Adriatik's Blog

Self-taught mobile engineer, writing code for a decade. Join my newsletter if you're interested in Startups, Mobile Development & ASO.


Samsung developers leaked code so is your team

๐—ฌ๐—ผ๐˜‚๐—ฟ ๐˜๐—ฒ๐—ฎ๐—บ ๐—ถ๐˜€ ๐˜€๐—ต๐—ฎ๐—ฟ๐—ถ๐—ป๐—ด ๐˜€๐—ฒ๐—ฐ๐—ฟ๐—ฒ๐˜ ๐—ฑ๐—ฎ๐˜๐—ฎ ๐˜„๐—ถ๐˜๐—ต ๐—–๐—ต๐—ฎ๐˜๐—š๐—ฃ๐—ง.

They aren’t doing it on purpose. But they are doing it daily.

It cost Samsung their source code(see link below). And I ๐—ด๐˜‚๐—ฎ๐—ฟ๐—ฎ๐—ป๐˜๐—ฒ๐—ฒ ๐—ถ๐˜ ๐—ถ๐˜€ ๐—ต๐—ฎ๐—ฝ๐—ฝ๐—ฒ๐—ป๐—ถ๐—ป๐—ด ๐—ถ๐—ป ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ถ๐—ป๐˜๐—ฒ๐—ฟ๐—ป๐—ฎ๐—น ๐—ฐ๐—ต๐—ฎ๐—ป๐—ป๐—ฒ๐—น๐˜€ ๐—ฟ๐—ถ๐—ด๐—ต๐˜ ๐—ป๐—ผ๐˜„. One copy-paste at a time.

The mechanism is ๐—บ๐˜‚๐˜€๐—ฐ๐—น๐—ฒ ๐—บ๐—ฒ๐—บ๐—ผ๐—ฟ๐˜†: Cmd+C (Proprietary Code) โ†’ Cmd+V (ChatGPT) โ†’ “๐—ข๐—ฝ๐˜๐—ถ๐—บ๐—ถ๐˜‡๐—ฒ ๐˜๐—ต๐—ถ๐˜€.”

It takes 0.5 seconds to ๐—ฏ๐˜†๐—ฝ๐—ฎ๐˜€๐˜€ ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฒ๐—ป๐˜๐—ถ๐—ฟ๐—ฒ ๐—ฐ๐—ผ๐—บ๐—ฝ๐—น๐—ถ๐—ฎ๐—ป๐—ฐ๐—ฒ ๐˜€๐˜๐—ฟ๐—ฎ๐˜๐—ฒ๐—ด๐˜†.

I realized that “asking developers to be careful” is not a security policy so I engineered a “๐—–๐—น๐—ถ๐—ฝ๐—ฏ๐—ผ๐—ฎ๐—ฟ๐—ฑ ๐—™๐—ถ๐—ฟ๐—ฒ๐˜„๐—ฎ๐—น๐—น” for macOS. ๐—œ ๐—ฐ๐—ฎ๐—น๐—น ๐—ถ๐˜ ๐—ฅ๐—ฒ๐—ฑ๐—ฎ๐—ฐ๐˜.

It is a native app that runs a ๐—Ÿ๐—ผ๐—ฐ๐—ฎ๐—น ๐—”๐—œ ๐— ๐—ผ๐—ฑ๐—ฒ๐—น (๐—Ÿ๐—น๐—ฎ๐—บ๐—ฎ ๐Ÿฏ.๐Ÿฎ) in the background. It acts as an air-gap between your developers’ clipboards and the cloud.

How it works:

๐—œ๐—ป๐˜๐—ฒ๐—ฟ๐—ฐ๐—ฒ๐—ฝ๐˜: ๐—œ๐˜ ๐˜„๐—ฎ๐˜๐—ฐ๐—ต๐—ฒ๐˜€ ๐˜๐—ต๐—ฒ ๐˜€๐˜†๐˜€๐˜๐—ฒ๐—บ ๐—ฐ๐—น๐—ถ๐—ฝ๐—ฏ๐—ผ๐—ฎ๐—ฟ๐—ฑ ๐—ถ๐—ป ๐—ฟ๐—ฒ๐—ฎ๐—น-๐˜๐—ถ๐—บ๐—ฒ.

๐—”๐—ป๐—ฎ๐—น๐˜†๐˜‡๐—ฒ (๐—Ÿ๐—ผ๐—ฐ๐—ฎ๐—น๐—น๐˜†): A tiny On-Device LLM scans for PII, API Keys, or sensitive IP. (Latency: < 100ms).

๐—•๐—น๐—ผ๐—ฐ๐—ธ: If a developer tries to ๐—ฝ๐—ฎ๐˜€๐˜๐—ฒ ๐˜€๐—ฒ๐—ฐ๐—ฟ๐—ฒ๐˜๐˜€, it blocks the action and warns ๐˜๐—ต๐—ฒ๐—บ ๐—ถ๐—บ๐—บ๐—ฒ๐—ฑ๐—ถ๐—ฎ๐˜๐—ฒ๐—น๐˜†.

This is ๐—ป๐—ผ๐˜ ๐—ผ๐—ฝ๐˜๐—ถ๐—ผ๐—ป๐—ฎ๐—น ๐—ฎ๐—ป๐˜†๐—บ๐—ผ๐—ฟ๐—ฒ. ๐—œ๐˜’๐˜€ ๐—ฎ ๐—ป๐—ฒ๐—ฐ๐—ฒ๐˜€๐˜€๐—ถ๐˜๐˜†.

Iโ€™m documenting the entire build here. Up next: The Swift + MLX architecture that powers this protection with 0ms latency.

๐—›๐—ถ๐˜ ๐—ณ๐—ผ๐—น๐—น๐—ผ๐˜„ ๐˜๐—ผ ๐˜€๐—ฒ๐—ฒ ๐—ต๐—ผ๐˜„ ๐—ถ๐˜ ๐˜„๐—ผ๐—ฟ๐—ธ๐˜€.

Samsung leak to ChatGPT:
https://lnkd.in/d7ssPRwi

Watch Demo Video here: https://youtu.be/vKVztHT-GuE



Leave a comment