Live data from Hacker News

CISA’s acting head uploaded sensitive files into public version of ChatGPT

politico.com

101–110 of 264 posts

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#102

Earlier quoted context omitted.

Then again the CTO of Crowdstrike that had their anti-malware code update cause huge problems, is the same guy that was CTO of McAfee when their AV code update, caused huge problems.

The CTO created the update? Otherwise it's not the same situation

No but they could have easily created the culture that massively increased the probability of such mishaps... we have all seen how not OK work environment negatively affects deliveries right, or read about boeing fiasco(s).

Not an insider just to be clear here so maybe just really bad luck. But no benefit of doubt for the third strike.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#103

There have to be GovCloud only LLMs just for this case. I swear this government is headed by appointed nephews of appointed nephews. I keep thinking back about that Chernobyl miniseries; head of the science department used to run a shoe factory. No one needs to be competent at their job anymore

> There have to be GovCloud only LLMs just for this case. I hear Los Alamos labs has an LLM that makes ChatGPT look like a toy. And then there's Sentinel, which may be the same thing I'm not sure.

Check the engineering salaries between each organization and reconsider your claim.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#104
post #95

the current united states government is staffed mostly with unserious people, or people who are serious about doing crimes against humanity. there's very little in between.

The vast majority of government staff are career professionals who know what they are doing, not political appointees who showed up in the past year.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#105

Where does this "cybersecurity monitoring" take place? On OpenAIs side? Or some kind of monitoring tools on the devices themself?

In any enterprise, normal would be to have monitoring on all ingress and egress points from the network and on devices themselves. You can't only have monitoring on managed devices because someone might BYOD and plug in an unmanaged device/connect it to internal wifi etc.

You bring in vendors and they need guest wifi to give you a demo, you need to be able to give them something to connect to but you don't want that pipe to be unmonitored.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#106

Earlier quoted context omitted.

It goes back long before the current regime. People may remember a certain cabinet secretary who ran her own exchange server in the basement.

It’s always fascinating how massive corruption is “whatabout”’d because someone years ago did something stupid.

Do you mean now, or then?

Bad is still bad, no matter what the party doing it.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#107
post #99

I’m a little surprised by the takes in the comments. Obviously, heads of departments or agencies, CEOs, or similar personnel are generally not in the same league as normal employees when it comes to compliance. Productivity and efficiency are key for their work. I am sure there are lots of Sysadmins here, that had to disable security controls for a manager or had to configure something in a way to circumvent security…

Obviously those kinds of stories are common, but you can’t seriously be suggesting that it is a good or acceptable thing?

Execs are just as stupid as your average person and bypassing security controls for them puts an organization at an even greater risk due to the kinds of information they have access to. They just get away with it because they’re in charge.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#108
post #91

This administration's op-sec has been consistently "barney fife" levels of incompetence.

And when the CCP compromised the law enforcement portal for every American ISP, stealing info on 80% of Americans, including both the Kamala and Trump campaigns, under the previous admin it was rock solid op-sec, presumably. Or when the previous admin leaked classified Iran attack plans from the Pentagon, so bad that they didn't even know whether they were hacked or not. You can at least pretend to make a technical a…

> CCP compromised the law enforcement portal for every American ISP

Isn’t that the fault of the ISPs, not the admin?

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#109
post #29

Earlier quoted context omitted.

The article says > [ChatGPT] is blocked for other Department of Homeland Security staff. Gottumukkala “was granted permission to use ChatGPT with DHS controls in place,” adding that the use was “short-term and limited.” He had a special exemption to use it as head of Cyber and still got flagged by cybersecurity checks. So obviously they don't think it's safe to use broadly. They already have a deal with OpenAI to bui…

Somehow I think that the weak link in our government security is at the top - the President, his cabinet, and various heads of agencies. Because nobody questions what they're allowed to do, and so they're exempt from various common-sense security protocols. We already saw some pretty egregious security breaches from Pete Hegseth.

[flagged]

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#110

Earlier quoted context omitted.

It goes back long before the current regime. People may remember a certain cabinet secretary who ran her own exchange server in the basement.

It’s always fascinating how massive corruption is “whatabout”’d because someone years ago did something stupid.

[flagged]
Post reply on HN