news.volyx.in

We hacked Gemini's Python sandbox and leaked its source code (at least some) (landh.tech)

669 points by topsycatt · 492 days ago · 144 comments on HN

Article summary

Researchers discovered a vulnerability in Google's Gemini AI sandbox, allowing them to leak internal source code. They used a custom Python script to map the sandbox's filesystem and extract a binary file, which contained internal Google code and proto files. The researchers were able to reconstruct the file and analyze its contents, revealing internal code and directory structures. The vulnerability was discovered during a bug bounty event, and the researchers were awarded the Most Valuable Hacker title.

Main themes

  • AI security
  • Sandbox vulnerabilities
  • Google Gemini
  • Bug bounty
  • Internal source code leak
  • Proto files

What commenters say

  • The leaked proto files are not as confidential as they seem, and similar information is already available online.
  • The vulnerability is not as significant as it appears, and the article's framing is exaggerated.
  • Having access to the internal proto file structure could be valuable information for an attacker, particularly for internal authn/z.
  • The Gemini AI has limitations, such as being unable to set timers reliably, and some users prefer the old Assistant voice.
  • The removal of the 'run' button for generated code in Gemini Canvas was due to underutilization, but some users want it back as an educational tool.
  • There is a mix of frustration and optimism within Google regarding the company's position in the AI market, with some employees feeling that the company is losing its lead to OpenAI.
  • The decline in quality of Google's apps and services is a concern for some users, who feel that the company is prioritizing profit over user experience.
  • Working for a big company like Google may not be as desirable as it once was, due to issues like bureaucratic red tape and lack of control for engineers.