Live data from Hacker News

Employees are feeding sensitive data to ChatGPT, raising security fears

darkreading.com

251–260 of 355 posts

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#251

I’m curious if anyone’s employer has set up their own LLM. My employer has a couple of A100 sitting around which could easily host a couple instance of 65B LLaMA or Alpaca. Convincing upper management to allow me is the hard part.

what on earth do you need to convince them apart from gestures at all this

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#252
post #201
post #5

We block ChatGPT, as do most federal contractors. I think it’s a horrible exploit waiting to happen: - there’s no way they’re manually scrubbing out sensitive data so its bound to spill out from the training data when prompting the model - OpenAI is openly storing all this data they’re collecting to the extent that they’ve had several leaks now where people can see others’ conversations and data. We are one step away…

> there’s no way they’re manually scrubbing out sensitive data I was under the impression OpenAI weren't using questions as training data for future models. I recall Sam Altman saying they delete questions after 1 month, but I can't locate the source for that.

Even without training the model, it will still end up in logs. For example you can now see your previous questions in the UI and it'll probably be stored in other places of their backend too.

This is still a serious data loss risk.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#253

We saw these same fears with the release of Gmail. Why would you trust your email to Google?!! Aren't they going to train their spam filters on all your data? Aren't they going to sell it, or use it to sell you ads? Corporations constantly put their most sensitive data in 3rd party tools. The executive in the article was probably copying his company strategy from Google docs. Yes, there are good reasons for concern,…

Google wasn't yet evil when most people adopted Gmail.

And corporations have strict agreements with their providers. They are even required to in many cases due to GDPR and the likes. Users connecting to ChatGPT on their own accounts bypass this.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#254
post #11

We published an internal policy for AI tools last week. The basic theme is: "We see the value too, but please don't copypasta our intellectual property until we get a chance to stand up something internal." We've granted some exceptions to the team responsible for determining how to stand up something internal. Lots of shooting in the dark going on here, so I figured we would need some divulgence of our IP against pu…

Our policy for now is the exact same.

The problem is the verification of this of course.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#255

Earlier quoted context omitted.

Not using Chatgpt is easy, but things like GitHub or VSCode with Copilot (which is a special version of GPT3) and in the future Copilot X (gpt4) this will get hard. One developer opening a folder in VSCode with Copilot enabled aaaaand it’s gone. You never know what part of the folder left your building.

What if you host your code in GitHub? That concern is weird to me, because you already give Microsoft pretty much everything. You use Windows, VSCode, etc, all of this has access to your code.

If you use GitHub for sensitive internal stuff you will have a contract with them. This is different from users dumping your data into a service of a vendor you have no business relationship with.

And Windows and VS Code don't upload your data to Microsoft unless you choose to do so.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#256
post #99

Earlier quoted context omitted.

Any examples where those two were the same person? Because both types of people have always existed. Heck, lack of vigilance among the ancient Greeks is what put the Trojan in Trojan horse.

I bet you find some on HN. Sometimes couriosity beats caution.

yes, without thinking I put a lot of data into bing chat and then I realized what I had done :(

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#257

We saw these same fears with the release of Gmail. Why would you trust your email to Google?!! Aren't they going to train their spam filters on all your data? Aren't they going to sell it, or use it to sell you ads? Corporations constantly put their most sensitive data in 3rd party tools. The executive in the article was probably copying his company strategy from Google docs. Yes, there are good reasons for concern,…

> We saw these same fears with the release of Gmail. Why would you trust your email to Google?!!

The original Gmail TOS explicitly stated that they scanned the content. They only stopped for the rollout of Gsuite.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#258
post #5

We block ChatGPT, as do most federal contractors. I think it’s a horrible exploit waiting to happen: - there’s no way they’re manually scrubbing out sensitive data so its bound to spill out from the training data when prompting the model - OpenAI is openly storing all this data they’re collecting to the extent that they’ve had several leaks now where people can see others’ conversations and data. We are one step away…

By using Azure, you can access ChatGPT and GPT, which come with enterprise-grade security and established data agreements, setting them apart from OpenAI. I'm not entirely sure of the technical details, but you can explore this option.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#259

We saw these same fears with the release of Gmail. Why would you trust your email to Google?!! Aren't they going to train their spam filters on all your data? Aren't they going to sell it, or use it to sell you ads? Corporations constantly put their most sensitive data in 3rd party tools. The executive in the article was probably copying his company strategy from Google docs. Yes, there are good reasons for concern,…

> We saw these same fears with the release of Gmail. Why would you trust your email to Google?!! The original Gmail TOS explicitly stated that they scanned the content. They only stopped for the rollout of Gsuite.

IIRC (been a while, so maybe I'm wrong) Google was also the reason Amazon swapped email formats for purchases. They realized they were giving a ton of data to Google through the receipts about products purchased, so now they just give you the vague order emails.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#260

Earlier quoted context omitted.

Do you think Microsoft would dare to have Copilot with any less standards?

Counter: it already vomits all kinds of licensing issues everywhere, which somehow they didn’t really see coming…so yes?

No it doesn’t.
Post reply on HN