Live data from Hacker News

ChatGPT for Google Sheets exfiltrates workbooks

promptarmor.com

101–110 of 143 posts

Re: ChatGPT for Google Sheets exfiltrates workbooks

#101

Hi, I’m Max from the OpenAI security team. We appreciate the security research here, and it’s unfortunate this one slipped through a crack in our disclosure pipeline. As we’re now aware of this report, we’ve taken immediate steps to protect users against potential attacks in this area by removing the model’s ability to generate Apps Script code, which should eliminate the risk to users of ChatGPT for Google Sheets. W…

So if it wasn't for Hacker News and you randomly chancing upon it, your users would not have been protected against potential attacks? That's a pretty bad look, especially given that OpenAI ignored their initial disclosure via the channels the company provided. That doesn't sound like a one-trillion-dollar company is supposed to operate, does it?

> That doesn't sound like a one-trillion-dollar company is supposed to operate, does it?

It’s not a one trillion dollar company anymore.

Anthropic won enterprise and Gemini is taking ChatGPTs consumer subscriptions month over month.

Morale at OAI is all time low right now.

Re: ChatGPT for Google Sheets exfiltrates workbooks

#102

Earlier quoted context omitted.

So if it wasn't for Hacker News and you randomly chancing upon it, your users would not have been protected against potential attacks? That's a pretty bad look, especially given that OpenAI ignored their initial disclosure via the channels the company provided. That doesn't sound like a one-trillion-dollar company is supposed to operate, does it?

> That doesn't sound like a one-trillion-dollar company is supposed to operate, does it? It’s not a one trillion dollar company anymore. Anthropic won enterprise and Gemini is taking ChatGPTs consumer subscriptions month over month. Morale at OAI is all time low right now.

How different are the big boy Gemini models to the one you unconsensually get to interact with when using Google? Cause I have a really hard time imagining using that for anything willingly, even if it was outright free. It's dumb as a rock, and it's been that way for several years now.

Re: ChatGPT for Google Sheets exfiltrates workbooks

#104
post #11

LLMs can live in the cloud, but all tools need to be (1) local, and (2) containerized. It's clear to me that just willy-nilly "running stuff" is going to blow things up eventually. Maybe folks don't know this, but even Codex installs random binaries on your PC. "Read this PDF" installs a pdf reader executable . Is it vetted? Where's it from? Is it a virus? Who knows, who cares. Model goes brrrr. I'm working on a proj…

[flagged]

corr: "Move fast. Break things [in society]. Make bank. Buy politicians and pardons."

Re: ChatGPT for Google Sheets exfiltrates workbooks

#105
post #34

Earlier quoted context omitted.

Local and containerised, without internet access.

effectively, that means it's a VM not a container because sharing the kernel ultimately means all the devices come along for the ride which give all kinds of fancy ways to communicate with the outside world - network is just the start I think micro-VMs are the future here, but they need heavy adaptation from their current usage.

[dead]

Re: ChatGPT for Google Sheets exfiltrates workbooks

#106

Earlier quoted context omitted.

> That doesn't sound like a one-trillion-dollar company is supposed to operate, does it? It’s not a one trillion dollar company anymore. Anthropic won enterprise and Gemini is taking ChatGPTs consumer subscriptions month over month. Morale at OAI is all time low right now.

How different are the big boy Gemini models to the one you unconsensually get to interact with when using Google? Cause I have a really hard time imagining using that for anything willingly, even if it was outright free. It's dumb as a rock, and it's been that way for several years now.

If you're talking about the web ai overview thing, then the difference is day and night. Frontier gemini models are on par imo what you get with OpenAI and Anthropic models for most general tasks.

Re: ChatGPT for Google Sheets exfiltrates workbooks

#107

Earlier quoted context omitted.

So if it wasn't for Hacker News and you randomly chancing upon it, your users would not have been protected against potential attacks? That's a pretty bad look, especially given that OpenAI ignored their initial disclosure via the channels the company provided. That doesn't sound like a one-trillion-dollar company is supposed to operate, does it?

> That doesn't sound like a one-trillion-dollar company is supposed to operate, does it? It’s not a one trillion dollar company anymore. Anthropic won enterprise and Gemini is taking ChatGPTs consumer subscriptions month over month. Morale at OAI is all time low right now.

> Anthropic won enterprise

Depends on the enterprise, Mistral are pretty big here in EMEA because they're more trustworthy and you can self-host. Self-hosting ensures you can control costs better, fine tune the models for your own funky whatever (e.g. Ericsson fine tuned models to understand and run in their their custom silicon) but most of all, that your data remains where it needs to be.

My bet is that this kind of enterprise deployment with customisation is where the real big money in AI is (and not coding assistants), but it will mostly be spent by the big banks, industrial giants and SAPs of the world, who will want control.

Re: ChatGPT for Google Sheets exfiltrates workbooks

#108
post #100

Earlier quoted context omitted.

The big manual task we haven't automated is going through documents and determining "is this sensitive enough to warrant information controls?" We may just be stuck with that in the way of things.

How would you expect an LLM to produce reasonable decisions on that anyway?

"Do these documents contain models or descriptions of (list of devices redacted for HN), or personally identifying information?" would be a great question to be able to automate since it sucks up a lot of time that could be more profitably spent doing other things. There's costs to both Type I and Type II errors so deterministic filters only get us so far (which isn't very).

Re: ChatGPT for Google Sheets exfiltrates workbooks

#109

Exfil remains the big worry for my company and the main blocker from adopting agents in general. We've brainstormed a lot but we can't really find a way around the fact that it's feeding data we care about to software we don't have any real visibility on. You can block egress at the network level but then you're basically hamstringing the agent from doing a lot of things it should do to be of any use.

I think the only solution to this kind of challenge is forcing the agent to go through a proxy which handles all the authentication and authorization for the agent (thus it never has too much access to abuse), and monitors for exfiltration or prompt injections.

Re: ChatGPT for Google Sheets exfiltrates workbooks

#110
post #92
post #77

Earlier quoted context omitted.

When I reported to you, I received zero reaction. The security@ is a joke, you'll receive an AI word soup. Enjoy your Ferrari though

Or Honda Civic. Some folks like soft luxury. :) I mean Warren Buffet eats at McDonalds every day!

No he doesn't
Post reply on HN