“Got into YC” is being used a bit loosely here. They got invited to startup school, which is a two-day event hosted by YC.
show comments
Aurornis
> Based on Paxel’s own site, 1.2 million+ coders have so far uploaded their reports to YC.
I checked the Paxel website and it says this:
> So far, 1,543,553 sessions have been uploaded and analyzed.
The count is for sessions, not coders. I assume the tool uploads a lot of sessions from each person who uses it.
That’s a large number, but it’s not a million different people. I am surprised that so many people think it’s a good idea to download a run a program which gathers up their coding sessions and submits information about them.
smcnc
I could be mistaken, but isn't Paxel a tool that YC *itself* built to understand how founders/applicants apply AI? If so, this feels less scary than some of the comments (i.e. not 3rd party).
Also, not trying to take shots, but should the title be "I got into YC Startup School by hacking it" instead? Isn't that different than the main YC program?
All in all, you did them a solid by finding and responsibly disclosing. Nice job.
jedberg
For the longest time, the YC application included the question "What was your greatest (non-computer) hack?". They have always liked people who think of ways to work around existing systems. So it's no surprise that their response was positive. Also, all the principals are ex-founders, mostly engineers, who totally understand hacking culture.
Sadly, it looks like they took that question off the application though.
show comments
rationalist
> YC wanted me to use something called Paxel on my computer as part of the application.
> I should run a script, a very easy-to-use cURL one-liner that installed something on my computer and analyzed every line of code I’ve written with a coding agent, compile a report, and upload it to YC’s servers.
Yikes! I hope this is NOT the future of hiring.
show comments
OtherShrezzing
Am I misreading this, or is ycombinator running a tool that transfers IP from an applicant’s machine to OpenAI and then transfers the generated summaries into their own servers. And that tool has some “webapp security 101” level vulnerability in it.
Feels like a disaster waiting to happen.
show comments
siva7
> I uncovered Y Combinator was scoring 100k+ founders around the world through Paxel
Alright, my ears are wide open. Tell us more, how did YC use the private submission data from thousands of founders to score them? They fed some 3rd-Party AI all personal data to score who should get an interview? I can't be the only one here seeing a bad news story unfolding in real time...
show comments
qphe95
This is how you end up with gstack. When you believe too hard in secret metrics because when people know about metrics it stops working you inflict psychosis chasing correlations that don't mean anything.
pudgywalsh
We live in a world now where piping strange unknown executables to bash is "incredible UX". I'm in disbelief.
Keep in mind people who regularly do this were complaining about Windows' machine ID.
speedgoose
Don't read this horror story before bed time if you care about information security.
Perhaps running the script outside a heavily sandboxed system should trigger an automatic rejection.
JCharante
surprised running paxel doesn't disqualify you, the program sounds sus
TZubiri
Oh, I remember that thing, it wanted to see my prompt and my code in exchange for telling me my horoscope.
Some hands you have to fold, and I'm folding this one. Patiently waiting for the "let's give all our data to a single AI user" bubble to bust with some massive exploits.
moomoo11
paxel and how it works sounds so dumb.
so i’m not at all surprised at how it is used and by whom.
“Got into YC” is being used a bit loosely here. They got invited to startup school, which is a two-day event hosted by YC.
> Based on Paxel’s own site, 1.2 million+ coders have so far uploaded their reports to YC.
I checked the Paxel website and it says this:
> So far, 1,543,553 sessions have been uploaded and analyzed.
The count is for sessions, not coders. I assume the tool uploads a lot of sessions from each person who uses it.
That’s a large number, but it’s not a million different people. I am surprised that so many people think it’s a good idea to download a run a program which gathers up their coding sessions and submits information about them.
I could be mistaken, but isn't Paxel a tool that YC *itself* built to understand how founders/applicants apply AI? If so, this feels less scary than some of the comments (i.e. not 3rd party).
Also, not trying to take shots, but should the title be "I got into YC Startup School by hacking it" instead? Isn't that different than the main YC program?
All in all, you did them a solid by finding and responsibly disclosing. Nice job.
For the longest time, the YC application included the question "What was your greatest (non-computer) hack?". They have always liked people who think of ways to work around existing systems. So it's no surprise that their response was positive. Also, all the principals are ex-founders, mostly engineers, who totally understand hacking culture.
Sadly, it looks like they took that question off the application though.
> YC wanted me to use something called Paxel on my computer as part of the application.
> I should run a script, a very easy-to-use cURL one-liner that installed something on my computer and analyzed every line of code I’ve written with a coding agent, compile a report, and upload it to YC’s servers.
Yikes! I hope this is NOT the future of hiring.
Am I misreading this, or is ycombinator running a tool that transfers IP from an applicant’s machine to OpenAI and then transfers the generated summaries into their own servers. And that tool has some “webapp security 101” level vulnerability in it.
Feels like a disaster waiting to happen.
> I uncovered Y Combinator was scoring 100k+ founders around the world through Paxel
Alright, my ears are wide open. Tell us more, how did YC use the private submission data from thousands of founders to score them? They fed some 3rd-Party AI all personal data to score who should get an interview? I can't be the only one here seeing a bad news story unfolding in real time...
This is how you end up with gstack. When you believe too hard in secret metrics because when people know about metrics it stops working you inflict psychosis chasing correlations that don't mean anything.
We live in a world now where piping strange unknown executables to bash is "incredible UX". I'm in disbelief.
Keep in mind people who regularly do this were complaining about Windows' machine ID.
Don't read this horror story before bed time if you care about information security.
Perhaps running the script outside a heavily sandboxed system should trigger an automatic rejection.
surprised running paxel doesn't disqualify you, the program sounds sus
Oh, I remember that thing, it wanted to see my prompt and my code in exchange for telling me my horoscope.
Some hands you have to fold, and I'm folding this one. Patiently waiting for the "let's give all our data to a single AI user" bubble to bust with some massive exploits.
paxel and how it works sounds so dumb.
so i’m not at all surprised at how it is used and by whom.