Live data from Hacker News

Microsoft says bug causes Copilot to summarize confidential emails

bleepingcomputer.com

21–30 of 85 posts

Re: Microsoft says bug causes Copilot to summarize confidential emails

#22
post #20

There are two issues I see here (besides the obvious “Why do we even let this happen in the first place?”): 1. What happened to all the data Copilot trained on that was confidential? How is that data separated and deleted from the model’s training? How can we be sure it’s gone? 2. This issue was found; unfortunately without a much better security posture from Microsoft, we have no way of knowing what issues are curre…

All the vendors paraphrase user data, then use the paraphrased data for training. This is what their terms of service say.

They have significant experience in this. Microsoft software since the 2014, for the most part, is also paraphrased from other people's code they find laying around online.

Re: Microsoft says bug causes Copilot to summarize confidential emails

#23

> However, this ongoing incident has been tagged as an advisory, a flag commonly used to describe service issues typically involving limited scope or impact. How is having Copilot breach trust and privacy an “advisory”? Am I missing something?

The LLM that wrote this nearly content-free story doesn't know what it's talking about.

The basic distinction in the infosec industry is that advisories are what you publish to tell customers that you had a bug in your product that might have exposed them or their data to attacks and you want them to take some specific action (e.g., upgrade a package, review logs); while an incident report is what you publish when you know that the damage happened, it involved your infrastructure, and you want to share some details about happened and how you're going to prevent it from happening again.

Because the latter invites a lot more public attention and regulatory scrutiny, a company like Microsoft will go out of their way to stick to advisories whenever possible (or just keep incidents under wraps). It might have happened at some points in their history, but off the top of my head, I don't recall Microsoft ever publishing a first-party security incident report.

Re: Microsoft says bug causes Copilot to summarize confidential emails

#24
post #18

> However, this ongoing incident has been tagged as an advisory, a flag commonly used to describe service issues typically involving limited scope or impact. How is having Copilot breach trust and privacy an “advisory”? Am I missing something?

https://www.merriam-webster.com/dictionary/advise meaning 2: to give information or notice to : INFORM An advisory gives notice and/or warns about something, and may give recommendations on possible actions (but doesn’t have to).

Words have multiple meanings depending on context, and here it's at best ambiguous. In the context of security incidents, logging, auditing, etc., "advisory" is often used as a severity level (and one of the lower ones at that).

So, yes, technically, it's de-facto advisory to publish this information, but assigning "advisory" as a severity tag here is questionable.

Re: Microsoft says bug causes Copilot to summarize confidential emails

#25
None of this should surprise anyone by now. You are being lied to, continually.

You guys need to read the actual manifestos these AI leaders have written. And if not them, then read the propagandist stories they have others write like The Overstory by Richard Powers which is an arrogant pile of trash that culminates in the moral:

humans are horrible and obsolete and all should die and leave the earth for our new AI child

Which is of course, horseshit. They just want most people to die off, not all. And certainly not themselves.

They don't care about your confidential information, or anything else about you.

Post reply on HN