Rabbit data breach: all r1 responses ever given can be downloaded (rabbitu.de)
from mke@lemmy.world to technology@lemmy.world on 25 Jun 21:34
https://lemmy.world/post/16929521

#technology

threaded - newest

db2@lemmy.world on 25 Jun 21:43 next collapse

I’m shocked. Shocked I say!

kia@lemmy.ca on 25 Jun 21:43 next collapse

Sounds about right.

sunzu@kbin.run on 25 Jun 22:02 next collapse

aint that shit a scam?

bu they still harvest the data?

So is this now 2x scam?

Downcount@lemmy.world on 25 Jun 22:04 next collapse

the most interesting key is for elevenlabs, which gives full privileges. this allows us to:

(…) delete voices (and crash the rabbitOS backend, thus rendering all r1 devices useless)

we have internal confirmation that the rabbit team is aware of this leaking of api keys and have chosen to ignore it. the api keys continue to be valid as of writing.

So there is a chance?

bisby@lemmy.world on 25 Jun 22:05 next collapse

That didn’t take long.

simple@lemm.ee on 25 Jun 22:07 next collapse

we have internal confirmation that the rabbit team is aware of this leaking of api keys and have chosen to ignore it.

Lmao, I guess nobody’s surprised. A scam is a scam.

we will not be publishing any more details out of respect for the users

Kind of lame, I was hoping they’d brick every r1 device just out of spite. Let it be a cautionary tale for whoever was dumb enough to buy one.

just_another_person@lemmy.world on 26 Jun 01:41 collapse

If they literally only have a handful of users, so probably don’t see a need to do anything about it 🤣

dannoffs@lemmy.sdf.org on 25 Jun 22:12 next collapse

Both Rabbit R1 users should be concerned.

[deleted] on 26 Jun 00:24 collapse

.

MyTurtleSwimsUpsideDown@fedia.io on 25 Jun 22:18 next collapse

Rabbit? Like… the personal massager?

empireOfLove2@lemmy.dbzer0.com on 25 Jun 22:24 next collapse

No, the personal wallet lightener (it’s just a shitty android phone with no LLM running a poorly written app)

VeganCheesecake@lemmy.blahaj.zone on 26 Jun 02:08 collapse

Using Android as a base was honestly the most reasonable thing they did. No reason to reinvent the wheel. What they made with it is admittedly really shit, though.

empireOfLove2@lemmy.dbzer0.com on 27 Jun 23:39 collapse

Oh for sure, an Android OS base is fine, but it just reinforces the fact that the actual device is manufactured shovelware E-waste that could have just been an expensive app, as the hardware itself doesn’t do anything special…

VeganCheesecake@lemmy.blahaj.zone on 28 Jun 00:02 collapse

I wouldn’t even say that. Even if they had a truly unique LLM that ran partially locally with a custom co-processor, Android might still have been a good choice. It’s just hard to beat an open source base that’s already compatible with most mobile hardware, and relatively easy to find Devs for.

Imgonnatrythis@sh.itjust.works on 26 Jun 01:23 collapse

No please don’t confuse these. One is a technological marvel that changed the world for the better and the other is just an orange box that doesn’t do anything at all except maybe steal your personal data.

nekusoul@lemmy.nekusoul.de on 25 Jun 22:20 next collapse

these keys allow anyone to […] brick all r1s

the rabbit team is aware of this leaking of api keys and have chosen to ignore it.

Assuming that’s true, then just bricking them all sounds like it might even be the ethically correct move.

brotkel@programming.dev on 25 Jun 23:27 next collapse

It’s like the ending of Silicon Valley. Maybe they’re trying to shit their pants so badly that nobody will ever try to make another device like this.

Imgonnatrythis@sh.itjust.works on 26 Jun 01:21 next collapse

It will be hard to tell. What’s the difference between a bricked r1 and a non bricked r1? Answer: not much at all.

RootBeerGuy@discuss.tchncs.de on 26 Jun 04:16 collapse

I don’t know if it is worth the effort to brick 3 devices out in the wild.

maxinstuff@lemmy.world on 25 Jun 22:23 next collapse

Lots of tech people who don’t know or care about the r1 device are going to get a jumpscare from this post 😁

postnataldrip@lemmy.world on 25 Jun 22:27 next collapse

Yup, had to read it twice! Just about had a heart attack

can@sh.itjust.works on 25 Jun 22:48 collapse

Why?

Edit: nvm saw someone say it’s also the name of a messenger.

maxinstuff@lemmy.world on 26 Jun 04:52 collapse

RabbitMQ is used internally by a lot of applications and is often referred to colloquially as just “Rabbit”.

pipe01@programming.dev on 26 Jun 01:01 next collapse

Wow so edgy, they don’t use uppercase letters

4am@lemm.ee on 26 Jun 03:38 collapse

See, it must have made their passwords easier to guess…

Imgonnatrythis@sh.itjust.works on 26 Jun 01:24 next collapse

Where do I download these?

Alphane_Moon@lemmy.world on 26 Jun 06:51 next collapse

Some context on what the fuck is rabbit and r1 would have been helpful.

DJDarren@thelemmy.club on 26 Jun 07:23 next collapse

I mean, today’s 10,000 and all that, but you’re on a technology forum and haven’t heard of the Rabbit R1?

Alphane_Moon@lemmy.world on 26 Jun 07:27 next collapse

It all depends on what areas of technology interest you. Some context (e.g. in the body of the lemmy post) for more niche areas is always helpful.

ocassionallyaduck@lemmy.world on 26 Jun 07:39 next collapse

No them, but even knowing what it is this is hardly a device with iPhone level popularity.

What you don’t know the RG35XX? You’re not down with the Orange Pi? You don’t fuck with marushier stick boxes?

It’s not internet vapoerware obscure, but this shit would be a distantly forgotten afterthought in another 12 months.

DJDarren@thelemmy.club on 26 Jun 08:03 next collapse

Oh aye, I wasn’t suggesting that they have to know ALL of the tech to be able to post on a tech forum, I’m just surprised that they’re completely unaware of it, given it’s ubiquity on the tech forum over the past month or so.

racemaniac@lemmy.dbzer0.com on 26 Jun 13:58 collapse

He just means it’s been all over the tech internet lately, and he has a point.

of course not everyone knows everything, but this and the humane AI pin have been featured everywhere as they’re the first companies bringing llm focused AI products to market, and are generating a lot of hype, get a lot of critical articles, and a lot of youtube videos & investigations regarding them.

Not hearing about the Rabbit R1 when you followed tech news the past month was harder than playing whamagheddon during christmas time. So i get his surprise, and i don’t think his reply was mean spirited, it was hard to avoid hearing about it.

T156@lemmy.world on 27 Jun 06:31 collapse

It can depend on your particular part of the tech-sphere. I barely saw anything about either of those, because I wasn’t all that interested in AI things, and didn’t really follow the kind of people who would talk about it. At most, it was a quick flash in the pan before it was overshadowed by other news.

racemaniac@lemmy.dbzer0.com on 27 Jun 06:51 collapse

It was indeed a very short flash not long ago :).

And i’m not at al interested in those products either, but they were hard to miss when that flash happened >_<.

Treczoks@lemmy.world on 26 Jun 07:44 collapse

You are aware that “technology” is not limited to shitty apps with a small user base?

DJDarren@thelemmy.club on 26 Jun 08:01 collapse

Yes, obviously, but that thing has been everywhere over the past month or so. I’m just surprised that they were completely unaware.

Treczoks@lemmy.world on 26 Jun 08:05 collapse

Not anywhere I read around, and I’m quite into tech.

uranibaba@lemmy.world on 26 Jun 08:09 next collapse

Since no one is explaining and I have only ever heard of Rabbit on Lemmy (again with no context, probably a US thing), here is a Kagi quick answer:

what is rabbit and r1?

Based on the available information, the Rabbit R1 is a new AI-powered device developed by a tech startup called Rabbit Inc. and designed by Teenage Engineering. The key details about the Rabbit R1 are:

  • It is a standalone handheld gadget about half the size of an iPhone, with a 2.88-inch touchscreen and a rotating camera for taking photos and videos. 【1】【2】
  • The Rabbit R1 is powered by an AI assistant and is intended to help users interact with various apps and services on their smartphone, essentially acting as a remote control. 【3】【4】
  • It connects to the internet via 4G LTE and Wi-Fi, allowing it to provide real-time information and assistance. 【5】
  • The Rabbit R1 currently supports integration with apps like Uber, Spotify, Midjourney, and DoorDash, allowing users to control these services through the device. 【6】
  • Reviews of the Rabbit R1 have been mixed, with some criticizing its unreliable performance, inaccurate answers, and short battery life. 【7】【2】

In summary, the Rabbit R1 is an AI-powered handheld device that aims to provide a more convenient way for users to interact with various apps and services on their smartphones. However, it seems the device still has some issues that need to be addressed.

  1. The Rabbit R1 is an AI-powered gadget that can use your apps for you
  2. Rabbit R1 review: an unfinished, unhelpful AI gadget - The Verge
  3. What are the main functions of the Rabbit R1? Its everyday use?
  4. What exactly is the Rabbit R1 AI device that confused many people?
  5. Rabbit R1 hands-on review: Something is iffy about this | Mashable
  6. Rabbit R1 Explained: What This Tiny AI Gadget Actually Does - CNET
  7. Rabbit R1 review: Avoid this AI gadget - Tom’s Guide
demonsword@lemmy.world on 26 Jun 13:43 next collapse

what the fuck is rabbit and r

It’s basically just a scam

Alphane_Moon@lemmy.world on 26 Jun 21:13 collapse

Hahaha, that’s a pretty wild read.

The fucking Gamaverse,

capital@lemmy.world on 26 Jun 14:37 next collapse

Search engines haven’t gotten that bad, have they?

DogWater@lemmy.world on 26 Jun 16:41 collapse

No fuck you. Just because search engines exist doesn’t mean we should normalize headlines and post titles with so little information that you have to Google shit for 3 minutes to figure out what they are talking about.

capital@lemmy.world on 26 Jun 17:05 collapse

lol knock it off with the helplessness.

Open another tab and do one single search. 3 mins? Lol.

DogWater@lemmy.world on 27 Jun 03:47 collapse

It’s not about the capability to find the info. it’s about the normalization of shitty writing that people like you enable. Fuck off with that hurrr durrr you’re so helpless…stfu. People who do this shit are annoying as fuck. It’s bad journalism.

capital@lemmy.world on 27 Jun 09:53 collapse

I wouldn’t call this journalism. It’s a jailbreak/hacking project centered around the r1. This is just an article they posted.

I know all of the above because I was capable enough to navigate to their home page and … read it.

Grow up.

Voroxpete@sh.itjust.works on 26 Jun 15:24 collapse
flappy@lemm.ee on 26 Jun 06:59 next collapse

This kills the rabbit.

zipzoopaboop@lemmynsfw.com on 26 Jun 15:47 collapse

Was it ever truly alive

douglasg14b@lemmy.world on 26 Jun 07:16 next collapse

Typical security negligence of startups.

Your data is essentially never secure if it’s sitting with a startup. It’s an atrocious world for security out there.

Voroxpete@sh.itjust.works on 26 Jun 15:31 collapse

Calling this a startup is being excessively generous. Startups are meant to eventually be viable.

This is a scam. The product just feeds your queries into ChatGPT and spits out the response. The backend tech they’ve described flat out does not exist. It’s all smoke and mirrors.

brsrklf@jlai.lu on 26 Jun 15:00 next collapse

Still think those people should have gotten a playdate instead, it’s more fun and certainly not less useful (which is, not at all).

(When I first heard about the r1 I immediately thought it was weird how the 2 devices looked alike, I’ve since learned they shared the same designers).

Semi_Hemi_Demigod@lemmy.world on 26 Jun 17:18 next collapse

That could be hundred of kilobytes of data!

Moonrise2473@feddit.it on 27 Jun 05:18 collapse

Why the fuck are they using a cloud tts on an Android device??? Can’t they use on device tts?? Seems extremely stupid for no reason

  1. It’s expensive. They are paying a fee to the third party tts provider each single time someone needs a response. They boast “no subscriptions” - that means those fees are paid only by new customer purchases. Ponzi 2.0

  2. It’s fucking expensive. Elevenlabs tts voices costs thousands of dollars per month plus $0.18 per 1000 characters. Ask the history of a monument and the verbose result that the LLM regurgitated costs them $0.15. Are they banking on the fact that most customers would just shelf the device after a day?

  3. It’s slower. Each time the device needs to reply, it needs to stream an audio file instead of a few bytes of compressed text

  4. For the more realistic voices it’s only cheaper in the short term. I get it - they don’t like the robotic free voices and licensing a good closed source one costs money. But then you don’t need to pay the “cloud” forever. Did they plan to shut down shortly after the launch? Where the money for running each user in a VM is coming out? (I saw from a YouTube video that it looked like they were using a browser automation tool in a VM)

At this point since everything is run on the cloud (=somebody else’s computer) this could not only be a smartphone app, but a smartwatch app.

I wonder if they will just fold and do a rug pull now blaming the hackers or fix the problem.

Fixing the problem seems difficult for them - need to fully rewrite the app and having everything proxied through their authenticated server, increasing their expenses (and a rushed fix isn’t secure/tested). But their money comes only from new investors and new customers, and at this point I doubt that they can sell more units or scam more investors.