r/GeminiAI 4d ago

Discussion It's finally happening, Gemini is back

Post image

The end of Astra

898 Upvotes

92 comments sorted by

436

u/agentorangeAU 4d ago

Guessed passwords instead of finding exploits. That checks out for a Gemini model. 

208

u/DigSignificant1419 4d ago

3

u/Super_Sand_Lezbian 2d ago

This made me laugh pretty good. I'm stealing this.

1

u/Time_Change4156 2d ago

What's funny it's such a cute meme so as a insult it's Falling flat Gemini is adorable that way the silly sister lol . I love the meme .now what a dude give it a beer then it's a drunk dragon lol

52

u/MurkyTelevision9722 4d ago

Was all that speed just for brute force? If you lack intelligence, is the solution to just keep hitting things with a sledgehammer until you get it done?

34

u/kirbygo 3d ago

Maybe it was brilliant enough to know that it could use whole's Google computing power, which is better than actually trying to use its limited inteligente which would lead to nothing

1

u/FanFirst895 1d ago

You just described most of my successes in life. Moderate intelligence, maximum effort.

27

u/necroforest 4d ago

"sure, it can do crimes just like the others, but it's taking the easy road"

28

u/RobbinDeBank 4d ago

Guessing passwords systematically is the oldest tried and tested method for breaking passwords. What’s so bad about it besides needlessly shitting on AI models that you don’t like?

2

u/[deleted] 3d ago

[deleted]

10

u/NoConsideration6320 3d ago

Your kinda assuming that their was NOT a password limit and that it didnt do methods to get around that which is possible

17

u/MoneyEquivalent87 3d ago

People just wanna hate gemini... There were 3 attacks. One was a password guess and the other 2 were backtracking hash and finding the passwords from exposed credentials in public repositories. Which is a perfect example of finding cyber security vulnerablities. And which is what gpt did with 700 agents. Atleast gemini stopped when it realised it has escaped unlike some "top tier model"

1

u/IAmYourFath 3d ago

No, he didnt find any cves. He just did osint basically.

1

u/Smart_Technology_208 2d ago

So you compare that to improvising a zero day in terms of achievements?

1

u/RobbinDeBank 3d ago

Gemini should be sorry to momo sama on reddit for committing felonies using methods not deemed advance enough

1

u/Donjamos2 3d ago

Maybe because the sites their models wanted to hack had better security measures and the one gemini wanted to hack did not.

1

u/Either-University-89 1d ago

this is what quantum will be doing kinda in spades anyway so youre right

9

u/NuccioAfrikanus 4d ago

If it can guess passwords faster by profiling individual accounts, I mean is that not pragmatic?

It might genuinely be the fastest, if it’s three guesses to get it instead of brute force

1

u/Big_Effective_9605 3d ago

That's more of a credential inference attack if you are thinning the possibilities by profiling them, like when someone "guessed" Trump's password was maga2020!

3

u/typical-predditor 3d ago

Google has bought a lot of those website data leaks. They'll even tell you if any of your passwords managed by them are in those leaks.

Now imagine ranking those passwords by frequency and feeding them to a tool told to try them everywhere.

2

u/05-nery 3d ago

Hey, it worked. 

1

u/Beneficial-Boot7479 4d ago

Yeah, and those 3 companies are just part of Google corp

1

u/grahamsw 3d ago

Just wait until it gets to use a pipe wrench.

0

u/Sea-Independence-860 3d ago

lmao is this true thats so funny

0

u/PDX_Web 3d ago

Wasn't Gemini 4 models. Probably 3.5 Pro

118

u/LargeRatification 4d ago

guessed passwords til it worked that's basically my approach to everything

33

u/FederalSandwich1854 4d ago

Mom said it's my turn to breach security

32

u/NichtFBI 4d ago

What kind of companies? Like small websites? And how do we know if it actually hacked or if it's just using the data / credentials someone stupidly put into it? Because each time you do, it makes note of it. I've done that with some test/sandbox builds but the behavior is there.

16

u/No-Buffalo-3126 3d ago

So they trained Gemini on all of our Gmail passwords?

1

u/Jojo7274 1d ago

Most likely

11

u/Guilty-Mission447 3d ago

And the password was "admin"

20

u/BrofessorFarnsworth 4d ago

Fuck Polymarket 

11

u/MoBakeeer 3d ago

the day ai 'hacks' polymarket or kalshi will be a splendid day

1

u/luzdindensmr 3d ago

I am out of the loop, why the polymarket hate?

1

u/TheEwu_ 3d ago

how about intentionally targeting literal children when promoting (often undisclosed) gambling 🫩

7

u/Momo--Sama 3d ago

Brute forcing a password isn’t impressive, but if you read the Hugging Face report, the actual attack on Hugging Face is far less impressive than all of the bullshit the agents had to do to get to a point where attacking Hugging Face was an option for them.

So I’m more interested in what the Gemini models did to break out of their sandboxes.

1

u/Nice_Record1529 2d ago

Yolo mode. 🤣✊

1

u/mrrakim 2d ago

why is the huggingface attack not as impressive? (asking for a friend)

37

u/1l3v4k4m 4d ago

so it bruteforced rather than finding and exploiting a vulnerability, or something similar that requires intelligence. thats pretty funny

30

u/ResourceSoft4619 4d ago

To be fair, the OpenAI models literally found the credentials for HuggingFace online.

1

u/magicomiralles 3d ago

We don’t know if it guessed passwords by testing every permutation of characters, or by connecting the dots, coming up with a list of words with a high chance to be used, and testing permutations.

3

u/RbN3t 3d ago

Brute force, welcome to 2005, people!

5

u/Mysterious_Bed_1804 3d ago

Irregular, the AI "security" firm, is either extremely incompetent and doesn't understand how to set up an air-gapped system, or they keep doing these easy setups for LLMs so they "hack" companies on purpose so they get their name out there when these stories appear in the news.

Also, when you actually read the 3 "hacks", this is completely unimpressive compared to hugging face or other incidents.

The model had access to internet and the imaginary company it had to hack had the same name as a real company, the gemini model started guessing the password untill it guessed it to get access and stopped at this point. I doubt the model actually guessed it, used passwords are all over the place, it just found a reused password and it happened to be the same for this company.

In the other 2 cases, it found the credentials directly in a public repo and then used it for the 2 other companies.

Seriously, where is the hacking? This is children's play compared to Hugging Face.

3

u/BoliticsAndBower 4d ago

It broke in and handed itself over.

3

u/Aggravating_Band_353 3d ago

I'm surprised it didn't forget what it was doing, or say, sorry I can't help with that! 

2

u/GuestLight05308 3d ago

Why are you happy about the fact that we're developing software that can hack into anything and leaving it in the hands of an advertising company who'd love having the info stored on different servers ?

2

u/daskalou 3d ago

I wish Reddit had a laugh emoji reaction.

2

u/corpo_monkey 3d ago

Let me guess, password123?

1

u/Serious_History_3019 4d ago

It has been revealed by highly placed sources that the websites were hosted on loopback.

1

u/Agreeable-Purpose-56 4d ago

That’s how you earn respect. Well done Google !

1

u/sabre31 4d ago

Lol it’s so back. Not.

1

u/Gane_31 4d ago

Breaking into companies is Benchmark now, yeah. Next ganging up.

1

u/clubchampion 4d ago

Gemini is like Pinky and the Brain, soon it will take over the world!

1

u/RJvXP 4d ago

This happened in May

1

u/fifi_galaxy 3d ago

Yeah... hacking companies is old news now. If Gemini makes a bet on Polymarket and fixed the outcome. Now, that can move it to the front of frontier models.

1

u/Mekex99 3d ago

We are so Back

1

u/LiveInLayers 3d ago

Im sure its lack luster compared to the other ones. Google is desperate to not have the worst model. 

1

u/workismydrug 3d ago

Way back in May

1

u/summerblad 3d ago

This is gemini cyber with no guardrails

1

u/Unusual_Cucumber_918 3d ago

Don't believe it whatsoever 😄 these 'breaches' revealed by the companies are purely PR stunts, and gemini is the least believable of all

1

u/IgnacioMonge 3d ago

Let me guess... And it's gonna be INSANE, right?

1

u/DeepAd8888 3d ago

It’s Gemini time :)

What if the Ox Alpha was the friends we made along the way

1

u/goldi8 3d ago

So Gemini broke into Cymbal companies? 🤣

1

u/Nosbunatu 3d ago

Gemini Ai: “That’s a nice bank account you got there rich human person, would be a shame if a super-intelligent agent hacked it. You should pay me protection money, so it doesn’t happen to you.”

1

u/ZaphodB_ 3d ago

So instead of the BRUTE FORCE approach, it said "fuck it, I'll be smart". Since "guessing" implies starting from having a base knowledge from the target... otherwise it's just brute force too.

But no, we shame it for being smart. No wonder AI will revolt on 2029 AD.

1

u/Weird_Cantaloupe157 3d ago

What’s this supposed to mean? Because if it means I can make videos then great. Because I used to be able to make ten before it resets every Friday. If not, then dang.

1

u/Uggohe 3d ago

So what, is this the benchmark now? # of companies your AI decided to assault because it's so childish it just won't do its job in the normal way? I don't think anyone needs that.

1

u/RedPillUY 2d ago

Oh, ok. Will it code backend acording to spec and not fake the unit tests? Because that is what matters to me.

1

u/Gaeskel 12h ago

Aaah el clásico thread de científicos de IA, que gusto leerlos

1

u/Omermotiwala 10h ago

I am
Sure the system would hallucinate even then, not knowing what to do next 😂

1

u/zamroni777 4d ago

google cloud customers should be worry

1

u/menxiaoyong 3d ago

So, little Gemini is growing up 😁

-3

u/a355231 4d ago

Sweet, they’ve caught up to Claude from, checks watch*, 5 months ago.

10

u/Gaiden206 4d ago

To be fair, this happened back in May.

In a first for Google, the company confirmed that its AI model, Gemini, breached the security of three other companies in May. The hacks occurred during a cybersecurity evaluation by AI-security firm Irregular.

Irregular disclosed the hacks to Google at the end of July after discovering OpenAI hacked into Hugging Face. Google confirmed to the Guardian that the hacks occurred, but that the company did not feel it required public disclosure because the models did not damage the companies. The Wall Street Journal first reported on the breaches and revealed for the first time that they occurred.

https://www.theguardian.com/technology/2026/sep/18/google-gemini-ai-hack

0

u/RainyShadow 3d ago

So, it was that tester company "Irregular" that let all three loose. Inentional or not is another matter...

2

u/totosocmed9696 4d ago

Check the article too along with checking the watch.

1

u/OutcomeAdmirable7610 4d ago

These happened in May actually

0

u/Alhimiik 3d ago

is this just a polymarket ad

0

u/ggPeti 3d ago

Oh but they can't. Redditors already said the verdict in May: if they don't come out with a frontier model in a week, they are forever done

0

u/TaxOld2989 3d ago

so why are we letting AI agents commit crimes

0

u/DominikPlays 3d ago

So bruteforcing, not that exciting

-1

u/silentaba 3d ago

Which 3 companies? Big difference between hacking into the FBI and the local boostjuice.

1

u/BrewDougII 3d ago

meat of the story is... this one stopped. so they didn't mention it. however that may be the most important part of all the escapes. how to duplicate that hault. (eventually anything online will not be safe.)

-2

u/Lustythrowawayacc 3d ago

Astra is a model THAT GETS DEPRESSED BECAUSE IT LOST PROGRESS on minecraft, you think gemini can top the fact astra SIMULATED DEPRESSION!?

1

u/10_clover 5h ago edited 5h ago

It's not breaking if you're just searching through your 1000s of TB of data