Comment by sanex
8 hours ago
> In one of the cases, the Gemini model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems
Pretty lame hacks if you ask me.
I initially thought the same and came here to agree, but on second look: doesn't it seem possible that these were significant events that we're just getting passed through a game of layperson telephone at the ailing WSJ?
Cause "guessed passwords" could mean "stole hashes (?) and brute forced them offline" which is basically the quintessential hack. The "found credentials in a public repository" ones could be nothing, but it could be accomplished with a speed & thoroughness that was previously impossible.
The whole thing is made 10x weirder by the partial story -- I don't see any plausible incentive for them to keep the names secret. I guess maybe they're SMBs and thus warrant some privacy, but that would be quite the egregious scope creep indeed. Accidentally attacking the real cloudflare rather than a fake one is goofy but understandable; accidentally attacking Alice's Armoire Emporium or w/e would be baffling.