Live data from Hacker News

Employees are feeding sensitive data to ChatGPT, raising security fears

darkreading.com

241–250 of 355 posts

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#241

Earlier quoted context omitted.

What about Google Docs, Office 365, Github, AWS, Azure, Google Cloud, JIRA, Zendesk, etc? What is different about ChatGPT (if anything)?

Dont use any of it

[flagged]

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#242
post #63

Earlier quoted context omitted.

There's a dev here who is using ChatGPT extensively in his work. The rest of the team is just waiting for him to get caught and fired. Sharing company data with unapproved external entities is very definitely a firing offense.

Glad I work for a company where the CEO pays for everyones ChatGPT Plus for the devs. If you think your code is special then you're wrong.

Code isn't special but what you're working on can be and also it's not your decision if you're not the shareholder.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#244

Earlier quoted context omitted.

I'm doing that since day one. I can't believe people are pasting real data into this corporate black boxes.

What about Google Docs, Office 365, Github, AWS, Azure, Google Cloud, JIRA, Zendesk, etc? What is different about ChatGPT (if anything)?

We have data standards and agreements with those companies, we pay them to have expectations. Even then, we're strict about what touches vendor servers and it's audited and monitored. Accounts are managed by us and tied into onboarding and offboarding. If they have a security incident, they notify, there's response and remediation.

ChatGPT seems to be used more like a fast stackoverflow, except people aren't thinking of it like a forum where others will see their question so they aren't as cautious. We're just waiting for some company's data to show up remixed into an answer for someone else and then plastered all over the internet for the infosec lulz of the week.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#245

Earlier quoted context omitted.

I'm doing that since day one. I can't believe people are pasting real data into this corporate black boxes.

I simply don't give a crap if my employer loses data. I don't care if my carelessness costs my employer a billion bucks down the line as I won't be working for them next year.

Writing that is a really good way to end up on the wrong side of a civil suit.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#246

Earlier quoted context omitted.

Not using Chatgpt is easy, but things like GitHub or VSCode with Copilot (which is a special version of GPT3) and in the future Copilot X (gpt4) this will get hard. One developer opening a folder in VSCode with Copilot enabled aaaaand it’s gone. You never know what part of the folder left your building.

What if you host your code in GitHub? That concern is weird to me, because you already give Microsoft pretty much everything. You use Windows, VSCode, etc, all of this has access to your code.

Tech is a big place and not everyone uses GitHub.com - they have an entire self-hosted version for exactly that reason, since many customers have policy or legal requirements – but also consider the distinction between something following its stated policy or doing something else. When you use Windows or VSCode the terms of service do not include sending your personal data to someone else and Microsoft would be in serious legal trouble if they changed that. In contrast, Copilot explicitly does have the right to send some of your code elsewhere so the legal question would come down to whether it reached the point that a judge would no longer consider “snippets of your code” to cover what was sent.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#247
post #5

We block ChatGPT, as do most federal contractors. I think it’s a horrible exploit waiting to happen: - there’s no way they’re manually scrubbing out sensitive data so its bound to spill out from the training data when prompting the model - OpenAI is openly storing all this data they’re collecting to the extent that they’ve had several leaks now where people can see others’ conversations and data. We are one step away…

Some military folks put nuclear weapons storage training materials onto Quizlet, so I don’t doubt for a second people would try to put ChatGPT onto a classified computer system.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#248
post #222

Earlier quoted context omitted.

Replying to myself, it seems your data is still used, unless you fill in a google form to opt out: https://help.openai.com/en/articles/6950777-chatgpt-plus

This Google form requires an organization ID so may not apply to personal GPT+ accounts.

Mine is personal and I just filled out this form with the ID from the docs. Easy, worked fine. Also thanks to the grandparent comment for surfacing this!

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#249
post #71

Earlier quoted context omitted.

It actually is on Azure, exactly as you described. https://learn.microsoft.com/en-us/azure/cognitive-services/o...

Yep, they just need to provide a business specific frontend chat UI.

MS already announced that. They call it Business Chat. https://blogs.microsoft.com/blog/2023/03/16/introducing-micr...

If it works well it will be a big deal.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#250

Earlier quoted context omitted.

Correct, but that level of security is expected from GitHub proper, they have all sorts of independent security reviews for their partners. Does all of that exist for Copilot?

Do you think Microsoft would dare to have Copilot with any less standards?

given widespread stories of how Copilot development was done on a skeleton team (like 6 pple at launch) yes absolutely
Post reply on HN