时间:2025-05-01 17:31:19 来源:网络整理编辑:熱點
"All [Rabbit] R1 responses ever given can be downloaded," according to an R1 research group called R
"All [Rabbit] R1 responses ever given can be downloaded," according to an R1 research group called Rabbitude.
Rabbit and its R1 AI device has already been dunked on for being nothing more than an Android app wrapped up in a hardware gadget, but something much more alarming is afoot.
SEE ALSO:I tested Rabbit R1 vs. Meta AI: The winning AI assistant will surprise youThe report (via The Verge) said Rabbitude gained access to the codebase and discovered API keys were hardwired into its code. That means anyone with these keys could "read every response every r1 has ever given, including ones containing personal information, brick all r1s, alter the responses of all r1s [and] replace every r1’s voice." The investigation discovered that these API keys are what provided access to ElevenLabs and Azure for text-to-speech generation, Yelp for reviews, and Google Maps for location data.
What's worse, Rabbitude said it identified the security flaw on May 16 and that Rabbit was aware of the issue. But "the API keys continue to be valid as of writing," on June 25. Continued access to the API keys means bad actors could potentially access sensitive data, crash the entire rabbitOS system, and add custom text.
The following day (June 26) Rabbit issued a statement on its Discord server saying that the four API keys Rabbitude identified have been revoked. "As of right now, we are not aware of any customer data being leaked or any compromise to our systems," said the company.
But the plot thickens. Rabbitude also found a fifth API key that was hardwired in the code, but not publicly disclosed in its investigation. This one is called sendgrid, which provides access to all emails to the r1.rabbit.tech subdomain. At the time Rabbitude published its follow-up report, the sendgrid API key was still active. Access to this API key meant Rabbitude could access additional user information within the R1's spreadsheet functions and even send emails from rabbit.tech email addresses.
If you were already skeptical of the R1's half-baked capabilities that Mashable Tech Editor Kimberly Gedeon blamed on "rushed innovation, disillusionment, and impetuousness" in her review, this might be your sign that Rabbit is at best, not worth the money, and at worst, incapable of keeping your data private.
TopicsArtificial IntelligencePrivacy
Olympian celebrates by ordering an intimidating amount of McDonald's2025-05-01 17:30
中沙之戰在沙迦空場進行 沙特“主場”計劃落空2025-05-01 17:30
若馬塔今夏合同到期後退役 曼聯願意提供教練工作2025-05-01 17:17
皇馬一周內簽姆巴佩!簽字費8000萬歐 年薪2500萬2025-05-01 17:04
WhatsApp announces plans to share user data with Facebook2025-05-01 16:36
曼聯結束兩輪不勝重返前四 未來9輪需戰3大強敵2025-05-01 16:32
西班牙人VS萊萬特首發 :德托馬斯先發 武磊繼續替補2025-05-01 16:27
國足4名巴西歸化表態無法進行體測 或無緣12強賽剩餘兩戰2025-05-01 15:45
Two states took big steps this week to get rid of the tampon tax2025-05-01 15:44
尤文前瞻 :斑馬全麵占優 弗拉霍維奇再現克星本色2025-05-01 14:51
These glasses hide a fitness tracker on your face2025-05-01 17:11
薩拉赫結束進球荒 4個賽季英超進球20+隊史第一2025-05-01 16:25
官宣 !季莫什丘克遭烏克蘭足協除名 取消一切榮譽2025-05-01 16:12
薩拉赫結束進球荒 4個賽季英超進球20+隊史第一2025-05-01 16:09
Early Apple2025-05-01 16:09
比賽日:埃裏克森助攻布倫特福德22025-05-01 15:45
最好褒獎 !名記:皇馬欲續約本澤馬 新合同至20242025-05-01 15:45
武磊與西班牙人談過未來 留隊因教練組仍認可能力2025-05-01 15:37
Uber's $100M settlement over drivers as contractors may not be enough2025-05-01 15:30
荷甲維特斯俄籍老板宣布出售股份 其與阿布關係密切2025-05-01 14:55