Live data from Hacker News

CISA’s acting head uploaded sensitive files into public version of ChatGPT

politico.com

71–80 of 264 posts

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#71
post #12

https://en.wikipedia.org/wiki/Madhu_Gottumukkala He was the 'CTO' of South Dakota and later the CIO/Commissioner of the South Dakota Bureau of Information and Telecommunications under governor Kristi Noem. Edit: (From a European perspective) it seems like the southern states really took over the US establishment. I hadn't really grasped the level of it, before.

> Edit: (From a European perspective) it seems like the southern states really took over the US establishment. I hadn't really grasped the level of it, before.

It's good to know the Americans aren't the only ones who never look at maps outside their own country

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#72
I really enjoyed unchecking all those cookie controls. Of the 1668 partner companies who are so interested in me, a good third have a "legitimate interest". With each wanting to drop several cookies, it seems odd that Privacy Badger only thinks there are 19 cookies to block. Could some of them be fakes - flooding the zone?

Damn. I forgot to read the article.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#73
post #62
post #58

Earlier quoted context omitted.

That they got this is shocking in itself.

Surely that must have been approved by the Secretary of Homeland Security Kristi Noem, his former boss back in SD.

Every cause that led to this event is, in itself, quite shocking.

I feel for my American friends, and hope they never again optimise their government for comedy value.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#75

Earlier quoted context omitted.

Somehow I think that the weak link in our government security is at the top - the President, his cabinet, and various heads of agencies. Because nobody questions what they're allowed to do, and so they're exempt from various common-sense security protocols. We already saw some pretty egregious security breaches from Pete Hegseth.

That's also the case in businesses. No one denies the CEO a security exemption.

Been there. The CEO of an internet security company was the one who clicked on the wrong email attachment and turned a virus loose.

I mean, I don't know if he had a security exemption, or if anyone who clicked on it would have infected us. But he was the weak link, at least in that instance.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#76

Earlier quoted context omitted.

Somehow I think that the weak link in our government security is at the top - the President, his cabinet, and various heads of agencies. Because nobody questions what they're allowed to do, and so they're exempt from various common-sense security protocols. We already saw some pretty egregious security breaches from Pete Hegseth.

That's also the case in businesses. No one denies the CEO a security exemption.

I have never worked in a company where an obviously incorrect CEO-demanded security exemption (like this one) would have been allowed to pass. Professionalism, boards (with a mandatory employee member/representative, after some size) and ethics exist.

30 years in about 8 software companies, Northern Europe. Often startups. Between 4 to 600 people. When they grow large the work often turns boring, so it's time to find something smaller again.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#77
post #7

This is a "Cybersecurity chief" causing an intern-level IT incident. In many industries, this would be a rapid incident at the company-level and also an immediate fireable offense and in some governments this would be a complete massive scandal + press conference broadcasted across the country.

Then again the CTO of Crowdstrike that had their anti-malware code update cause huge problems, is the same guy that was CTO of McAfee when their AV code update, caused huge problems.

The CTO created the update? Otherwise it's not the same situation

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#78
post #29

Earlier quoted context omitted.

The article says > [ChatGPT] is blocked for other Department of Homeland Security staff. Gottumukkala “was granted permission to use ChatGPT with DHS controls in place,” adding that the use was “short-term and limited.” He had a special exemption to use it as head of Cyber and still got flagged by cybersecurity checks. So obviously they don't think it's safe to use broadly. They already have a deal with OpenAI to bui…

Somehow I think that the weak link in our government security is at the top - the President, his cabinet, and various heads of agencies. Because nobody questions what they're allowed to do, and so they're exempt from various common-sense security protocols. We already saw some pretty egregious security breaches from Pete Hegseth.

It goes back long before the current regime. People may remember a certain cabinet secretary who ran her own exchange server in the basement.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#80

This administration's op-sec has been consistently "barney fife" levels of incompetence.

It's been the same with every administration, unfortunately. It's just a side effect of such an unnecessarily big goverment.

Inviting a reporter from the Atlantic to your signal chat where you coordinate military plans has nothing to do with government being too big
Post reply on HN