Live data from Hacker News

CISA’s acting head uploaded sensitive files into public version of ChatGPT

politico.com

111–120 of 264 posts

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#112
post #99

I’m a little surprised by the takes in the comments. Obviously, heads of departments or agencies, CEOs, or similar personnel are generally not in the same league as normal employees when it comes to compliance. Productivity and efficiency are key for their work. I am sure there are lots of Sysadmins here, that had to disable security controls for a manager or had to configure something in a way to circumvent security…

It touched a nerve because no one in the trump admin is qualified to do their job. There's a lot of corruption and a lot of people getting access to things they shouldn't due to their relationship and loyalty, not merit. There's a big difference from a sys admin having super user access and some random politically connected hack abusing their privilege.

DOGE/Musk, noem, Kash, hegseth, etc.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#113
post #99

I’m a little surprised by the takes in the comments. Obviously, heads of departments or agencies, CEOs, or similar personnel are generally not in the same league as normal employees when it comes to compliance. Productivity and efficiency are key for their work. I am sure there are lots of Sysadmins here, that had to disable security controls for a manager or had to configure something in a way to circumvent security…

Sysadmins are afforded special leniency because of their demonstrated competence. Their leeway is earned. In this case, the "cyber security chief" has no proven skill other than absolute loyalty to his boss, which justified his skipping the usual vetting procedure.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#114
post #72

I really enjoyed unchecking all those cookie controls. Of the 1668 partner companies who are so interested in me, a good third have a "legitimate interest". With each wanting to drop several cookies, it seems odd that Privacy Badger only thinks there are 19 cookies to block. Could some of them be fakes - flooding the zone? Damn. I forgot to read the article.

[deleted]

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#115
post #91

This administration's op-sec has been consistently "barney fife" levels of incompetence.

And when the CCP compromised the law enforcement portal for every American ISP, stealing info on 80% of Americans, including both the Kamala and Trump campaigns, under the previous admin it was rock solid op-sec, presumably. Or when the previous admin leaked classified Iran attack plans from the Pentagon, so bad that they didn't even know whether they were hacked or not. You can at least pretend to make a technical a…

You're the one making a political argument by doing a whataboutism that attempts to negate the failings of this administration. Which you're not even doing correctly because by every measure the previous administration was drastically more competent by looking at the qualifications of the people who filled their posts.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#116

There have to be GovCloud only LLMs just for this case. I swear this government is headed by appointed nephews of appointed nephews. I keep thinking back about that Chernobyl miniseries; head of the science department used to run a shoe factory. No one needs to be competent at their job anymore

Isn't using azure openai enough? I read their docs and they have self hosted instances for corporate data compliance.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#118

There have to be GovCloud only LLMs just for this case. I swear this government is headed by appointed nephews of appointed nephews. I keep thinking back about that Chernobyl miniseries; head of the science department used to run a shoe factory. No one needs to be competent at their job anymore

Hey, working at a shoe factory is serious business. You have to be a real bootlicker to get ahead in a place like that.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#119
I would like to be able to say that it is uncommon, but based on what I am seeing in my neck of the woods, all sorts of, one would think, private information is ingested by various online llms. I would have been less annoyed with it had those been local deployments, but, uhhh, to say it is not a first choice is being over the top charitable with current corporates. And it is not even question of money! Some of those corps throw crazy money at it.

edit: Just in case, in the company I currently work at, compliance apparently signed off on this with only a rather slim type of data verbotten from upload.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#120
post #76

Earlier quoted context omitted.

That's also the case in businesses. No one denies the CEO a security exemption.

I have never worked in a company where an obviously incorrect CEO-demanded security exemption (like this one) would have been allowed to pass. Professionalism, boards (with a mandatory employee member/representative, after some size) and ethics exist. 30 years in about 8 software companies, Northern Europe. Often startups. Between 4 to 600 people. When they grow large the work often turns boring, so it's time to find…

I used to work devops for a startup. The _only_ person who was exempted from 2-factor auth was the CEO. It's the perfect storm: a tech illiterate person with access to everything and the authority to exclude himself from anything he finds inconvenient.
Post reply on HN