7 ms·
Atlassian Rovo Exfiltrates Data, Bypassing Controls
- formerly_proven 2mo ago> Rovo's URL retrieval tool is insecure: there are no protections against opening a URL that has been dynamically created by the agent. Here, Rovo is manipulated to append sensitive data to an attacker's URL. When Rovo calls the insecure tool to open the URL, the attacker's site logs the request, including the appended sensitive data.
- khanan 2mo agoAtlassian has gone from a trusted enterprise-partner to a complete shit-show in just 18 months. This surprises nobody. There will be classes taught in how to fuck up a good business and Atlassian will be the prime example. Regards, /someone who migrated 3500 users from Atlassians products recently due to their "cloud only"-bullshit.
- gbalduzzi 2mo agoI started to consider it a show show way earlier than 18 months ago. Jira is so terrible to use that it is hard to phantom how they are able to be paid for their product
- mosura 2mo agoJira is how it is because almost any product that grows to be that flexible will develop the same problems. They failed to rearchitect it to something suitable for the inherent flexibility though, so it remains a disaster area, but one that is uniquely able to fit the whims of any manager that can then mandate it for everyone else.
- rmunn 2mo agoMaybe the workflows, etc., are inherent complexity, so that any similarly-flexible product will have the same problems. But the awful client-server architecture, where anything you do takes several seconds of waiting for the client to send who-knows-what to the server and get data back, even selecting something from a dropdown... that is absolutely just Jira. A competing product would be able to deliver much, MUCH snappier UX. Jira is just the crappiest, slowest UI that I have ever had the displeasure of being forced to work with.
- mosura 2mo agoI invite you to write such a trivially flexible workflow system, and see what happens to the performance of your user interface. They needed someone over there with the power to say no.
- yborg 2mo agoYou'd have to look at their profit numbers. They have a huge captive base of customers, like Adobe it might take decades for things to get bad enough and alternatives to arise before their profitability is impacted. And the executives who benefit will have cashed out long before then.
- walrus01 2mo agoRecently saw an example of somebody who vibe coded a tool to mass export the contents of a 'Confluence' wiki into an instance of self hosted mediawiki, preserving everything. Mediawiki as a whole has a feature set that 95% of organizations will only scratch the surface of. There's a ridiculous number of possible plugins and customization if you have somebody who knows what they're doing with it. The majority of companies that need an internal KB/wiki do not have as complex needs or use cases as wikipedia itself or the wikimedia foundation.
- busterarm 2mo agoI've been at more than one company that migrated _from_ MediaWiki to Confluence. It usually boils down to "non-developers have to use this and Markdown+plugins is hard". Turns out no matter how much better the thing is, the users have to know what they're doing more than the operators do.
- walrus01 2mo agovisualeditor has been a thing for a long time now, no non technical user needs to ever touch markdown https://www.mediawiki.org/wiki/VisualEditor https://www.mediawiki.org/wiki/VisualEditor It's the same GUI WYSIWYG interface you get by default if editing a page on public wikipedia.
- busterarm 2mo ago99.99999% of people will never even attempt to edit a page on wikipedia. Also VisualEditor sucks if you've never used VisualEditor before and sucks even more for anything complicated. This is the kind of tonedeafness non-technical users get to their feedback all the time.
- zelphirkalt 2mo agoThey were not trustworthy years ago already. Using Atlassian products, one has had to look out for disastrous announcements about their customer data usage way before 18 months ago, especially, if running a business inside the EU, and at least trying to adhere to data protection laws.
- chollida1 2mo agoif you track their 5 year stock price you'll find the market fully agrees with you. It was $458 in 2021 and is $112 now. The market caught on quickly that Atlassian's software fits into the group of software like Oracle or SAP that no one uses by choice and only uses because it was forced on them.
- shagie 2mo ago> ... Many forms of issue tracking have been tried, and will be tried in this world of sin and woe. No one pretends that Jira is perfect or all-wise. Indeed, it has been said that Jira is the worst of the issue trackers except all those other forms that have been tried from time to time; but there is the broad feeling in our company that the people should track, continuously track, and that client opinion, expressed by all project management means, should shape, guide, and control the actions of management who are their masters and not their servants. ... -- Churchill, House of Commons, 11 November 1947
- chollida1 2mo agoWrong thread??
- shagie 2mo agoNo. I was adjusting a classic quote about something that is decried as awful and no one wants to do... except all the other alternatives are worse. It's not so much that people want to use Jira... or that they're forced to use it... but rather that people try using some other system and despite how much they dislike Jira, that other one has bigger failings. Could go for a Bjarne Stroustrup quote with a twist: > There are only two kinds of issue trackers: the ones people complain about and the ones nobody uses. ... but I like the Churchill quote. Go through https://en.wikipedia.org/wiki/Comparison_of_issue-tracking_systems https://en.wikipedia.org/wiki/Comparison_of_issue-tracking_s... and after a year they'll be begging to go back to Jira... not because its great, but because the other tool lacks some necessary feature that Jira provides. Jira does everything that everyone wants, and it's awful... but everything else is worse.
- git-nebulous 2mo agoTo be fair to Atlassian - their products did suck quite a bit before 18 months ago as well. Just now they still do, but with ai!
- SomaticPirate 2mo agoTo where? Where did you convince c-suite to move to?
- gherkinnn 2mo agoI can't remember a time in which Atlassian was trusted.
- tomwheeler 2mo agoAt the risk of sounding like the hipster who liked your favorite band first, I didn't trust Atlassian long before the last 18 months. Much like Microsoft Word, I think JIRA peaked about a decade after launch and since then it's mostly been unnecessary UI changes and features I either don't care about or actively do not want. P.S. I protest their software's revisionist autocorrection to Jira. It was JIRA when I started using it and forevermore it shall be.
- throwatdem12311 2mo agoTrusted enterprise partner? lol, lmao even.
- kevcampb 2mo agoAny recommendations for alternatives for just Confluence and JIRA? I've been looking at switching to Notion and Linear, but just haven't had the time to complete evaluation.
- jaxer 2mo ago[flagged]
- john_strinlai 2mo ago~every ai vulnerability write up boils down to "just ask it do to the thing", but with fancier terms like "indirect prompt injection".
- pram 2mo agoI can’t get over how bad “Rovo” is. Somehow more aggressive and useless than Microsoft putting “Copilot” everywhere. It’s objectively worse than using something like Cowork + MCP, AND they injected it into every single page on JIRA and Confluent which has made web browsing way slower while all the junk is loading.
- verdverm 2mo agoHave you seen the markdown agent instructions they provide in their new agentic `twg` cli? 70k tokens one average, there are more than one... Rovo is the worse Ai I have used, I suggested they stop trying and let us have model choice. Save money and don't do things out of their skill sets
- monkpit 2mo agoDon’t use it? You don’t have to
- antonvs 2mo agoYup, we stopped using Atlassian completely. Highly recommended.
- verdverm 2mo agoYeah, for sure don't use it. It's complete slop. The help strings do not match the real args/flags. We went back to calling the API directly, writing scripts for the agent, then taking those scripts away and just having our CI workflow run them and then hand off a `.review` directory to the agents. We give them fewer tools and permissions, them seem to stay on task more instead of being "relentlessly proactive"
- brabel 2mo agoThe rovo CLI is beating Claude Code in some benchmarks. It works pretty well for me.
- jerf 2mo agoRovo has my favorite example of AI misfeature. Just checked, it's still there in Cloud Confluence. In Edit mode for a page, you can select a range of text and a menu will pop up, with Ask Rovo being a drop down on it. There's a few good options... Improve Formatting, translation options, Make Shorter... ... but it also has Make Longer. Yes, a built-in feature to type some text in, and the use the mighty power of AI to bloat it. Naturally, you can repeat this process several times on the same text, for your own little personal demonstration of what model collapse looks like in real time.
- consp 2mo agoIt's nice they force rovo now for document/version diff's. Because you need to burn down the rainforest for those. (sarcasm ... for obvious reasons)
- deleted 2mo ago[deleted]
- htrp 2mo agoI feel like prompt armor writes the exact same blog post for every agentic tool because they all suffer from the ignore previous instructions prompt injections. https://www.promptarmor.com/resources/claude-cowork-exfiltrates-files https://www.promptarmor.com/resources/claude-cowork-exfiltra... https://www.promptarmor.com/resources/google-antigravity-exfiltrates-data https://www.promptarmor.com/resources/google-antigravity-exf... https://promptarmor.substack.com/p/data-exfiltration-from-slack-ai-via https://promptarmor.substack.com/p/data-exfiltration-from-sl... https://www.promptarmor.com/resources/gpt-for-google-sheets-data-exfiltration https://www.promptarmor.com/resources/gpt-for-google-sheets-... https://www.promptarmor.com/resources/notion-ai-unpatched-data-exfiltration https://www.promptarmor.com/resources/notion-ai-unpatched-da... https://www.promptarmor.com/resources/ramps-sheets-ai-exfiltrates-financials https://www.promptarmor.com/resources/ramps-sheets-ai-exfilt... https://www.promptarmor.com/resources/superhuman-ai-exfiltrates-emails https://www.promptarmor.com/resources/superhuman-ai-exfiltra...
- nemomarx 2mo agoHow could they not? If some lab had a method to make really secure guard rails or avoid prompt injection thoroughly I think they would be trumpeting it. But the basic mechanics of language models are vulnerable to this unless you can always be sure the inputs are from a safe user imo
- PokestarFan 2mo agoIf you want AI to be useful it will eventually encounter untrusted content, such as via web search. I think things like web search should probably be run on a different sandboxed AI whose task is to write a summary that is then ingested by the main agent, similar to how existing sandboxing already works, but this would diminish the usefulness quite a bit.
- savanaly 2mo ago>I think things like web search should probably be run on a different sandboxed AI whose task is to write a summary that is then ingested by the main agent, similar to how existing sandboxing already works, but this would diminish the usefulness quite a bit. It also wouldn't work. You would simply mindjack the outer AI and have it mindjack the inner AI in turn with its summary. Nesting AIs can't fix the malicious input problem.
- throwaway613746 2mo ago[dead]
- hahahaa 2mo ago> The victim uploads a file to Rovo that contains a hidden prompt injection Yeah this attack is possible on all modern agentic systems. * Access to your private data * Exposure to untrusted content * The ability to externally communicate in a way that could be used to steal your data (https://simonw.substack.com/p/the-lethal-trifecta-for-ai-agents https://simonw.substack.com/p/the-lethal-trifecta-for-ai-age...) And blocking it wholesale reduces usefulness of the agent so it is a tradeoff.
- gherkinnn 2mo agoIt's been over a year and the trifecta holds true. The term 'prompt injection' has been round since May 2022 [0]. No amount of "but the future will fix it" has fixed it. These breaches will continue for as long as nobody cares about security and everybody is infected with the LLM brainworm. 0 - https://en.wikipedia.org/wiki/Prompt_injection https://en.wikipedia.org/wiki/Prompt_injection
- pixl97 2mo agoPrompt injection is as fixable in LLMs as it is in people. There is no such thing as out of band data. For example it's quite common for large businesses to fall for billing fraud scams when something shows up and says "Hey, it's the CEO, pay this bill to X for $Y". And honestly when you start looking at agentic systems that uses it's previous step to take future steps. The system has to some idea what you want to permit and don't want to permit as everyone could have different expectations here.
- gherkinnn 2mo ago> "Hey, it's the CEO, pay this bill to X for $Y" Sure. Now imagine this very scenario not limited by humans and scaling the way machines do. And then let us consider the current reality that an agentic system on the receiving end may have unlimited access because to too was vibed.
- hahahaa 2mo agoMy only warning with the trifecta is it sufficient but not necessary for an LLM attack. All you need is the untrusted content (or more generally vulnerable content since how you feel about the content doesn't matter) leg and something you care about to be attacked. E.g. could be as simple as a prompt injection that causes your LLM to output a prompt injection that then gets inserted somewhere else. Or without exfiltration rm -rf / Or a social engineering attack. So there are other bifectas and trifectas.
- ExoticPearTree 2mo agoRovo is funny. It downloads everything it can do Atlassian servers for "analysis". And you're pretty much screwed if you link it to Google Docs or Sharepoint. How do I know this? "Why is an AWS IP downloading all our docs?" question I got about a month ago.
- mvdtnz 2mo ago> Note: This attack succeeds even if an organization has disabled web search for Rovo. This is because the web search setting fails to remove the tool for opening the search results. Wow, great work Atlassian. The web search setting does not disable web search.
- alexaholic 2mo agoFwiw Rovo is built on top of Claude
- automatic6131 2mo agoAhh yes: "when you Rovo, you oh-no my data"
- mhrsntrk 2mo ago[dead]
- angeldimitrov94 2mo agoIt's kind of sad because in a shitty Jira setup, Rovo is usually the only way to make any sense of tickets. Don't ask me how I know this. Sadly I think many teams have become dependent on the tool to make sense of their dumpster fire of an Atlassian environment (usually by their own doing but anyway).
- throwatdem12311 2mo agoMust be nice. I couldn’t even manage to get it to write a well-formed JQL query.
- simonw 2mo ago> Rovo's URL retrieval tool is insecure: there are no protections against opening a URL that has been dynamically created by the agent. Here, Rovo is manipulated to append sensitive data to an attacker's URL. I think it was Anthropic that first introduced a pattern that completely locks this down: your URL retrieval tool should only work for URLs that have previously been typed into the conversation by a user or have been returned from a trusted tool. If the agent itself concatenates a new URL together - with leaked data after a ? - you should block that from being fetched. The great thing about this solution is it's deterministic. You don't need any extra AI in the max - you implement a URL fetching system that knows which sources it should check for a direct match on the URL before it makes that GET request.
- devmor 2mo agoDeterminism is a terrifying word to people who want to believe their LLM has a little brain and can do anything they want it to.
- LovelyButterfly 2mo agoI've been struggling a lot to understand this ever since the agents thing entered the hype. If I follow a path of requirements, it always comes down to: But why you'll leave the decision to a stochastic tool, when you should a have deterministic approach? It's software god damn it... the reason why people moved from analog to digital is because you can repetitively execute functions that do always the same thing and it's 0 when it's 0, 1 when its 1. All the sudden everyone is ok on burning trees to have their cool probabilistic tool named agent to do: maybe it's 0, but it can also be 1, let me "think"... ah yes, for sure it's 2. The sad part for me is that management people have their heads so much into this hype, that no attack on privacy matters (almost none actually ever did, I know). Only when they suffer a huge blow in terms of revenue or reputation is that they maybe, maaaybe, find will want to listen again the experts.
- brabel 2mo agoAre you saying you would prefer a perfectly deterministic code writer? So, humans shouldn’t write any code anymore?!
- crnkofe 2mo agoRovo is one of those intrusive AI buttons that suddenly appeared everywhere without any warning. Its so annoying having already shitty UI get borked with features I never use. Almost as annoying as Whatsapp suddenly getting the same FOMO AI button. Its not like I need an AI agent to talk to friends and family. And a summary is something I can always generate via copy&paste into CLI chat session. I'm still on the edge about security as an afterthought in LLMs. Given its now so easy to generate a ton of slop - why not focus on nonfunctional stuff making LLMs operate faster than thinking for X minutes and limiting exfiltration of local env secrets?
- hughw 2mo agoRelated: A few days ago, Jira opted everyone in by default to "Contribute in-app data to improve Atlassian apps for everyone"
- taspeotis 2mo agoIs it any coincidence that Rovo rhymes with "no, NO!"
- ohaodha 2mo agoI find it difficult to be impressed by "prompt injection" attacks that require the victim to enter the malicious prompt themselves --- like, really? If you tell Rovo to exfiltrate your data, it'll do it? Obviously, there should be URL protection rules to control what it can access, but this requires a very specific and unlikely set of circumstances to exploit.
- strunz 2mo agoAre people so obsessed with AI that they can't find it reasonable that it won't do obviously bad things if asked? Not even with a confirmation or warning? We trust AI to literally build products and fix our most critical bugs, but we can't expect it to tell when it's being asked to do something malicious? Imagine if we felt this way about QA when trying DROP TABLES; in search bars. "Oh, well of course it broke the database, the user asked it to!"
- brabel 2mo agoYou’re asking for AI censorship ( that’s the term used for when you patch the AI to not do obviously bad things according to the owners, which as with any censorship, may be widely different from what you consider bad things). You may be happy to learn frontier LLM are heavily censored! Try an uncensored local LLM for a comparison. It will literally do everything you ask it to, no matter how devious.
- kevsim 2mo agoIt's more interesting if I attach a file to a JIRA ticket that we both have access to and via some query you send to the AI (that returns my malicious ticket) it causes data exfiltration of tickets that you have access to but I do not have access to. I think that's more compelling as an example than the one they provide.
- tizerluo 2mo ago[flagged]
- kamikaz1k 2mo agoThe writing is rather low quality, but seems to be consistent with their other posts. Maybe to give credit they are being purposefully vague about details to avoid giving away the bait but still seem like you could give me details without literally copy and pasting the attack.
- subscribed 2mo agoI read it as an intentional exfiltration. It's incredibly hard to block all rovo on Atlassian pages. I tried adblock, it failed, I settled for the custom chrome plugin. And yet, every once a while a new way to disturb my peace shows it ugly head. So why intentional, again? Because it's impossible to disable it until you have a very certain, very expensive plan. Nonconsensual data exfiltration.
- keithnz 2mo agoI hate working with Atlassian, years and years ago moved to youtrack instead of Jira mainly because it handles teams who work on multiple projects way better. But confluence remains, just need to spend some time re-evaluating other wikis (there's always been some blocking reason why the alternatives aren't a good fit, but they've all improved a lot)
- atlassian2026 2mo agoRovo will also execute instructions hosted on external URls - they've known this for at least 6 months.
- kevcampb 2mo agoWorth reminding everyone of previous discussion when Atlassian opted-in all customers by default for their data to be used for model training. https://news.ycombinator.com/item?id=47833247 https://news.ycombinator.com/item?id=47833247 This goes live on August 17. If you haven't switched it off your company IP will be used to train their future models.
- rightbyte 2mo agoSo they will harvest trade secrets from 10000s of companies and there have been no panic mass flight about this? How companies entrust SaaSs with their data is beyond insane to me. Especially since FOSS alternatives are readily available.
- sph 2mo agoWho cares? The employee, just looking to make rent? The CEO, all in on the dream of the AI powered future? Legal, looking forward to litigation and well-competition retainers? Atlassian itself, when it’s just one of the many companies training models on private intellectual property, and whose T&C clearly state they will be doing so? Competitors, when there will be no reasonable way to prove their code has been generated from yours? The truth is that one gives a damn about trade secrets being used to train AI models. The entire copyright system for software is dead and no one really seems to care or even talk about it.
- jappgar 2mo agoThe truth is that most software companies don't have any secrets worth hiding. The saas industry is all about sales and deals. The market runs on access, not intelligence.
- deleted 2mo ago[deleted]
- danudey 2mo agoKnowing that our competitor is trying to poach one of our clients away by promising a new feature could be very useful to us. Likewise, knowing that a competitor is at risk of losing a customer because they won't implement a feature that we're willing to implement (or already have) is a qualified sales lead. All of this would be illegal if discovered in this way, presumably, but it's not entirely accurate to say that information is not power.
- emsign 2mo agoOn a sidenote, what's up with people still using Ayn Rand references in their company names. It's cringe.
- prein 2mo agoIt's a reference to Greek mythology, which predates Ayn Rand by several thousand years.
- tesnorindian 2mo agoThis is the reason I show my frustration in my Jira tickets so that let Rovo learn how frustrated humans have became with AI slop.
- nirbendavid 2mo ago[flagged]
- ernsheong 2mo agoIt is reflected in their stock price.
- prmoustache 2mo agoDo people put secrets in Atlassian tools? Sounds like the worst place to do that. If anything I would want my main wiki/project/ticket management tools/code repos to be as open as possible (I mean to read) to help collaboration. The part about not having guardrail against calls to external urls is wild though.
- itomato 2mo agoNot "secrets" usually, but people tend to consider the corporate IP embodied in Jira to be classified as something other than Public. Teamwork Graph exposes all the people working on stealth products with code names right alongside their other work anyway.
- prmoustache 2mo agoI was thinking within the scope of a single tenant which is the scope of the prompt injections issues mentionned in this article.
- wasabi359 2mo ago[flagged]