This summarizes a security and transparency issue with Google AI Studio: the visible delete control does not remove backend copies, leaving JSON tracking entries and many preserved Drive versions. An independent tech outlet, AI Weekly, flagged the CWE-459 vulnerability and criticized Google's automated Vulnerability Reward Program (VRP) after a researcher was banned in about 60 seconds for reporting deletion-integrity issues. The outlet advised organizations to treat the delete action as a UI-level illusion until Google publicly clarifies retention practices and noted that VRP systems auto-closing reports as "Intended Behavior" signals how such complaints will be triaged going forward.
The researcher provided reproducible forensic evidence - JSON tracking behavior, 106 retained Drive versions, and VRP audit trails - and those specifics were independently verified, countering claims that the findings were AI-generated or routine. The core argument is that Google’s backend retains user data despite a delete affordance and that automated VRP responses can suppress disclosure and remedial action. The practical takeaway for security, compliance, and governance teams is to assume deletion is unreliable for regulated prompts routed through AI Studio and to tighten retention controls and reporting practices until Google clarifies and fixes the behavior.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.