Live data from Hacker News

Employees are feeding sensitive data to ChatGPT, raising security fears

darkreading.com

281–290 of 355 posts

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#281

Earlier quoted context omitted.

I simply don't give a crap if my employer loses data. I don't care if my carelessness costs my employer a billion bucks down the line as I won't be working for them next year.

Writing that is a really good way to end up on the wrong side of a civil suit.

I have a addon, were every other sentence is generated by Chat GPT. Good luck holding me liable for a robots actions.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#282

Earlier quoted context omitted.

It is a bit crazy to me someone posts a regex like that without verifying and saying on surface level it looks good, implying the whole thing was useful and a good result.

I said it looks ok, not good. My comment is mostly about me being surprised a valid regex came out. I also asked it to write a regex to parse html which it happily answered. What does gpt4 say about parsing html ;)

But it is either going to be useful or harmful. Harmful if doing the regex validation itself is worse than not doing any validation at all or a very simple validation just checking that there is @ included somewhere.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#283

We saw these same fears with the release of Gmail. Why would you trust your email to Google?!! Aren't they going to train their spam filters on all your data? Aren't they going to sell it, or use it to sell you ads? Corporations constantly put their most sensitive data in 3rd party tools. The executive in the article was probably copying his company strategy from Google docs. Yes, there are good reasons for concern,…

Company I work for uses GMail - but we have business relation with them as we pay for Business licenses that have business data handling in the agreement.

If employee sets random GMail account that is not covered by agreement that is personal account. Sending company data to personal email account might be grounds for firing person.

Setting up some account at random with OpenAI and putting company details like customer names or else there is data breach.

Companies will let people use the tools - but it is not like one can start setting up random accounts without approval from management. Of course there are different types of companies with less or more red-tape.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#284
post #5

We block ChatGPT, as do most federal contractors. I think it’s a horrible exploit waiting to happen: - there’s no way they’re manually scrubbing out sensitive data so its bound to spill out from the training data when prompting the model - OpenAI is openly storing all this data they’re collecting to the extent that they’ve had several leaks now where people can see others’ conversations and data. We are one step away…

I am curious, do you block MS Edge? It has a grammar check for all input boxes that sends data to MS servers to check. Similar to what Grammarly does. MS also "helpfully" asks you if you want to use that enhanced grammar check in MS Word(as far as I have seen, might be there in other office products too). I cannot imagine sending all my documents to MS. But I am not sure most users will realize what is happening. All…

We don't but the grammar check is disabled. In general anything cloud-based services are vetted before being allowed.

I think MS Edge is getting even worse about this, with the big fucking Bing icon in the corner and making it impossibly hard to get rid of it.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#285
post #153

Earlier quoted context omitted.

Do you really think the people asking ChatGPT to write their code can make that abstraction? The fact that the can't do this is the whole reason they have to use ChatGPT.

I use it because it's 10-100x more interesting, fun, and fast as a way to program, instead of me having to personally hand-craft hundreds of lines of boilerplate API interaction code every time I want to get something done. Besides, it's not like it puts out great code (or even always working code), so I still have to read everything and debug it. And sometimes it writes code that is just fine and fit for purpose and…

Pair-programming with ChatGPT is like having an idiot-savant friend who always surprises you. Doesn’t matter if the code is horrible, amazing, or something inbetween. It’s always interesting.

And I agree it’s fun. Maybe it’s the simulated social interaction without consequences. I can be completely honest with my robot friend about the shitty or awesome code and no one’s feelings are going to get hurt. ChatGPT will just keep trying to be helpful.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#286

Earlier quoted context omitted.

If your competitor use ChatGPT to compete with you and they're 10x productive than yours, are you still willing to insist? If the productive is 100x, will you?

Man the fanboyism is out of control here.

Welcome to Sam Altman News. You must be new here.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#287

This is the issue with a tool so powerful, you can't just tell people not to use it, or to use it responsibly. Because there's too much incentive for them to use it. If it saves hours of a persons' workday, and they're not seeing any of the harm caused from data leakage, there's no incentive for them to not use it. Which is why a private option is so critical. To not fight against human nature, means providing an abi…

> you can't just tell people not to use it Uh, why can't you tell people not to use it...? If security is that important for your company, of course you can tell your employees which tools to use. A fun fact: in many areas of TSMC, smart phones are banned. No one says "you can't just tell people not to use smart phones."

> in many areas of TSMC, smart phones are banned

This does not surprise me at all. What I want to know is how they enforce it.

Unless they have something better than "fear of somebody seeing you using the smartphone", it isn't getting enforced. If they do have something better I want to know what.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#289

Earlier quoted context omitted.

What about Google Docs, Office 365, Github, AWS, Azure, Google Cloud, JIRA, Zendesk, etc? What is different about ChatGPT (if anything)?

We have data standards and agreements with those companies, we pay them to have expectations. Even then, we're strict about what touches vendor servers and it's audited and monitored. Accounts are managed by us and tied into onboarding and offboarding. If they have a security incident, they notify, there's response and remediation. ChatGPT seems to be used more like a fast stackoverflow, except people aren't thinking…

> We have data standards and agreements with those companies, we pay them to have expectations. Even then, we're strict about what touches vendor servers and it's audited and monitored. Accounts are managed by us and tied into onboarding and offboarding.

For every company like yours there are hundreds that don't. People use free gmail address for sensitive company stuff, paste random things in random pastebins, put their private keys in public repos, etc.

Yes, data leaks from OpenAI are bound to happen (again), and they should beef up their security practices.

But thinking people are using only ChatGPT in an insecure way vastly overestimates their security practices elsewhere.

The solution is education, not avoiding new tools.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#290
post #5

We block ChatGPT, as do most federal contractors. I think it’s a horrible exploit waiting to happen: - there’s no way they’re manually scrubbing out sensitive data so its bound to spill out from the training data when prompting the model - OpenAI is openly storing all this data they’re collecting to the extent that they’ve had several leaks now where people can see others’ conversations and data. We are one step away…

> Wouldn’t even put it past military personnel putting S/TS information into it at this point. Hey, they need someone to proofread their War Thunder forum posts to make sure they're using correct spelling and grammar when leaking classified info. ;-) (Ref if you don't get the joke: https://taskandpurpose.com/news/war-thunder-forum-military-t... )

Not only that, but the European theater nuclear forces leaking security arragements and even door PIN-codes for nuclear weapons bunkers via online flash card sites might be a better example.

As the leaks ware more inadvertent.

Post reply on HN