Live data from Hacker News

CISA’s acting head uploaded sensitive files into public version of ChatGPT

politico.com

41–50 of 264 posts

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#41
It's bizarre that someone would choose to use the public, 4o bot over the ChatGPT Pro level bot available in the properly siloed and compliant Azure hosted ChatGPT already available to them at that time. The government can use segregated secure systems set up specifically for government use and sensitive documents.

It looks like he requested and got permission to work with "For Unofficial Use Only" documents on ChatGPT 4o - the bureaucracy allowed it - and nobody bothered to intervene. The incompetence and ignorance both are ridiculous.

Fortunately, nothing important was involved - it was "classified because everything gets classified" bureaucratic type classification, but if you're CISA leadership, you've gotta be on the ball, you can't do newbie bullshit like this.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#42

There have to be GovCloud only LLMs just for this case. I swear this government is headed by appointed nephews of appointed nephews. I keep thinking back about that Chernobyl miniseries; head of the science department used to run a shoe factory. No one needs to be competent at their job anymore

> There have to be GovCloud only LLMs just for this case.

I hear Los Alamos labs has an LLM that makes ChatGPT look like a toy. And then there's Sentinel, which may be the same thing I'm not sure.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#44

This administration's op-sec has been consistently "barney fife" levels of incompetence.

It's been the same with every administration, unfortunately. It's just a side effect of such an unnecessarily big goverment.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#45
post #8
post #4

Earlier quoted context omitted.

Hand-picked by Noem, so yeah. https://en.wikipedia.org/wiki/Madhu_Gottumukkala > In April 2025, secretary of homeland security Kristi Noem named Gottumukkala as the deputy director of the Cybersecurity and Infrastructure Security Agency; he began serving in the position on May 16. That month, Gottumukkala told personnel at the agency that much of its leadership was resigning and that he would serve as its acting dire…

> Gottumukkala had requested to see access to a controlled access program—an act that would require taking a polygraph Are the US ok? It's 2026 not 1926

It's actually a few minutes to 1929, so that checks out.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#47

Earlier quoted context omitted.

Incompetence and conspiracies go hand-in-hand.

Not really. It is far easier to explain incompetence in powerful positions than to explain competence on purpose in powerful positions - the latter is definitely a conspiracy, the former is not.

Quite often it is both.

It's not uncommon for incompetent people to be put in positions of power. Because they are incompetent, competent but malicious people take advantage of this and commit actual crimes.

This is where actual conspiracies show up. And that is the incompetent powerful people cover up said crime to avoid looking incompetent.

It is an extremely common pattern.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#48
post #7

This is a "Cybersecurity chief" causing an intern-level IT incident. In many industries, this would be a rapid incident at the company-level and also an immediate fireable offense and in some governments this would be a complete massive scandal + press conference broadcasted across the country.

Then again the CTO of Crowdstrike that had their anti-malware code update cause huge problems, is the same guy that was CTO of McAfee when their AV code update, caused huge problems.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#49
post #9

This administration's op-sec has been consistently "barney fife" levels of incompetence.

this administrations competence on anything and everything has been a kid eating glue

We should get their heads checked for crayons.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#50
post #29

There have to be GovCloud only LLMs just for this case. I swear this government is headed by appointed nephews of appointed nephews. I keep thinking back about that Chernobyl miniseries; head of the science department used to run a shoe factory. No one needs to be competent at their job anymore

The article says > [ChatGPT] is blocked for other Department of Homeland Security staff. Gottumukkala “was granted permission to use ChatGPT with DHS controls in place,” adding that the use was “short-term and limited.” He had a special exemption to use it as head of Cyber and still got flagged by cybersecurity checks. So obviously they don't think it's safe to use broadly. They already have a deal with OpenAI to bui…

Somehow I think that the weak link in our government security is at the top - the President, his cabinet, and various heads of agencies. Because nobody questions what they're allowed to do, and so they're exempt from various common-sense security protocols. We already saw some pretty egregious security breaches from Pete Hegseth.
Post reply on HN