Live data from Hacker News

CISA’s acting head uploaded sensitive files into public version of ChatGPT

politico.com

171–180 of 264 posts

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#171
post #118

There have to be GovCloud only LLMs just for this case. I swear this government is headed by appointed nephews of appointed nephews. I keep thinking back about that Chernobyl miniseries; head of the science department used to run a shoe factory. No one needs to be competent at their job anymore

Hey, working at a shoe factory is serious business. You have to be a real bootlicker to get ahead in a place like that.

And when you get to the top, you actually experience how the shoe is on the other foot. One should get out early, not waiting for the other shoe to drop.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#172

Earlier quoted context omitted.

Do remember that HBO Chernobyl is fiction, there was no shoe guy publicly drinking vodka irl

It is perfectly plausible that someone from a shoe factory would end up in that guy’s position. He would just have been running the factory, not making shoes.

not in the USSR at the time of the events.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#173

There have to be GovCloud only LLMs just for this case. I swear this government is headed by appointed nephews of appointed nephews. I keep thinking back about that Chernobyl miniseries; head of the science department used to run a shoe factory. No one needs to be competent at their job anymore

> There have to be GovCloud only LLMs just for this case. I hear Los Alamos labs has an LLM that makes ChatGPT look like a toy. And then there's Sentinel, which may be the same thing I'm not sure.

Is it called "Skynet?"

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#174
post #29

Earlier quoted context omitted.

The article says > [ChatGPT] is blocked for other Department of Homeland Security staff. Gottumukkala “was granted permission to use ChatGPT with DHS controls in place,” adding that the use was “short-term and limited.” He had a special exemption to use it as head of Cyber and still got flagged by cybersecurity checks. So obviously they don't think it's safe to use broadly. They already have a deal with OpenAI to bui…

> So obviously they don't think it's safe to use broadly. More likely, everything gets added to the list because there shouldn't be false positives, it's worth investigating to make sure there isn't an adjacent gap in the security systems.

You are uploading information to the chat system every time you use it. Doubly true if you’re having it analyze or work with documents.

I presume pulling this data out is simple if you’re, say, China.

There really no security to investigate. Without a private instance, it’s an absolute non-starter for anything classified.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#175

Earlier quoted context omitted.

Somehow I think that the weak link in our government security is at the top - the President, his cabinet, and various heads of agencies. Because nobody questions what they're allowed to do, and so they're exempt from various common-sense security protocols. We already saw some pretty egregious security breaches from Pete Hegseth.

That's also the case in businesses. No one denies the CEO a security exemption.

Why would you? He’s literally the only person ostensibly in charge of the direction of the company. Destroying the company through a security exemption or a bad business deal - both are the leader making a poor decision due directly to his seat of power.

Give sound advice of course, but ultimately it’s the exec’s decision make.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#176

Earlier quoted context omitted.

That's also the case in businesses. No one denies the CEO a security exemption.

Why would you? He’s literally the only person ostensibly in charge of the direction of the company. Destroying the company through a security exemption or a bad business deal - both are the leader making a poor decision due directly to his seat of power. Give sound advice of course, but ultimately it’s the exec’s decision make.

There are many reasons to deny a CEO ... in a good company structure such denials are circled back around to the board for review.

Case in point: Allowing a CEO with no flight training to "have the keys" to the company because they want to take it for a spin.

Sheparding Royalty in Monarchies has been a neccessary, delicate, loaded, and life threatening role for centuries.

Being a C-suite Groom of the Stool isn't a happy job, but somebody has to do it.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#177

Where does this "cybersecurity monitoring" take place? On OpenAIs side? Or some kind of monitoring tools on the devices themself?

In any enterprise, normal would be to have monitoring on all ingress and egress points from the network and on devices themselves. You can't only have monitoring on managed devices because someone might BYOD and plug in an unmanaged device/connect it to internal wifi etc. You bring in vendors and they need guest wifi to give you a demo, you need to be able to give them something to connect to but you don't want that…

What I'm really asking/wondering is how (and who or which party) figured out that this was leaked, and secondly how that propagated to the public. I don't really expect to find that answer. But if I had to guess OpenAI found out first, because employees there are more likely to leak the fact that the leak happened.

But also, how was it caught in the first place? Was it automatically flagged because content scanners automatically identified this as a concern, or was his account specially flagged for extra monitoring because of who he is?

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#178

Earlier quoted context omitted.

They say it, but they're wrong. Historically speaking there have been basically about 2 fascist governments, and they fell because they lost wars. And Germany, for one, did run them with high competence, to the extend that it took years for many countries to do anything about. It we loosen "fascist" to just mean any authoritarian government, there are many that run of very long time.

WWII started in 1939 and was done in early 1945, so it didn't take that long. More importantly, maybe the Nazi's were competent at first, but they absolutely fell apart internally due to mistrust, back stabbing, and demanding of loyalty above all else. Hitler famously made many poor military decisions.

The Nazis were in power for years before they started WWII.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#179

I adore that this guy had security clearance and I doubt I'd clear that bar. Last time I looked at the interview there was a question: > have you ever misused drugs? and I doubt I'd be able to resist the response: > of course not, I only use drugs properly. also I wouldn't lie, because that's would undermine the purpose. Still sad I can't apply for SC jobs because I'm extremely patriotic and improving my nation is so…

You would not get a security clearance, and the admin would make a note on your IQ. The correct answer is simply > no and keep the rest of it in your head.

how is it low IQ to be honest? People have to make decisions and if the decision is "no", I can handle that. Empowering the person making the decision to the fullest extent is something I'd still be interested in, even if it is to my detriment. Its like when middle-management ask me to lie or withold information from the COO or CEO, its just a no. If they're shit then its on the organisation to sort that out. Second guessing everything leads to even worse dysfunction.

We're not talking about sneaking into a concert or something low-stakes, the security of our nation is the foundation of our very civilization. I have dual citizenship of a nation that borders Russia and was once the USSR, so I appreciate the stakes of worst case scenarios because one of my nations was under that boot rather recently.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#180

Earlier quoted context omitted.

> So obviously they don't think it's safe to use broadly. More likely, everything gets added to the list because there shouldn't be false positives, it's worth investigating to make sure there isn't an adjacent gap in the security systems.

You are uploading information to the chat system every time you use it. Doubly true if you’re having it analyze or work with documents. I presume pulling this data out is simple if you’re, say, China. There really no security to investigate. Without a private instance, it’s an absolute non-starter for anything classified.

> presume pulling this data out is simple if you’re, say, China

Why would you presume that?

Post reply on HN