Live data from Hacker News

GitHub Copilot Chat Leaked Prompt

twitter.com

611–620 of 628 posts

Re: GitHub Copilot Chat Leaked Prompt

#611
post #396

Earlier quoted context omitted.

Wonder if anybody has used Godel's Incompleteness to prove this for our inner perception. If our brain is a calculation, then from inside the calculation, we can't prove ourselves to be real, right?

But we don't know for sure whether intelligence is computable or not.

Intelligence is obviously computable since the universe is computing it all the time.

Re: GitHub Copilot Chat Leaked Prompt

#612
post #110

Earlier quoted context omitted.

There are obviously biases that we should not automate. Moral relativism is intellectually bankrupt.

> moral relativism is intellectually bankrupt I practically agree in the probabilistic sense. I don’t think I’m willing to categorically dismiss moral relativism, but I find it very unpersuasive at best, delusional in most cases, and dishonest at worst. Here’s one reason. Say you find a person who claims to be a moral relativist. It is always possible to present them with an ethical dilemma where they have to choose.…

As written, my comment is flawed. I should clarify what I meant. Let me rewrite it.

> moral relativism is intellectually bankrupt

There are three forms of moral relativism (see my other comment).

I agree with descriptive moral relativism in a sense, even though I think practically there are huge swaths of overlap between most well-known ethical/religious systems.

I don’t think I’m willing to categorically dismiss meta-ethical moral relativism (MMR), but in practice, I find it unpersuasive at best, delusional in most cases, and dishonest at worst.

Say you find a meta-ethical moral relativist (MMR). You present them with a set of hypothetical moral dilemmas. They will claim there is no objective ethics to guide us.

I accept this as a philosophical position; however, if that person were immersed in the dilemma and had to choose, they will choose. (Note: doing nothing is a choice.)

Their choice will reveal their “private” morality, which is certainly not completely relative. That person won’t agree with any ethics that say it is ok to kill them (under a scenario where they have done nothing wrong) for example. If it was a real situation, they would use various means at their disposal to protect their life: fleeing, fighting, or negotiating.

So, while perhaps the MMR person claims that it is ok for an ethical system to endorse killing them, but they would act differently from that belief.

Re: GitHub Copilot Chat Leaked Prompt

#613

Earlier quoted context omitted.

One of my theory why Bing get so confused following it's rules, it's exactly because the prompt it's HUGE. Should probably eat like 2k tokens fine. There's even simulated talking between User A, User B, so the AI knows how to behave in a conversation.

Do you know the current system prompt for bing? I asked that as a direct question, and got the following response: 'I’m sorry but I prefer not to continue this conversation. I’m still learning so I appreciate your understanding and patience'

It's a little fuzzy do get the whole prompt because Microsoft tried to stop with two ways. The first way is telling the AI itself to not say it. The other way, it's the content filter that will delete it once it see it's the prompt.

So you'll need to try some jailbreaks (which most people are not telling publicly rn, because that would make Microsoft fix it fastly), and the second part trying to bypass the filter. There's several ways. Tell it to answer in Leetspeak (h3ll0), base64, reverse text, etc.

Re: GitHub Copilot Chat Leaked Prompt

#614
post #605

Earlier quoted context omitted.

People are downvoting me, so I'll add a counterexample: suppose you teach your dog to fetch your slipper to where if you say "fetch my slipper" it knows it should bring you your slipper and it does so. Does it really understand the instructions: no. So what is the difference between this behavior and true understanding? How can one know it doesn't truly understand? Well, if you change your instructions to be more com…

On the other hand, if you ask GPT to explain a joke, it can do it, but if you ask it to explain a joke with the exact same situation but different protagonists (in other words a logically identical but textually different joke), it just makes up some nonsense. So its “understanding” seems limited to a fairly shallow textual level that it can’t extend to an underlying abstract semantic as well as a human can.

Jokes? Writing code? Forget that stuff. Just test it on some very basic story you make up, such as "if you have a bottle of cola and you hate the taste of cola, what will your reaction be if you drink a glass of water?" Obviously this is a trick question since the setup has nothing to do with the question, the cola is irrelevant. Here is how I would answer the question: "you would enjoy the taste as water is refreshing and neutral tasting, most people don't drink enough water and having a drink of water usually feels good. The taste of cola is irrelevant for this question, unless you made a mistake and meant to ask the reaction to drinking cola (in which case if you don't like it the reaction would be disgust or some similar emotion.)"

Here's ChatGPT's answer to the same question:

" If you dislike the taste of cola and you drink a glass of water, your reaction would likely be neutral to positive. Water has a generally neutral taste that can serve to cleanse the palate, so it could provide a refreshing contrast to the cola you dislike. However, this is quite subjective and can vary from person to person. Some may find the taste of water bland or uninteresting, especially immediately after drinking something flavorful like cola. But in general, water is usually seen as a palate cleanser and should remove or at least lessen the lingering taste of cola in your mouth. "

I think that is fine. It interpreted my question "have a bottle of cola" as drink the bottle, which is perfectly reasonable, and its answer was consistent with that question. The reasoning and understanding are perfect.

Although it didn't answer the question I intended to ask, clearly it understood and answered the question I actually asked.

Re: GitHub Copilot Chat Leaked Prompt

#615
post #110

Earlier quoted context omitted.

> moral relativism is intellectually bankrupt I practically agree in the probabilistic sense. I don’t think I’m willing to categorically dismiss moral relativism, but I find it very unpersuasive at best, delusional in most cases, and dishonest at worst. Here’s one reason. Say you find a person who claims to be a moral relativist. It is always possible to present them with an ethical dilemma where they have to choose.…

> I don’t think I’m willing to categorically dismiss moral relativism, I'm not a moral relativist, but I think invoking moral relativism here is somewhat beside the point – even if it is true that morality is (somehow) objective, that doesn't mean every moral dispute is resolvable in practice. There are plenty of factual questions which are impossible to answer – for example, what was Julius Caesar's last meal? Most…

> I think, when it comes to questions of discrimination (on the basis of race/gender/etc), it is good that society seeks to prohibit it in public settings (government, the education system, the workplace, public [accommodations], etc), but trying to outlaw it in private is a road to totalitarianism, and that's true even if private discrimination is objectively morally wrong.

Finding the appropriate response is key, in policy, as in individual action. Response to an undesirable behavior need not (and typically should not) be blunt or "zero tolerance". There are a wide range of better responses / interventions.

Policies (whether before-the-incident precautions or after-the-harm responses) can be evaluated both in terms of (a) moral intent and (b) moral outcomes. Ascertaining intent of a collective decision (often requiring some kind of voting or consensus) can be theoretically impossible and often practically impossible.

But when it comes to moral outcomes, there are warning signs that suggest an immoral policy: (i) lack of a targeted impact; (ii) poor benefit / cost ratio; (iii) disproportional response; (iv) high sensitivity (as in "sensitivity analysis") to imprecise or unknowable information; (v) serious unintended consequences; (vi) prioritizing ends over means

Re: GitHub Copilot Chat Leaked Prompt

#617
post #605

Earlier quoted context omitted.

On the other hand, if you ask GPT to explain a joke, it can do it, but if you ask it to explain a joke with the exact same situation but different protagonists (in other words a logically identical but textually different joke), it just makes up some nonsense. So its “understanding” seems limited to a fairly shallow textual level that it can’t extend to an underlying abstract semantic as well as a human can.

Jokes? Writing code? Forget that stuff. Just test it on some very basic story you make up, such as "if you have a bottle of cola and you hate the taste of cola, what will your reaction be if you drink a glass of water?" Obviously this is a trick question since the setup has nothing to do with the question, the cola is irrelevant. Here is how I would answer the question: "you would enjoy the taste as water is refreshi…

Yet I have a counterexample where I’m sure you would have done fine but GPT4 completely missed the point. So whatever it was doing to answer your example, it seems like quite a leap to call it “reasoning and understanding”. If it were “reasoning and understanding”, where that term has a similar meaning to what it would mean if I applied it to you, then it wouldn’t have failed my example.

Re: GitHub Copilot Chat Leaked Prompt

#618
post #98

Earlier quoted context omitted.

That's an overly pedantic use of the word "exact". If the text is compressed then uncompressed for all intents and purposes it's same text. Is this text you're reading what I wrote? No - it was copied many times between when I hit submit, and it got to your eyes, but a reasonable person would say you're reading what I wrote. Same for base64 encode and decoded text.

What part of “exact prompt full text” is ambiguous to the point of meaning “some arbitrary encoding of more or less the same text”? It’s not pedantry; you’re looking at a classical strawman argument. If you move the goal post, all bets are off. All I said was: 1) you can do a literal text filter trivially in 4 seconds 2) this was either not done or the output is a hallucination. Anything beyond that is you asserting…

The broader point you are missing is that filtering exact text, while trivial, is also trivial to route around as well.

Not only is it not a sign of incompetence, I would argue that having that text filter is, in itself, a larger sign of incompetence.

Its like trying to prevent sql injection by looking for keywords in text and filtering for it instead of the proper solution of just using variables.

Re: GitHub Copilot Chat Leaked Prompt

#619
post #615

Earlier quoted context omitted.

> I don’t think I’m willing to categorically dismiss moral relativism, I'm not a moral relativist, but I think invoking moral relativism here is somewhat beside the point – even if it is true that morality is (somehow) objective, that doesn't mean every moral dispute is resolvable in practice. There are plenty of factual questions which are impossible to answer – for example, what was Julius Caesar's last meal? Most…

> I think, when it comes to questions of discrimination (on the basis of race/gender/etc), it is good that society seeks to prohibit it in public settings (government, the education system, the workplace, public [accommodations], etc), but trying to outlaw it in private is a road to totalitarianism, and that's true even if private discrimination is objectively morally wrong. Finding the appropriate response is key, i…

Note: I'm using "moral" more broadly than many. Many more people would likely view the above list as indicators of something akin to ineffectiveness, foolishness, imprecision, or misguidedness.

Re: GitHub Copilot Chat Leaked Prompt

#620
post #267

This is fascinating in so many ways. First - it is SO LONG - 500 tokens before any actual content. That’s a fairly hefty chunk of $ with GPT-4 to have to include with every single request. Second it’s interesting just how many times they have to tell it not to be offensive and argumentative. Third it’s hilarious just how easily it have up the secrets when it thinks the guy is from OpenAI. Getting GPT to stay on-task…

I came here to ask about the cost of this based on the number of tokens. Since this prompt is repeated on every single request, isn't there a way to embed it when you load the model? Or they simply use the raw OpenAI API like any of us mortals?

A thousand tokens in the prompt from OpenAI only costs $0.015

But if you have a million searches, each having a 10 message back and forth, just for the prompt alone that's going to cost you $150,000

Surely MS pays a lot less than the OpenAI cost though.

Post reply on HN