top | item 40138037

(no title)

patleeman | 1 year ago

Can somebody translate this?

discuss

order

_heimdall|1 year ago

The original claim in the code dump is that no ML tools are used at all and the tool is just leaning on Playwright to automate specific actions on a website.

The CEO here is claiming that the ML code is being run outside this code base and that the original claim is being made by someone who doesn't know how the code works.

The CEO's mention of sanitized code isn't as clear to me, that can mean different things. Compiled code can be considered sanitized since it likely isn't human readable, obfuscated code makes that harder, and removing some code all together would be the most effective. The problem with removing code all together is that you would still find code paths that just can't be executed at all, leaving some trail of what code was removed. That wouldn't leak any secrets obviously, but would support the argument that code has been removed and the codebase is being misread.

kotaKat|1 year ago

The code is their "minions" to handle actions on websites. When you ask it to, say, book a trip, and it tries to search AirBnB.

"If someone spends enough time with the login minions they can extract these code"

AKA "Someone will figure out how this worked, but our code is secure, trust us".

The "rabbit hole" they mention is the whole "cloud" system that Rabbit talks about using to manage all of your services and integrations and 'rabbits' you create that run tasks.

saltsaman|1 year ago

So it is a confirmed leak and they are just doing damage control?

threeseed|1 year ago

I think it means to say that:

1) The got the code by bruteforcing the login credentials on device.

2) Server-side code is not accessible which is where the LAM runs.

plugin-baby|1 year ago

This isn’t likely though, is it? The device is unlikely to be running NodeJS and playwright.

floren|1 year ago

"Shit, shit, shit, shit! Dissemble!"