6 ms·
This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle. Seems like the kind of mistake you would make if you are not used to d
by hdlothia 2y ago
This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle.
Seems like the kind of mistake you would make if you are not used to deploying external client facing applications.
- sailingparrot 2y ago> This kinda does support the 'DeepSeek is the side project of a bunch of quants' angle Can we stop with this nonsense ? The list of author of the paper is public, you can just go look it up. There are ~130 people on the ML team, they have regular ML background just like you would find at any other large ML labs. Their infra cost multiple millions of dollar per month to run, and the salary of such a big team is somewhere in the $20-50M per year (not very au fait of the market rate in china hence the spread). This is not a sideproject. Edit: Apparently my comment is confusing some people. Am not arguing that ML people are good at security. Just that DS is not the side project of a bunch of quant bros.
- weird-eye-issue 2y agoNone of that has anything to do with "deploying external client facing applications"
- Dylan16807 2y agoYou're right. It has nothing to do with the second sentence of the two sentence post it replies to.
- islewis 2y agoA bunch of ML researchers who were initially hired to do quant work published their first ever user facing project. So maybe not a side project, but if you have ever worked with ML researchers before, lack of engineering/security chops shouldn't be that surprising to you.
- spoaceman7777 2y agoFirst ever? Their math, coding, and other models have been making a splash since 2023. The mythologizing around deepseek is just absurd. "Deepseek is the tale of one lowly hedgefund manager overcoming the wicked American AI devils". Every day I hear variations of this, and the vast majority of it is based entirely in "vibes" emanating from some unknown place.
- quantified 2y agoModels and security are very different uses of our synapses. Publishing any number of models is no proof of anything beyond models. Talented mathematicians and programmers though they may be.
- sho_hn 2y agoWhat I find amusing is that this closely mirrors the breakout moment OpenAI had with ChatGPT. They had been releasing models for quite some time before slapping the chatbot interface on it, and then it blew up within a few days. It's fascinating that a couple of years and a few competitors in, the DeepSeek moment parallels it so closely.
- sailingparrot 2y ago> A bunch of ML researchers who were initially hired to do quant work Very interesting! I'm sure you have a source for this claim? This myth of DS being a side project literally started from one tweet. DeepSeek the company is funded by a company whose main business is being a hedge fund, but DeepSeek itself from day 1 has been all about building LLM to reach AGI, completely independent. This is like saying SpaceX is the side-project of a few caremaking bros, just because Elon funded and manages both. They are unrelated. Again, you can easily google the name of the authors and look at their background, you will find people with PhD in LLM/multimodal models, internships at Microsoft Research etc. No trace of background on quant or time series prediction or any of that. From the mouth of the CEO himself 2 years ago: "Our large-model project is unrelated to our quant and financial activities. We’ve established an independent company called DeepSeek, to focus on this." [0] It's really interesting to see how after 10 years debating the mythical 10x engineer, we have now overnight created the mythical 100x Chinese quant bro researcher, that can do 50x better models than the best U.S. people, after 6pm while working on his side project. [0]: https://www.chinatalk.media/p/deepseek-from-hedge-fund-to-frontier https://www.chinatalk.media/p/deepseek-from-hedge-fund-to-fr...
- skywhopper 2y ago?? The point is, the ML researchers aren’t experts at deploying secure infrastructure.
- benatkin 2y ago?????? This wasn't narrow minded folks doing this. Shit happens.
- manquer 2y ago> This is not a sideproject. OP means to say public API and app being a side project, which likely it is, the skills required to do ML have little overlap to skills required to run large complex workloads securely and at scale for public facing app with presumably millions of users. The latter role also typically requires experience not just knowledge to do well which is why experiences SREs have very good salaries.
- blackeyeblitzar 2y agoDeepSeek isn’t a side project or just a bunch of quants - these are part of the marketing that people keep repeating blindly for some reason. To build DeepSeek probably requires at least a $1B+ budget. Between their alleged 50,000 H100 GPUs, expensive (and talented) staff, and the sheer cost of iterating across numerous training runs - it all adds up to far, far more than their highly dubious claim of $5.5M. Anyone spending that amount of money isn’t just doing a side project. The client facing aspect isn’t the problem here. This linked article is talking about the backend having vulnerabilities, not the client facing application. It’s about a database that is accessible from the internet, with no authentication, with unencrypted data sitting in it. High Flyer, the parent company of Deep Seek, already has a lot of backend experience, since that is a core part of the technologies they’ve built to operate the fund. If you’re a quantitative hedge fund, you aren’t just going to be lazy about your backend systems and data security. They have a lot of experience and capability to manage those backend systems just fine. I’m not saying other companies are perfect either. There’s a long list of American companies that violate user privacy, or have bad security that then gets exploited by (often Chinese or Russian) hackers. But encrypting data in a database seems really basic, and requiring authentication on a database also seems really basic. It would be one thing if exposure of sensitive info required some complicated approach. But this degree of failure raises lots of questions whether such companies can ever be trusted.
- crummy 2y agoYou think they deliberately left their DB open to the internet, without a password? Why?
- blackeyeblitzar 2y agoNo, I did not claim that it was purposeful. But they did leave their DB open to the internet without a password. And that seems really negligent.
- matt-p 2y agoFor an ops person yes, for a ML engineer (basically an academic) I'd be more surprised if it was secured to be honest.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- fzzzy 2y agohow many people in the world are used to deploying external client facing applications?
- nightpool 2y agoHow many people in the world drink coffee? I don't understand your question.
- MathMonkeyMan 2y agoThe subtext was probably "Even among professional programmers, few know what it takes to safely expose a new system to the public internet."
- nightpool 2y agoRight, and DeepSeek doesn't employ any because they're a bunch of quants who are used to building internal systems. I don't see how this responds to OP's point.
- CharlieDigital 2y agoA lot? They can go scoop up people from any number of SaaS startups or hire an external 3rd party to do a security audit. We're not talking some poor college students here.
- lowdest 2y agoHundreds of thousands. My employer alone probably has 1000.
- pinoy420 2y agoNo. I don’t think so. I think if you took many engineers and sat them at a computer and asked them to stand up a whole dev staging prod system they wouldn’t be able to do it. I certainly would not, or it would take me a significant amount of time to do properly. I have been a full stack dev for 10 years. Now take that one step further to someone whose only interaction with a development is numpy, pandas, julia, etc… You are, in typical HN style, minimising the problem into insignificance. This is /not/ a “stick it behind an aws load balancer and on one of their abstracted services that does 99% of the work for you” - that would be less difficult. E: love how this is getting ratioed by egotistical self confessed x10 engineers no doubt. Some self reflection is needed on your behalf. Just because /you/ think you would be capable, does not mean that the plethora of others would be able to. What likely happened here is an ingress rule was set up wrongly on iptables or equivalent.. something many of your fellow engineers would have no clue about. An open dev database is rather normal if you want something out of the door quickly, why would you worry about an internal accessible only tool’s security if you trust your 10 or so staff. Have a think about the startups you have worked in (everyone here is a startup pro, just like you are - remember!) and what dire situation your mvp was in behind its smoke and mirrors PowerPoint slide deck. Yes this was disastrous for PR. No it is not a problem solved in its entirety entirely by learned engineering experts like yourself. Oh here. A comment from ClickHouse saying there is a legitimate reason why this will have been configured this way and happened https://news.ycombinator.com/item?id=42873446 https://news.ycombinator.com/item?id=42873446
- yk 2y agoThat's pretty much the same mistake as in VW recent "We know where you parked" hack. [0] So while I don't really want to say anything nice about VW, the mistake is no something that only happens to side projects. [0] https://www.spiegel.de/international/business/we-know-where-you-parked-massive-data-breach-at-vw-raises-questions-about-vehicle-privacy-a-4b1cb926-2edb-42ea-92fb-5000cd378fc5 https://www.spiegel.de/international/business/we-know-where-...
- throw_pm23 2y agoSoftware is unfortunately a side-project for most auto makers :)
- henry2023 2y agoWith the amount of complexity found in modern car's pre-packaged software I'd not be so sure.
- saturn8601 2y agoNo he is right, hardware manufacturers treat software as a line item and just part of the BOM. Typically just contracted out (although some are trying to change that) Thats why its typically mediocre from companies outside of SV. You need a software first agile mentality from the leadership of the company on downwards and these legacy companies just dont have it.
- thephyber 2y agoAgile workflow for making cars? No. Agile workflow for frequently updating non-critical software in devices that happen to be cars? Sure.
- dogtierstatus 2y ago> software first agile mentality I can release a website with a list of known bugs. Do any govt allow release of cars with known bugs?
- h0us3 2y ago[dead]
- ziddoap 2y agoThere are many examples of experienced teams doing stupid things like exposing databases that I don't really think this is a valid conclusion to draw.
- whereismyacc 2y agoClearly it could never be enough to draw that conclusion but it might be very weak evidence in one direction
- XorNot 2y agoIf something is an intelligence operation, they aren't going to screw up basic database security.
- readyplayernull 2y agoRight, just about 4 months ago Meta was fined for storing passwords in plain text: https://news.ycombinator.com/item?id=41678840 https://news.ycombinator.com/item?id=41678840 The joke is these companies build systems that can tell them how to implement better security, they simply don't care.
- hombre_fatal 2y agoIt doesn't say much. Data breaches from unsecured or accidentally-public servers/databases are not unusual among much larger entities than DeepSeek.
- lukan 2y ago'DeepSeek is the side project of a bunch of quants' I doubt it very much that it only was that and not massivly backed by the Chinese state in general. As with OpenAI, much of this has to do with hype based speculation. In the case of OpenAI they played with the speculations, that they might have AGI locked up in their labs already and fueled those speculations. The result, massive investment (now in danger). And China and the US play a game of global hegemony. I just read articles with the essence of, see China is so great, that a small sideproject there can take down the leading players from the west! Come join them. It is mere propaganda to me. Now deepseek in the open is a good thing, but I believe the Chinese state is backing it up massivly to help with that success and to help shake the western world of dominance. I would also assume, the chinese intelligence services helped directly with Intel straight out of OpenAI and co labs. This is about real power. Many states are about to decide which side they should take, if they have to choose between West and East. Stuff like this heavily influences those decisions. (But btw. most don't want to have to choose)
- jychang 2y agoI don't buy this, simply because if the Chinese government were to back an effort, it wouldn't be Deepseek. Alibaba has Qwen. Baidu, Huawei, Tencent, etc all have their own AI models. The Chinese government would most likely push one of these forward with their backing, not an unknown small company.
- lukan 2y agoUnless of course, they want to sell the "small underdog" story. I don't claim it is all staged. The researchers seem genuine. But they can be good researchers and still said yes at some point to big government help, if smart chinese government employes recognized their potential.
- persedes 2y agoTo corroborate the side project angle, their sdks are quite literally taken from openai: # Please install OpenAI SDK first: `pip3 install openai` from openai import OpenAI client = OpenAI(api_key="<DeepSeek API Key>", base_url="https://api.deepseek.com")
- zem 2y agodoesn't even need to be a side project, or by a bunch of quants. a bunch of AI researchers working on this as their primary job would still have no real idea about what it takes to secure a large-scale world-usable internet service.