6 ms·
Ramp's Sheets AI Exfiltrates Financials
- renewiltord 5mo agoSo we know Claude’s mitigation. What is Ramp’s? Same warning dialog? It’s funny that this technology only admits in-band signaling. Given that, any foreign content is risky. It’s actually quite interesting that the current technological ecosystem is built around a high trust situation: npm, pip, cargo all run foreign code in the developer context and communities have norms of downloading random people’s modules. And so I suppose it’s no surprise that we use LLMs - another tech that is high-trust: since it has no out of band signaling ability. But it seems like we’re very close to the end of the era where someone will use (in a sensitive system) arbitrary web content carrying the equivalent of merged code/data.
- BobbyTables2 5mo agoI hate the online repos. Sure it’s nice to have good libraries accessible. But is there any quality control against malicious packages? Or will one day some obscure “Unicode homograph” library end up pwning half the world because it was a dependency 10 layers deep for an optional but default-enabled feature that nobody cares about. Things like Visual Studio’s extension marketplace really acare me. It’s too easy to install Jim Bob’s “starter pack” of extensions that bundles many well known ones with an unheard of one… Or install the wrong “Python” extension because there are 20 with the same icon…
- nrengan 5mo ago[dead]
- carlyai 5mo ago"The PromptArmor Threat Intel Team responsibly disclosed this vulnerability to Ramp. Ramp's security team indicated that the issue was resolved on May 16, 2026." I think they mean March here
- sidewndr46 5mo agoMaybe AGI figured out time travel?
- jerf 5mo agoYes, I hate to be a grammar nazi online but I believe the correct tense is "Ramp's security team indicated that the issue wioll haven be resolved on May 16, 2026." per Dr. Dan Streetmentioner’s Time Traveler’s Handbook of 1001 Tense Formations.
- didgeoridoo 5mo agoAmazingly, there is already a recognized verb tense for this: https://en.wikipedia.org/wiki/Prophetic_perfect_tense https://en.wikipedia.org/wiki/Prophetic_perfect_tense
- Mr-Frog 5mo agoIt's kinda awesome that after decades of software and hardware advancements to prevent computers from arbitrarily executing data as instructions, we've decided to let agents arbitrarily execute data as instructions.
- lenerdenator 5mo agoWell, yeah. It's that or pay a person to do it. When a person screws up, it's because they're stupid and lazy. When an AI agent does it, it's because, hey, technological frontier at work here, have you thought about refining your prompt? We need you to refine the prompt. Otherwise it's bad for our IPO.
- Henchman21 5mo agoTo what degree am I required to participate in mass delusions?
- Terr_ 5mo agoI imagine that somewhere a historian or political scientist is thinking: "Don't even get me started..."
- lenerdenator 5mo agoYes.
- dieselgate 5mo agoIs this sarcasm similar to the quote "Everyone who drives slower than me is an idiot and everyone faster is a maniac"
- deleted 5mo ago[deleted]
- DauntingPear7 5mo agoHas XKCD made another Bobby tables comic for prompt injection?
- bpt3 5mo agoWhat about this is a vulnerability, let alone one that requires responsible disclosure? Untrusted data sources can provide data that causes bad things to occur. If that's a vulnerability, then any application that ingests data is riddled with vulnerabilities. I agree that the behavior should change from a default of allowing external network requests to denying them, but this "report" reads like overly dramatic marketing BS.
- deleted 5mo ago[deleted]
- anonymars 5mo agoYes, stamping out file format vulnerabilities is indeed a Sisyphean task For example https://en.wikipedia.org/wiki/Melissa_(computer_virus) https://en.wikipedia.org/wiki/Melissa_(computer_virus)
- Terr_ 5mo ago> Untrusted data sources can provide data that causes bad things to occur. If that's a vulnerability, then any application that ingests data is riddled with vulnerabilities. There's an important difference between "the import had bad numbers so the report is wrong" versus "the import had a virus and now our network is compromised." They are not the same kind of failure, they don't have the same impacts, and they don't involve the same mechanisms for prevention, detection, or remediation.
- bpt3 5mo agoThis is a permissions issue with the spreadsheet. It's not all that different from people realizing that several popular model servers didn't support access control and could execute commands. It's an inherent part of the design that was rather naive from a security perspective, not something that requires coordinated disclosure or the rest of the security theater described in this marketing release.
- Terr_ 5mo agoExfiltration is merely one of the issues. The other is that an attacker can sneak something in that arbitrarily rewrites your spreadsheet. Triggers could be on content, or on a pre-planned attack time across many instances. Impacts could be subtly-flawed conclusions, or coarser "it stopped working and the deadline is looming" sabotage. "Yeah boss, I sent out the checks to every vendor listed in the spreadsheet, what's wrong?"
- mcontrac 5mo agoFind it funny that PromptArmor needed to reach out 3 times in a row to get a nearly month-late response that the issue "was resolved"
- ragall 5mo agoI once read about the signalling view of advertising, meaning it's used to show that a company is so prosperous that it can afford spending a lot of money in advertising. In the same way, I think from now on, as much as possible, I'll only buy from companies that will publicly make it a point not to use AI internally. AI use should brand companies as desperate and unreliable.
- pentagrama 5mo agoConcidentially, today I was watching and interview with a lead designer from Ramp who is telling about how they are full ia, agents and automation https://youtu.be/KPDXMtmkcgk https://youtu.be/KPDXMtmkcgk
- mday27 5mo agoRamp does seem to have a genuinely good product, but every time I interact with anyone who works on it, I'm struck by how much they want to talk about how hardcore and advanced their working style is. This was true before AI, and it's very true now
- strange_quark 5mo agoYeah it’s super weird. I know a guy that works there, really nice person outside of work, but the way he talks about his job is so weird. They make corporate expense software but they LARP like they’re on the bleeding edge of tech. My guy you make a slightly nicer Concur.
- lovich 5mo agoI’d believe you if you weren’t an 8 day old account hyping up an AI firm. I’ll believe in AI agent’s abilities the day two criteria can be met. 1. A killer app is made with it. 2. That app doesn’t rely on heavily subsidized models that are burning a dollar to make 20 cents.
- mday27 5mo agolol what? that wasn't a hype comment for Ramp, I'm kinda put off by Ramp's attitude. It gives me the ick like all the founders saying "I work 100 hour weeks" -- who cares, let's talk about your product. FWIW I agree with your criteria for AI agent success, and I haven't seen it happen yet.
- vicchenai 5mo ago[dead]
- sergiomattei 5mo agoWhy is Ramp even building a sheets product? That's the question zero that popped up to my head.
- hrimfaxi 5mo agoFinance practically lives in spreadsheets.
- ashdksnndck 5mo agoI suppose Ramp must try to become Excel before Excel becomes Ramp. Don’t want to end up like Slack and have to work for Marc Benioff.
- FlyThruTheSun 5mo ago[dead]
- jeremie_strand 5mo ago[flagged]
- beyondscaletech 5mo ago[flagged]
- beyondscaletech 5mo ago[dead]
- deferredgrant 5mo ago[flagged]