Employees are feeding sensitive data to ChatGPT, raising security fears
121–130 of 355 posts
Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#122Earlier quoted context omitted.
But you created a throwaway account specifically to reply in this thread? Unless your company really has nothing to hide, it's easy to accidentally dump a company secret or an API key in a chat session. Of course if everyone is aware of this and constantly careful then you may be OK.
That's because accounts get shadow banned all the time when people get upset when you point out hard truths. If you're copy pasting API keys or such into ANYTHING, you probably shouldn't be a programmer to begin with. It's like people who use root account key/secret credentials in their codebase. It's not AWSs fault you got a large bill or got hacked, its because you're dumb.
Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#123We saw these same fears with the release of Gmail. Why would you trust your email to Google?!! Aren't they going to train their spam filters on all your data? Aren't they going to sell it, or use it to sell you ads? Corporations constantly put their most sensitive data in 3rd party tools. The executive in the article was probably copying his company strategy from Google docs. Yes, there are good reasons for concern,…
I think this is different in that ChatGPT is expressly using your data as training in a probabilistic model. This means: * Their contractors can (and do!) see your chat data to tune the model * If the model is trained on your confidential data, it may start returning this data to other users (as we've seen with Github Copilot regurgitating licensed software) * The site even _tells you_ not to put confidential data in…
Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#124Meanwhile over at Github Copilot... Hahahahahahaha
If you're using Github already then Copilot isn't seeing anything new.
Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#125Earlier quoted context omitted.
Right. I've had ChatGPT completely fail at something as simple as writing a batch file to find and replace text in a text file.
Sure, but humans do that all the time as well
Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#126We saw these same fears with the release of Gmail. Why would you trust your email to Google?!! Aren't they going to train their spam filters on all your data? Aren't they going to sell it, or use it to sell you ads? Corporations constantly put their most sensitive data in 3rd party tools. The executive in the article was probably copying his company strategy from Google docs. Yes, there are good reasons for concern,…
Or the fears are real and companies that operate without them will be exploited, or extinguished for annoying their customers.
Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#127Given that they use all the labor of the Internet without attribution, we should assume that they will use every additional drop of data we give to them for their own ends.
Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#128Earlier quoted context omitted.
There's a dev here who is using ChatGPT extensively in his work. The rest of the team is just waiting for him to get caught and fired. Sharing company data with unapproved external entities is very definitely a firing offense.
Glad I work for a company where the CEO pays for everyones ChatGPT Plus for the devs. If you think your code is special then you're wrong.
Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#129We saw these same fears with the release of Gmail. Why would you trust your email to Google?!! Aren't they going to train their spam filters on all your data? Aren't they going to sell it, or use it to sell you ads? Corporations constantly put their most sensitive data in 3rd party tools. The executive in the article was probably copying his company strategy from Google docs. Yes, there are good reasons for concern,…
Trusting Gmail with corporate communication was was a terrible idea (and explicitly illegal in a lot of industries), and companies didn't start to adopt it until Google released an enterprise version with table-stakes security features like no training on the data, no ad targeting, auditing, compliance holds and more. There's a huge difference between trusting a third party service with strict security and data priva…
Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#130This is the issue with a tool so powerful, you can't just tell people not to use it, or to use it responsibly. Because there's too much incentive for them to use it. If it saves hours of a persons' workday, and they're not seeing any of the harm caused from data leakage, there's no incentive for them to not use it. Which is why a private option is so critical. To not fight against human nature, means providing an abi…
Uh, why can't you tell people not to use it...? If security is that important for your company, of course you can tell your employees which tools to use.
A fun fact: in many areas of TSMC, smart phones are banned. No one says "you can't just tell people not to use smart phones."