时间:2025-09-16 21:04:54 来源:网络整理编辑:熱點
"All [Rabbit] R1 responses ever given can be downloaded," according to an R1 research group called R
"All [Rabbit] R1 responses ever given can be downloaded," according to an R1 research group called Rabbitude.
Rabbit and its R1 AI device has already been dunked on for being nothing more than an Android app wrapped up in a hardware gadget, but something much more alarming is afoot.
SEE ALSO:I tested Rabbit R1 vs. Meta AI: The winning AI assistant will surprise youThe report (via The Verge) said Rabbitude gained access to the codebase and discovered API keys were hardwired into its code. That means anyone with these keys could "read every response every r1 has ever given, including ones containing personal information, brick all r1s, alter the responses of all r1s [and] replace every r1’s voice." The investigation discovered that these API keys are what provided access to ElevenLabs and Azure for text-to-speech generation, Yelp for reviews, and Google Maps for location data.
What's worse, Rabbitude said it identified the security flaw on May 16 and that Rabbit was aware of the issue. But "the API keys continue to be valid as of writing," on June 25. Continued access to the API keys means bad actors could potentially access sensitive data, crash the entire rabbitOS system, and add custom text.
The following day (June 26) Rabbit issued a statement on its Discord server saying that the four API keys Rabbitude identified have been revoked. "As of right now, we are not aware of any customer data being leaked or any compromise to our systems," said the company.
But the plot thickens. Rabbitude also found a fifth API key that was hardwired in the code, but not publicly disclosed in its investigation. This one is called sendgrid, which provides access to all emails to the r1.rabbit.tech subdomain. At the time Rabbitude published its follow-up report, the sendgrid API key was still active. Access to this API key meant Rabbitude could access additional user information within the R1's spreadsheet functions and even send emails from rabbit.tech email addresses.
If you were already skeptical of the R1's half-baked capabilities that Mashable Tech Editor Kimberly Gedeon blamed on "rushed innovation, disillusionment, and impetuousness" in her review, this might be your sign that Rabbit is at best, not worth the money, and at worst, incapable of keeping your data private.
TopicsArtificial IntelligencePrivacy
Michael Phelps says goodbye to the pool with Olympic gold2025-09-16 21:03
海港爆紅小將:在隊裏我不是最小的 要向武磊看齊2025-09-16 20:41
曝羅傑斯願意執教曼聯 但希望等到下賽季開始帶隊2025-09-16 20:38
英媒:C羅吃驚於曼聯水平下降 球員質疑索帥能力2025-09-16 20:29
'The Flying Bum' aircraft crashes during second test flight2025-09-16 20:11
恰20又挑釁米蘭!社媒發破門視頻 自稱是“國米人”2025-09-16 20:09
7日賠率:米蘭德比平局收場 西漢姆聯不懼利物浦2025-09-16 20:08
南都:今冬中國足球穩為先 泰山海港上演雙線爭霸2025-09-16 20:05
Is Samsung's Galaxy Note7 really the best phone?2025-09-16 19:58
英媒 :C羅對格林伍德感到沮喪 他想和卡瓦尼搭檔2025-09-16 18:44
U.S. government issues warning on McDonald's recalled wearable devices2025-09-16 20:42
國足向泰山征召球員遭拒理由是“有傷”李鐵無奈放棄2025-09-16 20:34
前阿曼國腳 :保持狀態可擊敗中國 在沙迦踢對我們有利2025-09-16 20:26
瓜迪奧拉看好哈維未來 :早知道他遲早會執教巴薩2025-09-16 20:17
The five guys who climbed Australia's highest mountain, in swimwear2025-09-16 20:08
庫蒂尼奧 :我職業精神不容置疑 狀態不佳因不被重用2025-09-16 19:59
鐵錘幫暴走 !聯賽杯KO曼聯曼城 終結5年不勝紅軍2025-09-16 19:10
武磊星夜抵達沙迦 與劉殿座一同缺席國足首練2025-09-16 18:58
Dog elected for third term as mayor of Minnesota town2025-09-16 18:40
名記 :曼聯沒有換帥跡象 希望索帥至少帶完本賽季2025-09-16 18:24