Live data from Hacker News

Employees are feeding sensitive data to ChatGPT, raising security fears

darkreading.com

321–330 of 355 posts

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#321

Earlier quoted context omitted.

Search engines (and url bars) are indeed not blocked, but I do worry every time I use them. Internal url leaks to google must be extremely common.

I imagine they must be. I'm habitually careful to either click on a link, paste the entirety of the internal URL at once, or enter only the most generic word or words that will surface the URL I want as a history suggestion - all to minimize the chances of leaking anything this way.

You can turn the auto search off

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#322
post #5

We block ChatGPT, as do most federal contractors. I think it’s a horrible exploit waiting to happen: - there’s no way they’re manually scrubbing out sensitive data so its bound to spill out from the training data when prompting the model - OpenAI is openly storing all this data they’re collecting to the extent that they’ve had several leaks now where people can see others’ conversations and data. We are one step away…

[dead]

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#323

Earlier quoted context omitted.

I'm doing that since day one. I can't believe people are pasting real data into this corporate black boxes.

What about Google Docs, Office 365, Github, AWS, Azure, Google Cloud, JIRA, Zendesk, etc? What is different about ChatGPT (if anything)?

To quote a children's TV show: "Which ones of these things are not like the other ones?"

Some of those are document tools working on language / knowledge. Others are infrastructure, working on ... whatever your infra does, and your infra manages your data (knowledge).

If you read their data policies, you'll find they are not the same.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#324
post #91

Earlier quoted context omitted.

But you created a throwaway account specifically to reply in this thread? Unless your company really has nothing to hide, it's easy to accidentally dump a company secret or an API key in a chat session. Of course if everyone is aware of this and constantly careful then you may be OK.

That's because accounts get shadow banned all the time when people get upset when you point out hard truths. If you're copy pasting API keys or such into ANYTHING, you probably shouldn't be a programmer to begin with. It's like people who use root account key/secret credentials in their codebase. It's not AWSs fault you got a large bill or got hacked, its because you're dumb.

Nice so avoiding getting shadowbanned on hackernews is fine but avoiding getting sued is petty ?

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#325
post #96

Earlier quoted context omitted.

Why? Uploading code to ChatGPT can be done by trainees.

Yeah, but the code coming out of ChatGPT is generally not in a state that you want to commit straight into you repo. Making adjustments (and writing the original prompt) is where your expertise comes in.

You can just submit the trash code and let a senior fix it for you in code review.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#326

No one cares about security because there is no consequence for getting it wrong. Look at all the major breaches ever. And look specifically at the stock price of those companies. They took small short term hits at best. Worst case the CISO gets fired and then they all play musical chairs and end up in new roles. Heck, even Lastpass, ostensibly a security company , doesn't seem particularly affected by their breach.…

I don't even agree to begin with the idea that a tool that vastly increases your productivity is a security risk in the grand scheme of things, since you know, you can just allocate the time you were spending before on writing boilerplate towards securing systems. Endpoint security software is a security risk too.

Yikes! Aside from the fact that nobody will take the "spare" time saved and spend it on internal security, once you have a lot of your sensitive data outside in a third party system you have lost control.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#327

Earlier quoted context omitted.

> in many areas of TSMC, smart phones are banned This does not surprise me at all . What I want to know is how they enforce it. Unless they have something better than "fear of somebody seeing you using the smartphone", it isn't getting enforced. If they do have something better I want to know what.

At Samsung, you typically walk through multiple sets of metal detectors and security before you can actually get into the fab. Anyone working in an office area can have a phone but they do some... stuff to it.

> Anyone working in an office area can have a phone but they do some... stuff to it.

This is what I'm interested in.

I get it, the guys in bunny suits will probably tolerate being groped and wanded every workday for the rest of their career. I have a hard time beliving the scientific staff and executives tolerate that.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#328
post #63

Earlier quoted context omitted.

There's a dev here who is using ChatGPT extensively in his work. The rest of the team is just waiting for him to get caught and fired. Sharing company data with unapproved external entities is very definitely a firing offense.

If you really care about your company's security, you should report it, otherwise you are just complicit.

Why not talk to the employee first?

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#329

Earlier quoted context omitted.

If your competitor use ChatGPT to compete with you and they're 10x productive than yours, are you still willing to insist? If the productive is 100x, will you?

It might be just as likely that ChapGPT will cause a mistake like Knight Capital because no one bothered to thoroughly verify the AI's looks-good-but-deeply-flawed answer, and the two aren't mutually exclusive possibilities.

The Knight meltdown was more of a disfunction of change management and trading system operations than it was of using a decommissioned feature flag.

Source: worked there after the meltdown.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#330
post #93

Earlier quoted context omitted.

You are still transferring your business data to an external entity, but on top of it you pay for it. And if you think that there is no special code then you're wrong.

If you think random snippets of code are special you really don't understand the business you're writing code for. So no, your code is not special, and pasting code snippets is not transferring business data.

What do you know about the code written by the people you are replying to?

Lots of code expresses buisness strategy that is a competitive advantage/ sensitive.

My org has done a risk assessment and accepted the risk of using such tools; arguing there is no risk is short sighted.

Post reply on HN