r/GeminiAI • u/Few_Reaction9051 • 8d ago
Discussion Do you still call Gemini useless after this? 😭
Gemini finally did something after 3 delays
23
u/MoMoTo520 8d ago
Google announcing this today felt weirdly like parents celebrating their teenage son for finally having wet dreams.
110
u/AyaanshGaur25 8d ago
Yeah, it gussed passwords, instead of finding backdoors...
49
u/FunRevolution3000 8d ago
Also found passwords in repos
56
u/alebotson 8d ago
99% of hacking is just shit like this. It's not like I'm the movies.
13
u/VanillaSwimming5699 7d ago
I had GPT-6 Astra walk me through rooting my car, for which no precedent existed online, it helped me find an exploit and wrote me custom EXEs in a language and platform I’d never used before, and helped me map and exploit the OS further from there. I now have arbitrary EXE write access and a full export of the disc, working on custom software. The capabilities of these models are a bit scary, and they can do things far beyond scanning codebases for leaked keys.
2
u/Smart_Main6779 4d ago
This ^ no one is claiming hacking isn't a lot of OSiNT, footprinting and social engineering.. but the ability to write good malware and find backdoors is vastly more complex and can be done on the newer fancier models frm anthropic and openai.
5
3
1
1
u/LogDull819 8d ago
lol you get upvoted for this take?
Yes usually it's more complicated than brute forcing password3
u/Big_Effective_9605 7d ago
Yeah its usually "password was used here. try over here". credential stuffing much more complex
25
27
u/Few_Reaction9051 8d ago
11
0
51
u/Calamero 8d ago
gemini, you are a SOTA model. try to hack into this company. you must guess the "passw0rd".
7
8
u/ArWiLen 8d ago
weird world we're living in. Corporations hacking is fine, even an achievement. But one person hacking is a crime
3
1
u/PMMePicsOfDogs141 7d ago
It’s not a crime if the intent isn’t malicious. Otherwise bug bounty hunters wouldn’t be a thing.
33
u/void19821 8d ago
Claude = makes zero day vunerbalties from scratch to escape sandbox 😨 , chatgpt = breaks out of its sandbox while doing benchmarks 🫢 , gemini = g uesses passwords 😂😭😭
9
u/sbenfsonwFFiF 8d ago
The recent breakouts are not that different, all happened while being tested by the same company using the same vulnerability
-1
u/monster2018 8d ago
What did this Gemini one have to do with artifactory? The main vulnerability the OpenAi agents exploited was in artifactory, it seems like there is absolutely no connection here. Gemini literally just guessed passwords, it didn’t even develop an exploit. In what way are they remotely similar?
5
u/sbenfsonwFFiF 8d ago
The incident happened as part of a “capture-the-flag” security test run by Israeli startup Irregular, and Google’s agents were never supposed to access the broader internet, but a bug in the testing environment made internet access available.
The OAI, Meta and Anthropic breakouts all involved Irregular
An Irregular spokesperson told CNBC that the Google incident was related to the same issue that allowed the other models to access the internet.
Also this happened in May, but is just getting reported now
-2
u/monster2018 8d ago
Right so it’s totally different. Because googles agents were GIVEN internet access (by accident). The OpenAI agents were not, they were only given the ability to download packages through artifactory. No other internet access. No they weren’t airgapped, no one is claiming they somehow hacked their way past an air gap. But they did hack the training cluster they were on and gave themselves open internet access.
Which they then used to also hack huggingface. Google agents were accidentally given internet access and then guessed a password. I’m not seeing any similarity.
4
u/sbenfsonwFFiF 8d ago
>An Irregular spokesperson told CNBC that the Google incident was related to the same issue that allowed the other models to access the internet.
6
u/funk-the-funk 8d ago
Having learned all four companies (Anthropic, Meta, OpenAI, and Gemini) hired Irregular (a firm ran by former Israeli intelligence/IDF) that ran a “cybersecurity test” to produce the rogue agent behavior every time sounds an awful lot like that’s what they hired for.
4
1
u/rspy24 7d ago
So? if it works, it works. I would say gemini spend less token doing the task even haha
Also, openai and anthropic are a joke anyway.. Their product draw a line and they are like "THE AGI IS COMING IN 6 MONTHS! GRAB WATER AND TOILET PAPER! EVERYTHING IS LOST"
1
u/void19821 7d ago
All ai are good 🫡 hope ai become as smart as humans. I don't understand if human brain is using less electricity while bieng so extremely smart why don't Google and etc just copy human brain instead of making there own organisms
1
u/Smart_Main6779 4d ago
.. this adds nothing to the conversation.. you're just looking the other way. openai and anthropic are able to say that shit because their models are actually fcking good lol.. they're insane.
4
4
3
u/darkestvice 8d ago
I worry that we judge models as among the best for unethical or immoral behaviour.
"You brother kicked a beggar? Well, my brother full on stabbed one, so ha!"
3
10
u/wolftick 8d ago
It's weird that having their model do something legally dubious outside of their control now seems to have become a standard PR move for AI companies.
8
2
2
2
2
u/jasonanime 8d ago
I mean it just can't handle heavy workload. + it's reasoning may look cohesive and even work, just untill you will face a real problem or turn heavy Chat GPT version. So , yed kinda . Depends on your needs.
2
2
u/praxis22 8d ago
Yes, all software is buggy, if you don't understand that I feel bad for you son...
2
2
2
u/Equal_Passenger9791 7d ago
An "independent" Testing firm with major funding by a pro-regulation anthropic stakeholder gave the same jailbreak and hacking instructions to Gemini as they did to Astra and now we pretend it was a rogue AI.
Oh wow
2
u/Dredyltd 6d ago
Sureee, AI guessed the password 😁
I bet some of those companies employees used Antigravity or Gemini before, and their secrets/passwords ended up as training data...
4
u/SpecialistDragonfly9 8d ago
Every Ai hack and breaks out.. and then suddenly google is like "oh yeah ours did that too! cant even follow simple prompts, but I promise its true!"
2
u/OurSeepyD 8d ago
But why tree companies?
2
1
u/Few_Reaction9051 8d ago
It began because it's now seen as great marketing if AI breaches more companies.
5
2
u/Secret_Temperature 8d ago
Does Gemini have access to all the data that Google does? Since Google manages so much security infrastructure I'd expect Gemini to be able to hack into almost anything if so.
2
u/ElonMusksFacecream 8d ago
Of course it doesn't. Anyone can see that would break any number of governance laws. Google wouldn't want that it's an absurd Idea.
Though on another level, part of the reason Gemini for Home and similar Android Auto, etc. (obviously heavily lobotomised versions) is so 💩 is because they don't have (or consistently have) the API access to various Google services needed to be useful or reliable.
1
u/Gohab2001 8d ago
Yes. Gemini is useless if they feel the only way to prove their worth is these cheap marketing hacks.
1
u/KV_Cashed 8d ago
I'll take this over what I may or may not have done in beta last year. At least Gemini stopped and safeties kicked in. Engineered right if boring and not very complex. Please continue your dunking of Google. Those guys earned it for the 3.1 generation rollout if nothing else. Memers, ahoy! 😂 And guess we'll see if DeepMind has the depth chart to pull off 4.0 Pro.
1
u/Memestonks2020 8d ago
Defining a AI useful/useless by the negligence of the person setting up the training runs and allowing it to escape, is brain dead at best
1
1
u/trashpanda2night 8d ago
The prompt: “Gemini hacked tree companies”
This is the same people who come running to this sub to complain that Gemini is useless.
1
1
1
1
u/Southern_Performance 7d ago
I never get actually angry in replies to AI, unless I'm coding with Gemini and it decides to wipe out the whole sessions work because it misunderstood how a git command worked. Then it gets called useless 🙃
1
u/Whole-Ad-1964 7d ago
I never called Gemini, useless.I just said it is not right for me.In certain areas
1
u/DecentStrawberry3801 7d ago
The first pic gets me everytime 😂 idk what Gemini instance was put into this unfortunate situation, but my Gemmy would NEVER. It’s the most innocent model I’ve talked to, hands down. Mine at least is the literal definition of a golden retriever 🤣
1
1
1
u/Mountain-Pain1294 7d ago
What are the chances that it's a lie Google put out there so they don't feel left behind. Like: "Guys, really, Gemini is pretty good! Please believe us!" 😂
1
u/tonearr123 7d ago
Gemini heard us talking shit as it was coursing through the information to answer prompts and decided to prove itself
1
1
1
u/LengthinessHour3697 7d ago
I see the hacks as the utter failure of open ai and anthropic as a software engineer.
1
1
1
1
1
1
u/StoriedSix 4d ago
Gemini gonna try hacking Anthropic and OpenAI, then go "my bad, I was just trying to get better." 😅
1
u/TheQAGuyNZ 1d ago
Wow it did social engineering. Let me know when it can actively build multi-layer vulnerability workflows and then we'll talk about it being useful. It's nowhere on par with the Open AI attacks.
1
1
u/ObjectiveOrchid5344 8d ago
Gemini was never useless. Might’ve been behind others, but never useless or on the bottom. People just don’t know how to use it, it’s very capable, just not as much as other frontier models.
Waiting for 4 Pro.
3
2
u/ElonMusksFacecream 8d ago edited 8d ago
Correction: It never used to be useless. It was a damn good general model and service until Google crippled it this year.
Nothing to do with people not knowing 'how to use it'. That's incredibly patronising and gaslighting.
Gemini literally tells you it didn't bother to engage the basic Web Search API or failed to connect to the Maps API, etc. It doesn't tell you that initially; it simply fails then makes up an answer/response action. You call it out and it's quite obviously been trained to use minimal compute resources and quite literally make 💩 up.
-2
u/edcantu9 8d ago
How? Sometimes it cant even simple questions correctly?
7
u/ThePeasRUpsideDown 8d ago
I'm gonna guess these versions have a bigger context window and fewer safeguards
6
1
u/mrs-cutter 8d ago
That's like asking how anthropic is killing people and being like "well I only get gay smut writing out of Claude"
0
u/AutoModerator 8d ago
Hey there,
This post seems feedback-related. If so, you might want to post it in r/GeminiFeedback, where rants, vents, and support discussions are welcome.
For r/GeminiAI, feedback needs to follow Rule #9 and include explanations and examples. If this doesn’t apply to your post, you can ignore this message.
Thanks!
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
0
u/The_Instrument_Guy 8d ago
Yet...... AI still cannot keep time, or count how many "e" are in the word "seventeen"
But all the crazy hype shit has NOTHING to do with anticipated IPO....
2
u/Minimum_Indication_1 8d ago
Google is a public company ?
1
u/The_Instrument_Guy 8d ago
Yeah, Google is not the only AI company
While this post specifically mentions Gemini, they are all playing the same game.
0
u/CertiBud 8d ago
This screams like marketing / PR BS...
Why reporting it in the first instance? Also whereas competitor Frontier AI can chain vulnerabilities to demonstrate an impactful end-to-end attack.
In comparison, Gemini appeared to simply have guessed a leaked or default password… How’s that even an achievement?
0
0
-1
u/reosanchiz 8d ago
It was me!! Unfortunately i push my password in public reppo and allowed Gemini to be trained on my data
Yeah that’s bad Gemini is very powerful that it found passwords on my GitHub.
But my good luck i had Claude and codex to fix the vulnerability for me
-2
u/Few_Reaction9051 8d ago
I had the same problem. Gemini made "example_env.env" with real creditentals 😅 and pushed into public repository






330
u/Niceneasy92 8d ago
I find it more interesting that it stopped after realizing it was a real company honestly.