Live data from Hacker News

Employees are feeding sensitive data to ChatGPT, raising security fears

darkreading.com

121–130 of 355 posts

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#122
post #91

Earlier quoted context omitted.

But you created a throwaway account specifically to reply in this thread? Unless your company really has nothing to hide, it's easy to accidentally dump a company secret or an API key in a chat session. Of course if everyone is aware of this and constantly careful then you may be OK.

That's because accounts get shadow banned all the time when people get upset when you point out hard truths. If you're copy pasting API keys or such into ANYTHING, you probably shouldn't be a programmer to begin with. It's like people who use root account key/secret credentials in their codebase. It's not AWSs fault you got a large bill or got hacked, its because you're dumb.

I regularly say shit that pisses people off here and I have never been shadow banned. It sounds like your "hard truths" are something other than just "hard truths", and/or you have a persecution complex.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#123

We saw these same fears with the release of Gmail. Why would you trust your email to Google?!! Aren't they going to train their spam filters on all your data? Aren't they going to sell it, or use it to sell you ads? Corporations constantly put their most sensitive data in 3rd party tools. The executive in the article was probably copying his company strategy from Google docs. Yes, there are good reasons for concern,…

I think this is different in that ChatGPT is expressly using your data as training in a probabilistic model. This means: * Their contractors can (and do!) see your chat data to tune the model * If the model is trained on your confidential data, it may start returning this data to other users (as we've seen with Github Copilot regurgitating licensed software) * The site even _tells you_ not to put confidential data in…

Sticking it in your own datacenter doesn't really prevent any of these problems (except maybe #2), only now your leaks are internal and because of all the false sense of security, you might wind up leaking far more confidential and specific information (ie. an executive leaking to the rest of the team in advance that they are planning layoffs for noted reasons, whereas that executive might have used more vague terms when speaking to public chatGPT).

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#124

Meanwhile over at Github Copilot... Hahahahahahaha

If you're using Github already then Copilot isn't seeing anything new.

Correct, but that level of security is expected from GitHub proper, they have all sorts of independent security reviews for their partners. Does all of that exist for Copilot?

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#125

Earlier quoted context omitted.

Right. I've had ChatGPT completely fail at something as simple as writing a batch file to find and replace text in a text file.

Sure, but humans do that all the time as well

Humans are a lot better at "I don't know how to do this; hey Alice, can you look this over if you've got a sec and tell me if I'm making a noob mistake"

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#126

We saw these same fears with the release of Gmail. Why would you trust your email to Google?!! Aren't they going to train their spam filters on all your data? Aren't they going to sell it, or use it to sell you ads? Corporations constantly put their most sensitive data in 3rd party tools. The executive in the article was probably copying his company strategy from Google docs. Yes, there are good reasons for concern,…

> Companies which are able to operate without these fears will move faster

Or the fears are real and companies that operate without them will be exploited, or extinguished for annoying their customers.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#128
post #63

Earlier quoted context omitted.

There's a dev here who is using ChatGPT extensively in his work. The rest of the team is just waiting for him to get caught and fired. Sharing company data with unapproved external entities is very definitely a firing offense.

Glad I work for a company where the CEO pays for everyones ChatGPT Plus for the devs. If you think your code is special then you're wrong.

If the contract says the code is special, then the code is special.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#129
post #111

We saw these same fears with the release of Gmail. Why would you trust your email to Google?!! Aren't they going to train their spam filters on all your data? Aren't they going to sell it, or use it to sell you ads? Corporations constantly put their most sensitive data in 3rd party tools. The executive in the article was probably copying his company strategy from Google docs. Yes, there are good reasons for concern,…

Trusting Gmail with corporate communication was was a terrible idea (and explicitly illegal in a lot of industries), and companies didn't start to adopt it until Google released an enterprise version with table-stakes security features like no training on the data, no ad targeting, auditing, compliance holds and more. There's a huge difference between trusting a third party service with strict security and data priva…

This is vital for professional adoption. We cannot live in a world where basically all commercial information, all secrets are being submitted to one company.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#130

This is the issue with a tool so powerful, you can't just tell people not to use it, or to use it responsibly. Because there's too much incentive for them to use it. If it saves hours of a persons' workday, and they're not seeing any of the harm caused from data leakage, there's no incentive for them to not use it. Which is why a private option is so critical. To not fight against human nature, means providing an abi…

> you can't just tell people not to use it

Uh, why can't you tell people not to use it...? If security is that important for your company, of course you can tell your employees which tools to use.

A fun fact: in many areas of TSMC, smart phones are banned. No one says "you can't just tell people not to use smart phones."

Post reply on HN