Fetching from the wire…
Public story · 2026-09-20 · high
A researcher says the Delete button fakes a 404 while the prompt stays on Google's servers, and the bug bounty ruled it working as designed.
Why now: The report and Google's VRP reply both date to September 19.
Google AI Studio's Delete action doesn't delete anything, according to a researcher's evidence posted September 19. Anyone who typed something in and hit delete, assuming it was gone, was wrong if the claim holds up.
Per the writeup on Hacker News, clicking Delete returns a 404 as if the prompt is gone, but the data stays on Google's backend. Google's AI Vulnerability Reward Program reviewed the report and marked it "Intended Behavior" in about a minute.
That matters for anyone who pasted an API key into a test prompt or dropped in client data for a quick summary, then trusted the UI's word that it was erased.
I want the network traces before I believe the strong version of this. One researcher, no confirmation from Google past the VRP's boilerplate close. "Intended Behavior" is a label Google applies to plenty of reports that turn out to be exactly what they sound like: expected, not exploitable. A screenshot of a 404 doesn't prove the backend still has the row.
The weak version needs no confirmation. Google hasn't published what AI Studio does with deleted prompts. Until it does, the safe assumption is that Delete changes what you see, not what Google keeps. Treat it as a UI state change, not a retention guarantee.
Watch for two things next. Whether Google issues an actual retention statement instead of a VRP disposition label, and whether a second researcher replicates the network capture independently. One report plus a fast bounty close is a claim. Two independent captures is a pattern Google would have to answer.
Each link below shares sources, entities, or timing with this story.
689 points and 527 comments, the largest thread of the cycle, ending the MV2 wind-down by delisting rather than deprecating (Hacker News). The thread splits on safety versus revenue protection, with the strongest practitioner argument being that ad blocking is now itself a sec...
Google shipped a full-stack vibe coding experience in AI Studio powered by the Antigravity coding agent with Firebase backend integration. The agent auto-detects when prompts need data storage or auth and provisions Firestore, Firebase Authentication, and connects the codebase...
The published retirement date for gemini-2.5-pro and gemini-2.5-flash is October 16, 2026, pushed back from an original June date, with Gemini 3.1 Pro and 3.6 Flash as the recorded upgrade paths at higher list prices. The specific loss named in the thread is 2.5 Pro's document...
John Gruber's Daring Fireball post drew 368 points and 348 comments, with most technical commenters rejecting his prose-quality argument: the watermark only biases high-entropy tokens where several continuations are near-equiprobable, and Google's A/B tests reportedly showed n...
An automated system broke the platform that hosts automated systems. The irony writes itself. Railway published its incident report: at 22:20 UTC on May 19, Google Cloud's automated systems incorrectly suspended Railway's production account. Not a single service. The entire ac...
The SDKs you pip install and npm install every day just changed ownership. Anthropic announced the acquisition of Stainless, the SDK generation company founded by former Stripe engineer Alex Rattray, for over $300 million. That's more than double Stainless's December 2025 valu...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.