Live data from Hacker News

Employees are feeding sensitive data to ChatGPT, raising security fears

darkreading.com

91–100 of 355 posts

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#91
post #63

Earlier quoted context omitted.

There's a dev here who is using ChatGPT extensively in his work. The rest of the team is just waiting for him to get caught and fired. Sharing company data with unapproved external entities is very definitely a firing offense.

Glad I work for a company where the CEO pays for everyones ChatGPT Plus for the devs. If you think your code is special then you're wrong.

But you created a throwaway account specifically to reply in this thread?

Unless your company really has nothing to hide, it's easy to accidentally dump a company secret or an API key in a chat session. Of course if everyone is aware of this and constantly careful then you may be OK.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#92

Earlier quoted context omitted.

Inform us when you figured out a way to host something with the quality of ChatGPT internally :-)

I can host llama's 7b model internally. It hallucinates more often than not and has a tendency to ramble, but dammit it's local and secure!

What's it like with code, documentation, regex, etc?

That's all I use ChatGPT for. I don't need it to be able to write poetry.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#93
post #63

Earlier quoted context omitted.

There's a dev here who is using ChatGPT extensively in his work. The rest of the team is just waiting for him to get caught and fired. Sharing company data with unapproved external entities is very definitely a firing offense.

Glad I work for a company where the CEO pays for everyones ChatGPT Plus for the devs. If you think your code is special then you're wrong.

You are still transferring your business data to an external entity, but on top of it you pay for it.

And if you think that there is no special code then you're wrong.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#94
post #38

In my experience most corporate employees just take the path of least resistance. It is not uncommon for people to paste non public data into websites just to do json formatting, and paste base64 strings to random websites just to decode them. So just telling people not to do something won't accomplish much. Most corporate employees also somehow think they know better than the policy. Any company that doesn't want to…

> and any website serving as a wrapper over it I agree this would be a good move, but it's going to be harder and harder to do that definitively.

Perhaps we need an “LLM Block” browser extension? :)

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#95
post #42

We went pretty quickly from: No way I’m giving Google any of my data! I will use 5 different browsers in incognito mode and never log in. To -> Sure I will login with my name and email and feed you as much of my most personal thoughts and data as I can dear ChatGPT!

My problem with Google is they'll ban me from gmail for something I do on youtube.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#96
post #63

Earlier quoted context omitted.

There's a dev here who is using ChatGPT extensively in his work. The rest of the team is just waiting for him to get caught and fired. Sharing company data with unapproved external entities is very definitely a firing offense.

If they're more productive by doing it, I think it's an equal chance said dev gets promoted.

Why?

Uploading code to ChatGPT can be done by trainees.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#98

Earlier quoted context omitted.

Possibly I don't know how this all works, but I think if the host of a ChatGPT interface were willing to provide their own API key (and pay), they could then provide a "service" to others (and collect all input). In that case, you wouldn't know to block them until it was too late. Ultimately either you must watch/block all outgoing traffic, or you must train your people so thoroughly that they become suspicious of ev…

> Possibly I don’t know how this all works, but I think if the host of a ChatGPT interface were willing to provide their own API key (and pay), they could then provide a “service” to others (and collect all input). Well, GP was referring to blocking ChatGPT as a federal contractor . I suspect that as a federal contractor, they are also vetting other people that they share data with, not just blocking ChatGPT as a one…

But it really seems like a cat and mouse game. For example, a very determined bad actor could infiltrate some lesser approved government contractor and provide an additional interface/API which would invite such information leaking, and possibly nobody would notice for a long time.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#99
post #42

We went pretty quickly from: No way I’m giving Google any of my data! I will use 5 different browsers in incognito mode and never log in. To -> Sure I will login with my name and email and feed you as much of my most personal thoughts and data as I can dear ChatGPT!

Any examples where those two were the same person? Because both types of people have always existed. Heck, lack of vigilance among the ancient Greeks is what put the Trojan in Trojan horse.

I bet you find some on HN.

Sometimes couriosity beats caution.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#100
post #63

Earlier quoted context omitted.

There's a dev here who is using ChatGPT extensively in his work. The rest of the team is just waiting for him to get caught and fired. Sharing company data with unapproved external entities is very definitely a firing offense.

If they're more productive by doing it, I think it's an equal chance said dev gets promoted.

He's not more productive, but even if he were, it wouldn't affect his getting fired.

Productivity isn't everything.

Post reply on HN