Live data from Hacker News

Employees are feeding sensitive data to ChatGPT, raising security fears

darkreading.com

101–110 of 355 posts

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#101

This is the issue with a tool so powerful, you can't just tell people not to use it, or to use it responsibly. Because there's too much incentive for them to use it. If it saves hours of a persons' workday, and they're not seeing any of the harm caused from data leakage, there's no incentive for them to not use it. Which is why a private option is so critical. To not fight against human nature, means providing an abi…

1.) It's not at all clear it's nearly as powerful as you think. Certainly in my domain--writing about various topics--it's not.

2.) Of course, you can tell people not to use it. Unlike people at SV companies apparently, people in government and government contractors accept restrictions like not having phones in secure labs all the time. Start firing or even prosecuting people and people will discover very quickly they don't really need some tool.

And, yes, private versions of this sort of thing helps a lot.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#102
post #63

This is the issue with a tool so powerful, you can't just tell people not to use it, or to use it responsibly. Because there's too much incentive for them to use it. If it saves hours of a persons' workday, and they're not seeing any of the harm caused from data leakage, there's no incentive for them to not use it. Which is why a private option is so critical. To not fight against human nature, means providing an abi…

There's a dev here who is using ChatGPT extensively in his work. The rest of the team is just waiting for him to get caught and fired. Sharing company data with unapproved external entities is very definitely a firing offense.

If you really care about your company's security, you should report it, otherwise you are just complicit.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#103
post #91

Earlier quoted context omitted.

Glad I work for a company where the CEO pays for everyones ChatGPT Plus for the devs. If you think your code is special then you're wrong.

But you created a throwaway account specifically to reply in this thread? Unless your company really has nothing to hide, it's easy to accidentally dump a company secret or an API key in a chat session. Of course if everyone is aware of this and constantly careful then you may be OK.

That's because accounts get shadow banned all the time when people get upset when you point out hard truths.

If you're copy pasting API keys or such into ANYTHING, you probably shouldn't be a programmer to begin with.

It's like people who use root account key/secret credentials in their codebase. It's not AWSs fault you got a large bill or got hacked, its because you're dumb.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#104
post #5

We block ChatGPT, as do most federal contractors. I think it’s a horrible exploit waiting to happen: - there’s no way they’re manually scrubbing out sensitive data so its bound to spill out from the training data when prompting the model - OpenAI is openly storing all this data they’re collecting to the extent that they’ve had several leaks now where people can see others’ conversations and data. We are one step away…

This really depends on the cost/benefit tradeoff for the entity in question. If using ChatGPT makes you X% more productive (shipping faster / lowers labor costs / etc), but comes with Y% risk of data leakage, is that worth it in expectation or not? I would argue that there definitely exist companies for which it's worth the tradeoff.

By the way, OpenAI says they wont use data submitted through its API for model training - https://techcrunch.com/2023/03/01/addressing-criticism-opena...

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#105
post #63

Earlier quoted context omitted.

There's a dev here who is using ChatGPT extensively in his work. The rest of the team is just waiting for him to get caught and fired. Sharing company data with unapproved external entities is very definitely a firing offense.

If you really care about your company's security, you should report it, otherwise you are just complicit.

I agree.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#107
post #97

OpenAI. The heist of the century. I am waiting for A.I. generated blockbuster in the near future.

I was just watching Altman's interview from the Lex Friedman podcast a few days ago

It really does feel like YC was a plot to fund the harvesting of all with an OpenAI climax. Not a serious conclusion I have, its just funny to watch it unfold, as if nobody even cares about the optics.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#109

Earlier quoted context omitted.

If your competitor use ChatGPT to compete with you and they're 10x productive than yours, are you still willing to insist? If the productive is 100x, will you?

This isn't an argument of ChatGPT vs nothing. This is an argument of "external" ChatGPT vs some other AI sitting on your own secured hardware, maybe even a branch of ChatGPT.

> some other AI sitting on your own secured hardware, maybe even a branch of ChatGPT.

Where can I, a random employee, get that? I know how to get ChatGPT.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#110

This is one of the reasons Databricks created Dolly, a slim LLM that unlocks the magic of ChatGPT. A homegrown LLM that can tap into/query the datasets of all the data in an organizations Data Lakehouse will be hugely powerful. I am working with customers that are looking to train a homegrown LLM that they host and have blocked access to ChatGPT. https://www.datanami.com/2023/03/24/databricks-bucks-the-her... https:/…

This reads like you had an LLM write an ad for you
Post reply on HN