"All [Rabbit] R1 responses ever given can be downloaded," according to an R1 research group called Rabbitude.
Rabbit and its R1 AI device has already been dunked on for being nothing more than an Android app wrapped up in a hardware gadget, but something much more alarming is afoot.
SEE ALSO: I tested Rabbit R1 vs. Meta AI: The winning AI assistant will surprise youThe report (via The Verge) said Rabbitude gained access to the codebase and discovered API keys were hardwired into its code. That means anyone with these keys could "read every response every r1 has ever given, including ones containing personal information, brick all r1s, alter the responses of all r1s [and] replace every r1’s voice." The investigation discovered that these API keys are what provided access to ElevenLabs and Azure for text-to-speech generation, Yelp for reviews, and Google Maps for location data.
What's worse, Rabbitude said it identified the security flaw on May 16 and that Rabbit was aware of the issue. But "the API keys continue to be valid as of writing," on June 25. Continued access to the API keys means bad actors could potentially access sensitive data, crash the entire rabbitOS system, and add custom text.
The following day (June 26) Rabbit issued a statement on its Discord server saying that the four API keys Rabbitude identified have been revoked. "As of right now, we are not aware of any customer data being leaked or any compromise to our systems," said the company.
But the plot thickens. Rabbitude also found a fifth API key that was hardwired in the code, but not publicly disclosed in its investigation. This one is called sendgrid, which provides access to all emails to the r1.rabbit.tech subdomain. At the time Rabbitude published its follow-up report, the sendgrid API key was still active. Access to this API key meant Rabbitude could access additional user information within the R1's spreadsheet functions and even send emails from rabbit.tech email addresses.
If you were already skeptical of the R1's half-baked capabilities that Mashable Tech Editor Kimberly Gedeon blamed on "rushed innovation, disillusionment, and impetuousness" in her review, this might be your sign that Rabbit is at best, not worth the money, and at worst, incapable of keeping your data private.
文章
3182
浏览
62887
获赞
78922
Woman finally gets 'the smoking hot body' she's always wanted, in her obituary
This obituary is truly something else. A woman in Ontario, Canada, wrote her own obituary, because .A working prototype of Apple's AirPower mat is out in the wild
Oh, what could have been.Back in the spring of 2019, Apple did something it almost never does and caHow to watch Apple's WWDC 2021
Another month, another Apple event. This time, it's Apple's Worldwide Developers Conference 2021, an20 Snapchat tips and tricks you might not know about
Snapchat can really do it all these days – take a quick pic, send a text chat, Shazam a song,This alignment test will tell you if you're a stupid horny baby
People online love a good alignment test. They also love to say "I'm baby." Here's something that coTwitter suspends Wordle
Twitter has suspended @wordlinator, a bot that spoiled the game with clues for the next day's puzzleGet the benefits of a personal trainer at
You: I always get the most out of my workouts and feel the best about my health when I work out withThe catchiest earworms of 2021 that you just can't get out of your head
There's probably a scientific explanation for why we've have been so susceptible to a good old-fashiThere's finally an easy way to see 'Retweets with Comments' on Twitter
Jack Dorsey might be spending his quarantine going rogue on Periscope, but Twitter's product team isThe 10 best and funniest tweets of the week, including maple syrup and Brockhampton
We've finally made it to the long weekend, and not a moment too soon, am I right? Well, it's long weCongressman tweets photo of his laptop and it sure looks like he shared a password, too
No one has ever accused politicians of being the most technically savvy, but this one takes the cakeBlurry photos taken with iPhone's Night Mode are the latest Instagram trend
Earlier this year, Kourtney Kardashian shared a photo of her and her fiancé Travis Barker toElon Musk's latest misinformation tweets are about protecting Tesla
Like our president, Tesla and SpaceX CEO Elon Musk just CAN'T. STOP. TWEETING. Musk's latest commentGoogle Maps dark mode and live location updates coming to iPhone
Soon iPhone users will be able to use Google Maps in dark mode anytime, day or night.Currently, iPhoPrequel app turns your photos into hot cartoons
If you're in need of a massive ego boost, this is your sign to turn yourself into a cartoon. Twitter