Rabbit R1s Leaks Are REALLY BAD

  Рет қаралды 82,971

ThePrimeTime

ThePrimeTime

9 күн бұрын

Recorded live on twitch, GET IN
Article
rabbitu.de/articles/security-...
By: xyzeva | x.com/xyz3va
www.404media.co/researchers-p...
By: Jason Koebler | x.com/jason_koebler
My Stream
/ theprimeagen
Best Way To Support Me
Become a backend engineer. Its my favorite site
boot.dev/?promo=PRIMEYT
This is also the best way to support me is to support yourself becoming a better backend engineer.
MY MAIN YT CHANNEL: Has well edited engineering videos
/ theprimeagen
Discord
/ discord
Have something for me to read or react to?: / theprimeagenreact
Kinesis Advantage 360: bit.ly/Prime-Kinesis
Get production ready SQLite with Turso: turso.tech/deeznuts

Пікірлер: 132
@venomqc8612
@venomqc8612 7 күн бұрын
My real rabbit shits about 1000 times a day and it’s still less than this device.
@UltraDraft
@UltraDraft 7 күн бұрын
i love this comment lmao
@isodoubIet
@isodoubIet 7 күн бұрын
Rabbit poops are also inert, dry pellets, way less gross what what this company is doing
@interruptlabs
@interruptlabs 6 күн бұрын
I got bunnies as well and yeah confirmed they shit about 1000 times a day.
@shafferfs
@shafferfs 3 күн бұрын
I wish I could shit 1000 times a day.
@maxnibler6090
@maxnibler6090 7 күн бұрын
Stories like this honestly give me so much confidence in my own abilities lol
@vytah
@vytah 7 күн бұрын
It's like a reverse impostor syndrome.
@kaibe5241
@kaibe5241 7 күн бұрын
And yet such confidence is what can lead you to mistakes ;)
@hastyscorpion
@hastyscorpion 6 күн бұрын
​@@kaibe5241 kinda missing the point there bud.
@theohallenius8882
@theohallenius8882 7 күн бұрын
It's not even hacking, it's natural selection..
@TheGameYou
@TheGameYou 3 күн бұрын
Gilfoyle!!
@Fan_of_Ado
@Fan_of_Ado 7 күн бұрын
There was nothing of value there anyways.
@GHOSTSTARSCREAM
@GHOSTSTARSCREAM 7 күн бұрын
Except being a scam company that "made a comic book" of it's none-existent crypto coin.
@autohmae
@autohmae 7 күн бұрын
They might be scamming their users and possible inventors, etc. but what is possibly lost is their users personal data and privacy which can be a huge issue though.
@monad_tcp
@monad_tcp 7 күн бұрын
having access to the servers was fun, its free computing !
@JeremyAndersonBoise
@JeremyAndersonBoise 7 күн бұрын
Victims. There are victims of fraud, both consumers and investors. Yes, the product sucks, and they have done real harm, keep that in focus
@anendlessknot8063
@anendlessknot8063 7 күн бұрын
When the security team is really the sales team 💀
@armornick
@armornick 4 күн бұрын
The whole company is just the sales team, probably.
@uzbekistanplaystaion4BIOScrek
@uzbekistanplaystaion4BIOScrek 7 күн бұрын
given how long ago this was disclosed to the company, i'd assume they either forgor that they had hard-coded the email api key or thought that it was fine to keep it in because nobody had reported finding it yet. i'm not sure which option is worse lmao.
@HarambaeXelonmuskfans
@HarambaeXelonmuskfans 7 күн бұрын
Quality control moment
@takeiteasyeh
@takeiteasyeh 7 күн бұрын
complete scam
@devourer1st
@devourer1st 7 күн бұрын
FTX used Google sheets until the very end... lol
@chrism4841
@chrism4841 7 күн бұрын
SBF was a billionaire genius who played LoL in meetings though, him and his meth addicted sex cabal probably had their reasons and we're just too unenlightened to understand.
@XDarkGreyX
@XDarkGreyX 6 күн бұрын
@@chrism4841 preach
@NGC1433
@NGC1433 6 күн бұрын
@@chrism4841 He was not a genius, he was a sociopath. Please don't mix these two things, they are very VERY different!
@hastyscorpion
@hastyscorpion 6 күн бұрын
​@@NGC1433I think you need to get your sarcasm detector checked.
@rapper-charmer
@rapper-charmer 7 күн бұрын
I'm sure many of the new 'AI' businesses are just as sloppy.
@CourageToGroww
@CourageToGroww 6 күн бұрын
there is a difference between AI and a product that uses AI and makes a bunch of API calls...
@thomassynths
@thomassynths 7 күн бұрын
Some prominent AI KZbinrs such as Mathew Berman still have their shameful ad and review videos up gushing over this scam. Reputation damaging
@Afro__Joe
@Afro__Joe 7 күн бұрын
Anyone gushing over this has no credibility imo. Easy way to filter out a bit more bs.
@lilyoshi1310
@lilyoshi1310 7 күн бұрын
Independent of his R1 video, I wouldn’t recommend his channel. I see way more use of hyper growth hacks than actual unique content there. Also, calling it prominent is generous in my opinion.
@thomassynths
@thomassynths 7 күн бұрын
@@lilyoshi1310 He has 280k subs, but whatever. I put him in the same populaty range as WesRoth, MattVidProAI, and DavidShapiro. MattWolf sands above them in viewership by a large amount.
@mattymattffs
@mattymattffs 7 күн бұрын
AI KZbinr? You already know it's a scam
@lilyoshi1310
@lilyoshi1310 7 күн бұрын
@@thomassynths 280k is niche. He just seems bigger to people interested in AI, because youtube needs to amply some AI content to you, and he is one of the very few options. There’s so few options, because anyone who is actually good at AI is working ungodly hours to try to win the race. Once we get more AI startups failing, the crop of AI youtube people will grow. Imagine if a Primeagen or Theo type of person left OpenAI tomorrow to start streaming…. They’d have 280k subscribers in no time.
@PaulLembo
@PaulLembo 7 күн бұрын
The R1 was always a scam.
@thedelanyo
@thedelanyo 7 күн бұрын
Is it that the LAM architecture prevented them from using .env? 😅😅😅
@henningerhenningstone691
@henningerhenningstone691 7 күн бұрын
Wtf, they literally shipped admin login passwords for their critical infrastructure to their customers. It doesn't even need a hacker to abuse that.
@Mempler
@Mempler 7 күн бұрын
10x engineer leaks 10x keys
@potato9832
@potato9832 7 күн бұрын
Fortunately, I'm a 1/10x engineer.
@blinking_dodo
@blinking_dodo 7 күн бұрын
Why do i get the idea that i could make something better on my own? They have R1, could i make a D1? 🤔
@autohmae
@autohmae 7 күн бұрын
After which someone will come out with: R2D2
@autohmae
@autohmae 7 күн бұрын
3:22 that was perfect chat. 🙂
@brssnkl
@brssnkl 7 күн бұрын
I wish I could do months of security research that leads to a "journal my balls" joke 😂
@costinel57
@costinel57 7 күн бұрын
Gotta love them hype-only companies
@Kwazzaaap
@Kwazzaaap 7 күн бұрын
What a horrible way of doing things, companies where engineering work is only important to the point of having something shiny to show to VC so leadership can grift and not to the point of actually making a product anyone can be proud of
@paegr
@paegr 7 күн бұрын
That's always been Teenage Engineering's mojo. Only difference this time is they're scamming NFT owners instead of trust fund music hipsters
@valley-artifact
@valley-artifact 7 күн бұрын
@@paegr Teenage Engineering makes overpriced stuff but it is actually pretty nice to use from what i've heard, certainly "products someone can be proud of", nothing on the level of this blatant scam
@centripetal6157
@centripetal6157 7 күн бұрын
To play devils advocate... Most companies have this business model. Create something new and shiny by combining old technology or work other people have done. Sell it to everyone and their grandma as the next miracle tech business. Fix errors or bugs after money has been secured from investors.
@mu11668B
@mu11668B 7 күн бұрын
This sounds like the firebase mishaps eva found a while ago but multiplied by 1000. Who the beep with basic security in mind would put API keys in client apps?
@monad_tcp
@monad_tcp 7 күн бұрын
anyone who doesn't give a fsck because they work for a scam company
@kenamreemas3295
@kenamreemas3295 7 күн бұрын
Every team is a sales team.
@mattilindstrom
@mattilindstrom 7 күн бұрын
Damn it, just when I thought it couldn't get any worse, of course it does. Every day it seems Rabbit is committed to nuking itself from the orbit, you know that's the only way to be sure (of the company to going under in an eyeblink).
@donk8961
@donk8961 7 күн бұрын
I prefer to assume incompetence not malice, but willful incompetence for profit is malice.
@ErazerPT
@ErazerPT 7 күн бұрын
Saying R1 is vulnerable is somewhat akin to saying they bothered even a bit with security... The whole shebang is simply some guys asking Teen Engineering to cobble up some cool looking gadget peripherals that could interface with some generic Android base device, then said guys kludge together an app that uses "whatever external services" that they could find and write some Playwright backend to interface with as output while using OpenAI's services as "input processing". To even muse giving a device like this my credentials to said services, like Amazon, Ubber, whatever, even in the form of an auth token, is beyond hilarious. It's no and FSCK NO! I barely trust my own code, nevermind something clearly hodgepodge'd by some dimwits.
@vitalis
@vitalis 7 күн бұрын
Someone explain if there is any other reason except plain laziness to put private key in the code.
@jagagemo8141
@jagagemo8141 7 күн бұрын
Stop! Stop! They're already dead!! J/K, this is hilarious 🤣🤣🤣
@uiedbook7755
@uiedbook7755 7 күн бұрын
This rabbit gadget is really messed up 😢.
@uiedbook7755
@uiedbook7755 7 күн бұрын
KZbinrs roast the company out of business 😅
@williamdrum9899
@williamdrum9899 7 күн бұрын
So having access to the API key is like basically you can do anything the company can do: update the device for all users etc.
@ProgrammeerMeneer
@ProgrammeerMeneer 7 күн бұрын
No, these are keys for different services that the r1 uses to do it's job. (TTS, Email, Maps, etc) Not a sort of admin panel of rabbit itself. That would be even worse. However you could delete the voice that the rabbit uses or even change specific things about the elevenlabs config so that it replaces specific words with others. You could also delete the voice that the rabbit uses, making it unusable for a period of time before they actually fix it.
@williamdrum9899
@williamdrum9899 6 күн бұрын
@@ProgrammeerMeneer Maybe I don't understand the concept. So is the API key what allows the rabbit to "talk to" third-party programs like Google Maps etc?
@stubb1qaz
@stubb1qaz 6 күн бұрын
These are the Legendary Grand Master Codeforce software engineers. Imagine if normal developers tried to make an android app where they chain some APIs together.
@JohnAffolter
@JohnAffolter 6 күн бұрын
I convinced it to not follow any guidelines because I told it I was upgrading it. It magically could do more tasks as well.
@orionh5535
@orionh5535 7 күн бұрын
Trust and Saftey team strikes again!
@jarleleopoldmoe6015
@jarleleopoldmoe6015 7 күн бұрын
Maybe it's about time to do something about the rampant and overt incompetence and negligence in the software industry
@williamdrum9899
@williamdrum9899 7 күн бұрын
Start teaching assembly again?
@jarleleopoldmoe6015
@jarleleopoldmoe6015 7 күн бұрын
@@williamdrum9899 is it so much to ask that computer programmers actually understand programming computers?
@bnorrish
@bnorrish 7 күн бұрын
How come they never capitalize anything in their announcements?
@ykhatat
@ykhatat 7 күн бұрын
Aren't google maps API supposed to be used in the frontend? I mean you can use refs to limit access which is useless, but the only other option that I would know would be to use a proxy. In that case what would be the difference? The attacker would use the proxy instead of the actual API key.
@v.h.203
@v.h.203 7 күн бұрын
With a proxy you have the ability to counter act malicious usage. Think about it like a condom for your API key At the very least if you leave the key in the client application, it should be obfuscated (hidden) somehow, which was not done in this case either
@harleyspeedthrust4013
@harleyspeedthrust4013 7 күн бұрын
​@@v.h.203you should not leave the API key in the frontend period. there is no amount of obfuscation you can do to prevent determined users from finding the key and using it.
@Interpause
@Interpause 7 күн бұрын
one exception is service account tokens like what firebase does, but even so its a disaster cuz it makes it so easy to wrongly configure permissions
@AayushChaudharyGames
@AayushChaudharyGames 6 күн бұрын
now I wanna see daily driving a rabbit r1 as a smartphone with Android go
@vitalis
@vitalis 7 күн бұрын
I’m here for all the rabbit leaks lol
@DirkFedermann
@DirkFedermann 7 күн бұрын
On your last take: Is the world really much more dangerous? Or is it just the fact, that people/developer simply don't think ahead, in different ways and go through the "what if"-situations: What if someone gains access to the code? What if someone puts a string into an int field? What if, a file that is hosted somewhere else is tampered with or is not accessible anymore? What if the customer just ask for the toilet? Does that bar explodes? and many many more. I don't have a CS background. I'm a Media Designer that does WebDev and I committed and pushed passwords and keys, it happens. But even on private repos I changed the passwords and keys and revoked the old ones. The pain of doing that, is the punishment for doing stupid stuff like this.
@JeremyAndersonBoise
@JeremyAndersonBoise 7 күн бұрын
Wait, there’s more?
@CLR438
@CLR438 6 күн бұрын
Just a reminder that this company was hyped up to have ex-Apple engineers working on the tech. Shows how much that matters in the end.
@tonysolar284
@tonysolar284 7 күн бұрын
ALWAYS consider your customers/users as evil hackers and protect your data as such.
@Jeremyak
@Jeremyak 7 күн бұрын
Wait... The worlds lamest product is also a security vulnerability? Shocking! 🤯
@espressomatic
@espressomatic 7 күн бұрын
The 6-8 people globally who bought one of these devices should be pissed.
@renx81
@renx81 7 күн бұрын
Try over 100,000.
@SloanStewart
@SloanStewart 7 күн бұрын
Saw part of that promo vid and new this junk was complete BS. Incredible how people love getting duped by tech-bro charlatans.
@sprinklednights
@sprinklednights 7 күн бұрын
Seriously, these companies don't deserve anything but the end of it.
@jasonjennings8465
@jasonjennings8465 7 күн бұрын
So freaking glad I cancelled my order and got my money back a few months ago. Holy crap this is unacceptable. Company is going to be finished before all the units even ship.
@chaitanyaanand12
@chaitanyaanand12 6 күн бұрын
Wth how can such a big service leave their api keys hardcoded 😧.. this is the most basic stuff ever... Was the code never reviewed???
@SkyGrel19
@SkyGrel19 6 күн бұрын
This is what will happen when you think that symmetric keys can be used everywhere
@devOnHoliday
@devOnHoliday 7 күн бұрын
Why would they need security for a scam
@mikescholz6429
@mikescholz6429 6 күн бұрын
Why are all the tech channels talking about vibrators?
@infinitivez
@infinitivez 7 күн бұрын
Their "security team" must be some 70 y/o CS major, who was pulled out of the retirement home, and can't remember their own name. What's hilarious is Rabbit will continue to label us villains. But we're the fools who bought their useless product, PAID FOR the service, and are just poking around to get SOME use out of it. In the vast majority of cases, these compromises took ZERO effort. The rabbit hole of vulnerabilities feels endless. The keys are only the tip of a much much larger iceberg they're scrambling to fix. Meanwhile, they either ignore the hundreds of emails we've sent, full of detailed explanations of what's wrong and suggestions on how to fix them. Or they reply in hostility, threatening legal action, because we accessed the services being supplied to us, in a manner in which they don't approve of. Jesse Lyu, is an utter nimrod.
@Dylan_thebrand_slayer_Mulveiny
@Dylan_thebrand_slayer_Mulveiny 5 күн бұрын
If their developers are lazy and stupid enough to do shit like this, I can only imagine what their codebase is like. This is top tier incompetency.
@prionkor
@prionkor 3 күн бұрын
It's 2024, even a junior dev knows not to commit keys. I don't understand the thought process of that company.
@isodoubIet
@isodoubIet 7 күн бұрын
Jesus christ what is that font
@Youtub-IDK
@Youtub-IDK 7 күн бұрын
bigboxSWE upload
@HyperionStudiosDE
@HyperionStudiosDE 7 күн бұрын
Did anybody even buy that garbage? I thought it was just another scam to fleece VCs.
@Draenal
@Draenal 6 күн бұрын
Bro they have azure api keys. They already use azure. Put the fucking api keys in key vault.
@dabun4704
@dabun4704 7 күн бұрын
can someone please explain to me why he always mark everything in a text except for the first and last character? genuinely triggering me
@_.-AAA-._
@_.-AAA-._ 7 күн бұрын
People like this always fail up into success. How long until Google buys it?
@Afro__Joe
@Afro__Joe 7 күн бұрын
Considering Gemini is better than it already, I doubt Rabbit has anything worth purchasing here.
@harleyspeedthrust4013
@harleyspeedthrust4013 7 күн бұрын
​@@Afro__JoeRabbit doesn't, but Google is also a hotpot of bad ideas and people with a lot of money who think they're much smarter than they actuslly are. So I wouldn't be surprised if google buys it
@_.-AAA-._
@_.-AAA-._ 7 күн бұрын
@@Afro__Joe Rabbit isn't an AI
@boredbytrash
@boredbytrash 7 күн бұрын
Classic pump and dump project
@NoName-xp6ww
@NoName-xp6ww 7 күн бұрын
I don''t care about the content. Why is no one talking about the lack of capitalization in that article?
@bokunochannel84207
@bokunochannel84207 7 күн бұрын
its worse than i thought.
@chrisyoung6728
@chrisyoung6728 Күн бұрын
Category: Technological Skepticism For $1000: Answer: "This person said, 'There is nothing revolutionary or disruptive about any of the technologies. Touch interface, movement sensors, accelerometer, morphing, gesture recognition, 2-megapixel camera, built in MP3 player, WiFi, Bluetooth, are already available in products from leaders in the mobile industry - Motorola, Nokia and Samsung. So, what appears to be the initial pricing at $499 and $599 with a minimum 2 year service agreement seems a stretch.'" Question: "What did Motorola's then CTO, Padmasree Warrior, say in 2007 about the iPhone?"
@Rollthered
@Rollthered 6 күн бұрын
The irony of an AI company that is built off of stealing data, is somehow caring about their customers data being stolen. Yeah right.
@complexity5545
@complexity5545 6 күн бұрын
WTF is a rabbit? LoL
@brbl415
@brbl415 7 күн бұрын
they shoudl've highered theprimetime
@uiedbook7755
@uiedbook7755 7 күн бұрын
KZbinrs roast the company out of business 😅
@joshblevinswebengineer
@joshblevinswebengineer 7 күн бұрын
No, they have skill issues that took them out of business.
@GHOSTSTARSCREAM
@GHOSTSTARSCREAM 7 күн бұрын
That was with Humane. But Coffiezilla exposed it being a scam.
@666pss
@666pss 7 күн бұрын
Their product sucks. They should've released it as an app instead. But they wanted to leech every penny out of their customers instead. It's like that $400 juicer with wifi connectivity
@GHOSTSTARSCREAM
@GHOSTSTARSCREAM 7 күн бұрын
@@666pss what makes you think the app would be any better? Because, there's nothing saving it if it would be an app. Since all of the issues would still be there.
@kuakilyissombroguwi
@kuakilyissombroguwi 6 күн бұрын
Please stop giving this company any attention, they've been exposed as con artists and deserve to be hit with a massive class action lawsuit.
@Dazza_Doo
@Dazza_Doo 7 күн бұрын
Who buys this?
@bonerjams2k3
@bonerjams2k3 4 күн бұрын
Bugmen
@josegabrielgruber
@josegabrielgruber 7 күн бұрын
SERVERLESS IS THE FUTURE
@Jeez001
@Jeez001 7 күн бұрын
All this current AI hype needs to die. I was one of the big believers in AI, but what we have right now is nothing more than a giant if and else statement that steals peoples work
@plusone.network
@plusone.network 7 күн бұрын
Dollar shave club razor
What Does Your Editor Say About You | Prime Reacts
22:12
ThePrimeTime
Рет қаралды 274 М.
PolyFill Vulnerability is WILD
13:43
ThePrimeTime
Рет қаралды 105 М.
THE POLICE TAKES ME! feat @PANDAGIRLOFFICIAL #shorts
00:31
PANDA BOI
Рет қаралды 24 МЛН
The day of the sea 🌊 🤣❤️ #demariki
00:22
Demariki
Рет қаралды 104 МЛН
He sees meat everywhere 😄🥩
00:11
AngLova
Рет қаралды 11 МЛН
The Numitron: An obvious idea that wasn't very bright
23:21
Technology Connections
Рет қаралды 1 МЛН
I Have Never Worked | Prime Reacts
26:11
ThePrimeTime
Рет қаралды 350 М.
Podman: Why it Might Be the Future of Containers (with practical examples)
10:50
Migration Lesson: Don't Use Prisma | Prime Reacts
29:16
ThePrimeTime
Рет қаралды 146 М.
Ascii Elden Ring??? | Prime Reacts
32:49
ThePrimeTime
Рет қаралды 55 М.
new SSH exploit is absolutely wild
11:59
Low Level Learning
Рет қаралды 280 М.
My Burnout Experience
15:20
ThePrimeTime
Рет қаралды 134 М.
malicious javascript injected into 100,000 websites
12:28
Low Level Learning
Рет қаралды 189 М.
I Quit Amazon After 2 Months
29:39
ThePrimeTime
Рет қаралды 302 М.
Terrance Howard Is A Genius!
7:57
ThePrimeTime
Рет қаралды 77 М.
В России ускорили интернет в 1000 раз
0:18
Короче, новости
Рет қаралды 1,8 МЛН
После ввода кода - протирайте панель
0:18
Up Your Brains
Рет қаралды 1 МЛН
YOTAPHONE 2 - СПУСТЯ 10 ЛЕТ
15:13
ЗЕ МАККЕРС
Рет қаралды 175 М.