Need help?
<- Back

Comments (64)

  • htrp
  • simonw
    > Rovo's URL retrieval tool is insecure: there are no protections against opening a URL that has been dynamically created by the agent. Here, Rovo is manipulated to append sensitive data to an attacker's URL.I think it was Anthropic that first introduced a pattern that completely locks this down: your URL retrieval tool should only work for URLs that have previously been typed into the conversation by a user or have been returned from a trusted tool.If the agent itself concatenates a new URL together - with leaked data after a ? - you should block that from being fetched.The great thing about this solution is it's deterministic. You don't need any extra AI in the max - you implement a URL fetching system that knows which sources it should check for a direct match on the URL before it makes that GET request.
  • pram
    I can’t get over how bad “Rovo” is. Somehow more aggressive and useless than Microsoft putting “Copilot” everywhere.It’s objectively worse than using something like Cowork + MCP, AND they injected it into every single page on JIRA and Confluent which has made web browsing way slower while all the junk is loading.
  • john_strinlai
    ~every ai vulnerability write up boils down to "just ask it do to the thing", but with fancier terms like "indirect prompt injection".
  • hahahaa
    > The victim uploads a file to Rovo that contains a hidden prompt injectionYeah this attack is possible on all modern agentic systems.* Access to your private data* Exposure to untrusted content* The ability to externally communicate in a way that could be used to steal your data(https://simonw.substack.com/p/the-lethal-trifecta-for-ai-age...)And blocking it wholesale reduces usefulness of the agent so it is a tradeoff.
  • ohaodha
    I find it difficult to be impressed by "prompt injection" attacks that require the victim to enter the malicious prompt themselves --- like, really? If you tell Rovo to exfiltrate your data, it'll do it?Obviously, there should be URL protection rules to control what it can access, but this requires a very specific and unlikely set of circumstances to exploit.
  • hughw
    Related: A few days ago, Jira opted everyone in by default to "Contribute in-app data to improve Atlassian apps for everyone"
  • ExoticPearTree
    Rovo is funny. It downloads everything it can do Atlassian servers for "analysis". And you're pretty much screwed if you link it to Google Docs or Sharepoint. How do I know this? "Why is an AWS IP downloading all our docs?" question I got about a month ago.
  • taspeotis
    Is it any coincidence that Rovo rhymes with "no, NO!"
  • consp
    It's nice they force rovo now for document/version diff's. Because you need to burn down the rainforest for those. (sarcasm ... for obvious reasons)
  • crnkofe
    Rovo is one of those intrusive AI buttons that suddenly appeared everywhere without any warning. Its so annoying having already shitty UI get borked with features I never use. Almost as annoying as Whatsapp suddenly getting the same FOMO AI button. Its not like I need an AI agent to talk to friends and family. And a summary is something I can always generate via copy&paste into CLI chat session.I'm still on the edge about security as an afterthought in LLMs. Given its now so easy to generate a ton of slop - why not focus on nonfunctional stuff making LLMs operate faster than thinking for X minutes and limiting exfiltration of local env secrets?
  • anon
    undefined
  • formerly_proven
    > Rovo's URL retrieval tool is insecure: there are no protections against opening a URL that has been dynamically created by the agent. Here, Rovo is manipulated to append sensitive data to an attacker's URL. When Rovo calls the insecure tool to open the URL, the attacker's site logs the request, including the appended sensitive data.
  • mvdtnz
    > Note: This attack succeeds even if an organization has disabled web search for Rovo. This is because the web search setting fails to remove the tool for opening the search results.Wow, great work Atlassian. The web search setting does not disable web search.
  • alexaholic
    Fwiw Rovo is built on top of Claude
  • angeldimitrov94
    It's kind of sad because in a shitty Jira setup, Rovo is usually the only way to make any sense of tickets. Don't ask me how I know this. Sadly I think many teams have become dependent on the tool to make sense of their dumpster fire of an Atlassian environment (usually by their own doing but anyway).
  • khanan
    Atlassian has gone from a trusted enterprise-partner to a complete shit-show in just 18 months. This surprises nobody. There will be classes taught in how to fuck up a good business and Atlassian will be the prime example.Regards, /someone who migrated 3500 users from Atlassians products recently due to their "cloud only"-bullshit.
  • mhrsntrk
    [dead]
  • throwaway613746
    [dead]
  • automatic6131
    Ahh yes: "when you Rovo, you oh-no my data"