Live data from Hacker News

Google's Gemini AI caught scanning Google Drive PDF files without permission

tomshardware.com

141–150 of 163 posts

Re: Google's Gemini AI caught scanning Google Drive PDF files without permission

#141

Earlier quoted context omitted.

Training I can understand, but why scanning? It's literally just running an algorithm over your data and spitting out the results for you. Fundamentally it's no different from spellcheck, or automatically creating a table of contents from header styles. As long as the results stay private to you (which in this case, they are), I don't see what the concern is. The fact that the algorithm is LLM-based has zero relevanc…

I think that vouaobrasil was talking about scanning on the behalf of others, not scanning that you're doing on your own data. Scanning your own stuff is automatically and naturally an opt-in situation. You've consciously chosen for it to happen.

I don't think so -- that's not what the article is about. The subject here is entirely about a product scanning your own document to summarize it for you.

Re: Google's Gemini AI caught scanning Google Drive PDF files without permission

#142

Earlier quoted context omitted.

He had the permissions turned off, so regardless of what it did with the document, it did it without permission! The title is correct!

>He had the permissions turned off, so regardless of what it did with the document, it did it without permission! The title is correct! Honestly it sounds like he was toggling permissions off and on and actually has no idea why it summarized that particular document despite him requesting it summarize other documents. Google should make the settings more clear, but "I had the options off, except when I didn't, and I…

Agreed on that, but this is Google, do you really think they couldn’t have made this easier if it wasn’t in their best interest not to?

One would think, maybe even expect, a single setting in a single place would control this. And that their docs would be correct.

Re: Google's Gemini AI caught scanning Google Drive PDF files without permission

#143
post #135

Earlier quoted context omitted.

Except that's not what is happening here or what the rest of us are discussing, so why even bring it up?

We don’t know what’s happening beyond: ^the privacy settings used to inform Gemini should be openly available, but they aren't, which means the AI is either "hallucinating (lying)" or some internal systems on Google's servers are outright malfunctioning* Many AI systems do use user interactions as part of training data. So at most you might guess those documents aren’t directly being used for training AND they will n…

>which means the AI is either "hallucinating (lying)" or some internal systems on Google's servers are outright malfunctioning*

I'm not sure how that is implied.

>Many AI systems do use user interactions as part of training data.

There is no evidence of that being the case here, and none of the mainstream AIs do that yet. They'd be much more useful if they did.

>So at most you might guess those documents aren’t directly being used for training

Or we can actually know that, because that's the case.

>AND they will never include conversations in training data but you don’t know.

Conversations aren't part of this discussion at all, so I'm not sure what you're trying to imply, but it's wrong.

Re: Google's Gemini AI caught scanning Google Drive PDF files without permission

#144
post #63
post #52

Earlier quoted context omitted.

This is partly true but less and less every day. IMO the bigger concern is that this data is not just used to train models. It is stored, completely verbatim, in the training set data. They aren’t pulling from PDFs in realtime during training runs, they’re aggregating all of that text and storing it somewhere. And that somewhere is prone to employees viewing, leakage to the internet, etc.

> This is partly true but less and less every day. Isn't this like encryption, though? I'm fairly sure that the cryptography community basically says: if someone has a copy of your encrypted data for a long time, the likelihood over time for them to be able to read it approaches 100%, regardless of the current security standard you're using. Who could possibly guarantee that whatever LLM is safe now will be safe at a…

I think it’s different, unless you believe LLMs have broken theoretical limits on compression. I don’t see how an LLM with 1T 16 bit parameters could encode 100PB of data.

Re: Google's Gemini AI caught scanning Google Drive PDF files without permission

#145
post #135

Earlier quoted context omitted.

We don’t know what’s happening beyond: ^the privacy settings used to inform Gemini should be openly available, but they aren't, which means the AI is either "hallucinating (lying)" or some internal systems on Google's servers are outright malfunctioning* Many AI systems do use user interactions as part of training data. So at most you might guess those documents aren’t directly being used for training AND they will n…

>which means the AI is either "hallucinating (lying)" or some internal systems on Google's servers are outright malfunctioning* I'm not sure how that is implied. >Many AI systems do use user interactions as part of training data. There is no evidence of that being the case here, and none of the mainstream AIs do that yet. They'd be much more useful if they did. >So at most you might guess those documents aren’t direc…

> Conversations aren't part of this discussion at all

People only know about it because information from these documents is showing up in conversations.

It’s unclear which systems have access and why, but at a minimum Google is showing the data. If things are “misconfigured” or even intentionally set up like this then any assumptions about what’s private goes out the window.

Re: Google's Gemini AI caught scanning Google Drive PDF files without permission

#146

Earlier quoted context omitted.

You really think creating a country and creating software that respects your privacy are equally difficult?

Equally difficult, no. Equally important in principle, yes.

for someone that prefers to complain over solving the issues at hand, yes.

Re: Google's Gemini AI caught scanning Google Drive PDF files without permission

#147

Earlier quoted context omitted.

> It's literally just running an algorithm over your data and spitting out the results for you. I don't want any results from AI. I don't even want to see them. And there is too much of a grey area. What if they use how I use the results to improve their AI. I hate AI also and want nothing to do with its automations. If I want a document summarized, I will read it myself. I still want to be human and do things AT A R…

Again, that's like saying you don't want any results from spell-check. OK, sure. But then just don't use it. The problem is that you're calling for a legal policy against it to be "mandatory, enforced, and come with strict fines". Have your own personal preferences, that's great. But I don't want you imposing your preferences on the products I use. I want companies and the market to decide. An auto-summary feature th…

I don't want YOUR increasing use of AI to make a world where everyone is forced to use AI in their jobs and lives because it brings short-term business benefits.

Re: Google's Gemini AI caught scanning Google Drive PDF files without permission

#148

Earlier quoted context omitted.

Again, that's like saying you don't want any results from spell-check. OK, sure. But then just don't use it. The problem is that you're calling for a legal policy against it to be "mandatory, enforced, and come with strict fines". Have your own personal preferences, that's great. But I don't want you imposing your preferences on the products I use. I want companies and the market to decide. An auto-summary feature th…

I don't want YOUR increasing use of AI to make a world where everyone is forced to use AI in their jobs and lives because it brings short-term business benefits.

[deleted]

Re: Google's Gemini AI caught scanning Google Drive PDF files without permission

#149
post #63

Earlier quoted context omitted.

> This is partly true but less and less every day. Isn't this like encryption, though? I'm fairly sure that the cryptography community basically says: if someone has a copy of your encrypted data for a long time, the likelihood over time for them to be able to read it approaches 100%, regardless of the current security standard you're using. Who could possibly guarantee that whatever LLM is safe now will be safe at a…

I think it’s different, unless you believe LLMs have broken theoretical limits on compression. I don’t see how an LLM with 1T 16 bit parameters could encode 100PB of data.

My point was about attack angles. The original comment said, that for example, you could exfiltrate data with the right prompt attack.

To which the reply was "they'll just make the LLM able to better defend itself".

And my point was "the attackers will learn to build better prompts, too".

Re: Google's Gemini AI caught scanning Google Drive PDF files without permission

#150

All AI should be opt-in, which includes both training and scanning. You should have to check a box that says "I would like to use AI features", and the accompanying text should be crystal clear what that means. This should be mandatory, enforced, and come with strict fines for companies that do not comply.

This exists and is called encryption. Give the key out to people you want to read it. If anyone can read it, AI is going to read it wether your feelings like it or not
Post reply on HN