Live data from Hacker News

Employees are feeding sensitive data to ChatGPT, raising security fears

darkreading.com

311–320 of 355 posts

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#311
post #305

Earlier quoted context omitted.

> We block ChatGPT, as do most federal contractors. I think it’s a horrible exploit waiting to happen: Do you also block pastebin? Anything else that has a web form? How is ChatGPT special compared to any other service on the Internet where people can paste data in a form? I mean... I see the problem, but I think one needs to realize that it's a far more generic problem that has basically nothing to do with ChatGPT a…

> Do you also block pastebin? Anything else that has a web form? pastebin and indeed most things that has some sort of public webform is blocked in all the companies I have worked with. It is probably a losing battle though, as it is very hard to block everything without default deny. Paradoxically, maybe GPT could be used to veto websites on first access :)

> pastebin and indeed most things that has some sort of public webform is blocked in all the companies I have worked with.

Search engines too? And these days, that means web browsers, because the (IMHO stupid) idea of combining address and search bars into one means everything you type while trying to open a website gets leaked to some party (most likely Google).

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#312

Earlier quoted context omitted.

> Do you also block pastebin? Anything else that has a web form? pastebin and indeed most things that has some sort of public webform is blocked in all the companies I have worked with. It is probably a losing battle though, as it is very hard to block everything without default deny. Paradoxically, maybe GPT could be used to veto websites on first access :)

> pastebin and indeed most things that has some sort of public webform is blocked in all the companies I have worked with. Search engines too? And these days, that means web browsers, because the (IMHO stupid) idea of combining address and search bars into one means everything you type while trying to open a website gets leaked to some party (most likely Google).

Search engines (and url bars) are indeed not blocked, but I do worry every time I use them. Internal url leaks to google must be extremely common.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#313

Earlier quoted context omitted.

What about Google Docs, Office 365, Github, AWS, Azure, Google Cloud, JIRA, Zendesk, etc? What is different about ChatGPT (if anything)?

Doesn't OpenAI explicitly say that your Q/A on the free ChatGPT are stored and sent to human reviewers to be put in their RL database? Now of course we can't be sure what google, AWS etc do with the data on disks there, but it would be a pretty big scandal if some whistleblower eventually comes out and say that google employees sit and laugh at private bucket contents on GCP or private Google Docs. So there's a diffe…

Who in their right mind is using free ChatGPT through that shitty no good web interface of theirs, that can barely handle two queries-and-replies before grinding down to a halt? Surely everyone is using the pay-as-you-go API keys and any one of the alternative ffrontends or integrations?

And, IIRC, pay-as-you-go API requests are explicitly not used for training data. I'm sad GPT-4 isn't there yet - except for those who won the waitlist lottery.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#314

Earlier quoted context omitted.

Writing that is a really good way to end up on the wrong side of a civil suit.

I have a addon, were every other sentence is generated by Chat GPT. Good luck holding me liable for a robots actions.

"I do not take any kind of responsibility about what I'm doing, or not doing, or thinking about doing or not doing, or thinking about whenever I should be doing or not doing, or thinking about whenever I should be thinking about doing or not doing".

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#315
post #5

We block ChatGPT, as do most federal contractors. I think it’s a horrible exploit waiting to happen: - there’s no way they’re manually scrubbing out sensitive data so its bound to spill out from the training data when prompting the model - OpenAI is openly storing all this data they’re collecting to the extent that they’ve had several leaks now where people can see others’ conversations and data. We are one step away…

> they’ve had several leaks now where people can see others’ conversations and data Do you have a source for this? I know some people have claimed to see others' data, but I haven't seen any evidence that that's what's actually being seen, vs LLM hallucinations. OpenAI claims, and I can't imagine they're lying, that the training data is fixed and ends in 2021, so I don't see how it would be possible for user prompts…

I think they’re referencing this: https://openai.com/blog/march-20-chatgpt-outage

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#316

Earlier quoted context omitted.

> pastebin and indeed most things that has some sort of public webform is blocked in all the companies I have worked with. Search engines too? And these days, that means web browsers, because the (IMHO stupid) idea of combining address and search bars into one means everything you type while trying to open a website gets leaked to some party (most likely Google).

Search engines (and url bars) are indeed not blocked, but I do worry every time I use them. Internal url leaks to google must be extremely common.

I imagine they must be. I'm habitually careful to either click on a link, paste the entirety of the internal URL at once, or enter only the most generic word or words that will surface the URL I want as a history suggestion - all to minimize the chances of leaking anything this way.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#317

Earlier quoted context omitted.

Writing that is a really good way to end up on the wrong side of a civil suit.

I have a addon, were every other sentence is generated by Chat GPT. Good luck holding me liable for a robots actions.

Unless you can prove a given sentence was generated by ChatGPT, it will be assumed it wasn't.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#318
post #269

Earlier quoted context omitted.

As the saying goes, if the product is free, then you are the product.

The product is $20!

The product is pay-as-you-go, just sign up for the API keys and use the playground, or an alternative client, instead of their ChatGPT webapp.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#319
post #306
post #305

Earlier quoted context omitted.

> We block ChatGPT, as do most federal contractors. I think it’s a horrible exploit waiting to happen: Do you also block pastebin? Anything else that has a web form? How is ChatGPT special compared to any other service on the Internet where people can paste data in a form? I mean... I see the problem, but I think one needs to realize that it's a far more generic problem that has basically nothing to do with ChatGPT a…

Because "awareness only " has such a great track record when it comes to security-adjacent issues, and totally satisfies auditors/customers/regulators/...?

I don't think awareness only has any reasonable track record and I would always prefer a technical control if there is one. But I have a hard time seeing any alternative here.

I don't think the idea that you can give people access to the www and at the same time preventing them from putting things in forms can be done. That's simply not how it works. And if you're blocking access to a few services where they might do that, well, they have a million others, and you're deceiving yourself that you've done something.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#320

Earlier quoted context omitted.

Doesn't OpenAI explicitly say that your Q/A on the free ChatGPT are stored and sent to human reviewers to be put in their RL database? Now of course we can't be sure what google, AWS etc do with the data on disks there, but it would be a pretty big scandal if some whistleblower eventually comes out and say that google employees sit and laugh at private bucket contents on GCP or private Google Docs. So there's a diffe…

Who in their right mind is using free ChatGPT through that shitty no good web interface of theirs, that can barely handle two queries-and-replies before grinding down to a halt? Surely everyone is using the pay-as-you-go API keys and any one of the alternative ffrontends or integrations? And, IIRC, pay-as-you-go API requests are explicitly not used for training data. I'm sad GPT-4 isn't there yet - except for those w…

It's really funny to see these types of comments. I would assume a vast majority of users are using the Web interface, particularly in a corporate context where an account for the API could take ages or not be accepted.

If people were smart and performed according to best practices, articles like this one would not be necessary.

Post reply on HN