Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It sounds like some of these companies call the OpenAI or Anthropic APIs directly from their frontend. Later, the author also mentions "response time patterns for every major AI API," so maybe there's some information about the backend leaking that way even if the API calls are bridged.

But I'd like to know an actual answer to this, too, especially since large parts of this post read as if they were written by an LLM.



> It sounds like some of these companies call the OpenAI or Anthropic APIs directly from their frontend.

Which would be a major security hole. And sure, lots of startups have major security holes, but not enough that he could come up with these BS statistics.

I'm a little dismayed at how high up this has been voted given the data is guaranteed to be made up.


> > It sounds like some of these companies call the OpenAI or Anthropic APIs directly from their frontend.

> Which would be a major security hole.

An officially supported security hole

https://platform.openai.com/docs/api-reference/realtime-sess...


Realtime API is a very small use case that most products don't touch.


"I found 12 companies that left API keys in their frontend code. I reported them all. None responded."

They claim to have found that.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: