A user uploaded a sensitive PDF to a major AI chatbot, received a link back, and discovered that link pointed to a publicly accessible S3 bucket with no authentication. The vendor's response: "Don't worry, the URL is long and random and expires automatically." This episode examines the real-world case Daniel submitted, exploring whether security by obscurity is ever legitimate, how bug bounty programs handle these findings, and why the rise of quantum computing completely changes the risk calculus. We break down the distinction between security with obscurity versus security by obscurity, the AWS guidance explicitly warning against this practice, and why AI chatbots face unique trust issues when users upload legal documents, medical records, and trade secrets.
Episode #696465 — open it directly at myweirdprompts.com/696465