← Back to context

Comment by ls612

9 hours ago

It doesn’t even sound like it hacked anyone it sounds like there was a “s3 bucket set to public” type issue and the agent just naively downloaded the data. That should absolutely not incur liability, how is a reasonable person or agent supposed to know if a dataset you can download from a website designed to serve datasets is intended to be downloaded?

>> “s3 bucket set to public”

I don't believe that was mentioned in the article in any way. Could you share your reasoning there?

  • It wasn’t literally that, it was that the dashboard contained both data intended to be public and data not intended to be public, all accessible by anyone on the internet.