Live data from Hacker News

Employees are feeding sensitive data to ChatGPT, raising security fears

darkreading.com

51–60 of 355 posts

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#51
post #5

We block ChatGPT, as do most federal contractors. I think it’s a horrible exploit waiting to happen: - there’s no way they’re manually scrubbing out sensitive data so its bound to spill out from the training data when prompting the model - OpenAI is openly storing all this data they’re collecting to the extent that they’ve had several leaks now where people can see others’ conversations and data. We are one step away…

Possibly I don't know how this all works, but I think if the host of a ChatGPT interface were willing to provide their own API key (and pay), they could then provide a "service" to others (and collect all input).

In that case, you wouldn't know to block them until it was too late.

Ultimately either you must watch/block all outgoing traffic, or you must train your people so thoroughly that they become suspicious of everything. Sadly, being paranoid is probably the most economical attitude these days if IP and company secrets have any value.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#52
post #42

We went pretty quickly from: No way I’m giving Google any of my data! I will use 5 different browsers in incognito mode and never log in. To -> Sure I will login with my name and email and feed you as much of my most personal thoughts and data as I can dear ChatGPT!

Not quite. These are the same people that use only Chrome while being logged in to their Google account. Convenience wins.

> These are the same people that use only Chrome while being logged in to their Google account

This situation is much dumber than that. ChatGPT is very clear that you shouldn't give it private data and that anything you type into it can/will be used for training.

Google is nowhere near that level of transparency.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#53
post #42

We went pretty quickly from: No way I’m giving Google any of my data! I will use 5 different browsers in incognito mode and never log in. To -> Sure I will login with my name and email and feed you as much of my most personal thoughts and data as I can dear ChatGPT!

Google takes your data and sells it. Literally making your data available to the highest bidder. Is OpenAI doing that? If Google existed in its current form during the early internet it would be classified in the same category as Bonzai Buddy. Spyware. That is what Google is. So I can very reasonably understand why people would trust OpenAI with data they wouldn't trust Google with. OpenAI hasn't spit in the face of its users yet.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#54
post #2

when it first came out and my boss was behind himself about how cool it was, he was feeding it all of his emails with other businesses to have it clean them up. boggled my mind.

do those other businesses use gmail? does your company?

I think those are different models.

Gmail has a vested interested in keeping any knowledge it gains about you secret - it's competitive advantage is knowing more about you than anyone else does.

ChatGPT's strength is its ability to clearly communicate the knowledge it has (including training data it gains from people it interacts with) to give you good responses.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#55
post #11

We published an internal policy for AI tools last week. The basic theme is: "We see the value too, but please don't copypasta our intellectual property until we get a chance to stand up something internal." We've granted some exceptions to the team responsible for determining how to stand up something internal. Lots of shooting in the dark going on here, so I figured we would need some divulgence of our IP against pu…

Inform us when you figured out a way to host something with the quality of ChatGPT internally :-)

Just use the API? It deletes your data after 30 days...

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#56
post #48
post #34

Earlier quoted context omitted.

Uh, there's no sign of that yet.

[flagged]

> Think about how long it's taken tools like pandas to reach the point that it is now. That entire package can be built to the level it is now in a couple of days.

I don't think that is true at all. Do you have an example of a significant project being duplicated in days, or even months, with ANY of these tools?

By significant, I mean something on the order of pandas which you claimed.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#57
This is scary, but it doesn't surprise me even in the slightest. ChatGPT is useful for so many things that it's extremely tempting to convince yourself that you should trust it.

For example, I was having some issues with my LTO-6 drive recently, and I had to finagle through a bunch of arcane server logs to diagnose it. I had the idea of simply copypasting the logs into ChatGPT and having it look at them, and it quickly summarized the logs and told me what things to look for. It didn't directly solve the problem, but it made the logs 100x more digestible and I was able to figure out my problem. It made a problem that probably would have taken 2-3 hours of Googling take about 20 minutes of finagling.

I'm not doing anything terribly interesting or proprietary on my home server, so I didn't really have any reservations sharing dmesg logs with it, but obviously that might not be the case in a company. Server logs can often have a ton of data that could be useful for a competitor (whether it should be there or not), and someone not paying attention to what they're pasting into ChatGPT could easily expose that data.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#58
post #42

We went pretty quickly from: No way I’m giving Google any of my data! I will use 5 different browsers in incognito mode and never log in. To -> Sure I will login with my name and email and feed you as much of my most personal thoughts and data as I can dear ChatGPT!

Google takes your data and sells it. Literally making your data available to the highest bidder. Is OpenAI doing that? If Google existed in its current form during the early internet it would be classified in the same category as Bonzai Buddy. Spyware. That is what Google is. So I can very reasonably understand why people would trust OpenAI with data they wouldn't trust Google with. OpenAI hasn't spit in the face of…

> Google takes your data and sells it. Literally making your data available to the highest bidder.

Even if they are not doing it now(?), what makes you think that they will not do so in the future? It's not like your data has an expiration date.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#60
post #48
post #34

Earlier quoted context omitted.

Uh, there's no sign of that yet.

[flagged]

Cool, please provide a link to a library of similar size and complexity to pandas which was written using ChatGPT in the span of a few days. We'll be waiting.
Post reply on HN