hi mom, I miss you." 🥺😔

mahmutpekkara
Автор

So the R1 was essentially some kid's middle school science project that somehow became a product.

xpkareem
Автор

This is like old school weekend update.
“Rabbit one exploit found that allows someone to read and edit any message!”
“This has affected… 8 users around the nation”

lukesjukes
Автор

Imagine a whole team of engineers ignoring a hard coded api key like this...

I think we're all going to make it (to a high paying SE job) bros...

Flappy
Автор

"Chuck it in the Kola superdeep borehole" — shows a photo of the kimberlite mine "Mir" in Sakha Republic...

vrtxxxx
Автор

Thanks, I will keep this in mind when I’m asking for millions of dollars for my new tech-AI startup company

noahm
Автор

I find it funny how a lot of the products we think are super complex, professional, ‘industry-standard’, ‘at-scale’, and well engineered are often poorly made grifts obfuscated by the mystique of private software. And when you try to call it a grift every ego within a one mile radius goes thermonuclear.

Everybody thinks they’re Alan Turing once they learn how to use an SDK and build an API to make a CRUD app with infinite skins :) And I’m directly referencing that ugly man child behind the scam companies.

sandman.
Автор

“I was blown away by its utter uselessness along with the amount of cringe buzzwords used by its CEO” describes literally every “AI Startup” founded after OpenAI released GPT to the public

theactualslimshady
Автор

Considering they hardcoded Spotify to play any Beatles song, I'm not surprised if they hardcoded api key

yumekarisu
Автор

"I was blow away by it's uselessness" is such a good way to describe the rabbit

TheMassgames
Автор

I made the mistake of pushing an API key for a web page I was working on in college. Never... again... I'm still getting emails from Git Guardian.

OUmSKILLS
Автор

nothing wrong with client side API KEYS, in fact they are required for example in firebase clients, it only becomes an issue when the key gives you access to things you shouldnt have access to

NTonik
Автор

Rabbit hole❌️
Loophole✅️
Edit: My new record for likes on a comment

Random_MCrafter