Live data from Hacker News

CISA’s acting head uploaded sensitive files into public version of ChatGPT

politico.com

231–240 of 264 posts

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#231
post #148

I for one, after doing a bit of reserach, was shocked to find out the person in question is apparently completely unqualified for the job (if him pasting sensitive information into public ChatGPT didn't already make that abundantly clear). But the highlight from his Wikipedia page is this one: >In December 2025, Politico reported that Gottumukkala had requested to see access to a controlled access program—an act that…

Polygraphs have to be one of the most awkward / bizarre requirements for accessing a program. They are not scientifically reliable.

They're somewhat effective at stopping people applying if those people know they will have to lie

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#232
post #220
post #184

It's so often the guys that are at the top who are the exception to the rules that are the problem. I knew some folks who worked military communications and they broke rules regularly because senior officers just didn't want to walk across the street to do something secure...

Have worked in places where juniors had to lock devices when on prem; only authorized hardware in the rooms. Yet, the danger was from sloppy O6+ not the O1/GS6 who would (ready&abel) carry the water. The is a serious problem with folk with power and authority and somehow no responsibility. That's across government, service and corporate.

> The is a serious problem with folk with power and authority and somehow no responsibility.

Or perhaps the fundamental problem is with people in general - perhaps people without power and authority follow rules only because they don't have the power and authority to ignore them.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#233
post #148

I for one, after doing a bit of reserach, was shocked to find out the person in question is apparently completely unqualified for the job (if him pasting sensitive information into public ChatGPT didn't already make that abundantly clear). But the highlight from his Wikipedia page is this one: >In December 2025, Politico reported that Gottumukkala had requested to see access to a controlled access program—an act that…

Polygraphs have to be one of the most awkward / bizarre requirements for accessing a program. They are not scientifically reliable.

There is a reason why nobody uses them but the U.S.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#234

Earlier quoted context omitted.

You would not get a security clearance, and the admin would make a note on your IQ. The correct answer is simply > no and keep the rest of it in your head.

how is it low IQ to be honest? People have to make decisions and if the decision is "no", I can handle that. Empowering the person making the decision to the fullest extent is something I'd still be interested in, even if it is to my detriment. Its like when middle-management ask me to lie or withold information from the COO or CEO, its just a no. If they're shit then its on the organisation to sort that out. Second…

A smart person seeking a security clearance would not volunteer information that wasn't asked for, that causes him to be denied the clearance.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#235

It’s absolutely necessary to have ChatGPT.com blocked from ITAR/EAR regulated organizations, such as aerospace, defense, etc. I’m really shocked this wasn’t already the case.

Sure. That doesn't mean denying access to ChatGPT though - the way I see it, the entire value proposition of Microsoft offering OpenAI models through Azure is to enable access to ChatGPT under contractual terms that make it appropriate for use in government and enterprise organizations, including those dealing with sensitive technology work.

I mean, they are all using O365 to run their day-to-day businesses anyway.

I used to work in a large technology multinational - not "tech industry", but proper industrial technology; the kind of corp that does everything, from dishwashers to oil rigs. It took nearly a year from OpenAI releasing GPT-4 to us having some form of access to this model for general work (coding and otherwise) internally, and from what I understand[0], it's just how long it took for the company to evaluate risks and iron out appropriate contractual agreements with Microsoft wrt. using generative models hosted on Azure. But they did it, which proves to me it's entirely possible, even in places where people are more worried about accidentally falling afoul of technology exports control than insider training.

--

[0] - Purely observational, I had no access to any insider/sensitive information regarding this process.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#236
post #56

Earlier quoted context omitted.

> It's bizarre that someone would choose to use the public, 4o bot over the ChatGPT Pro level bot available in the properly siloed You're assuming the planted lackey has any knowledge of these tools.

Or any reason to give a shit and use the less convenient tool.

Another example why shitty software can easily become a compliance or security problem.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#237

Earlier quoted context omitted.

Polygraphs have to be one of the most awkward / bizarre requirements for accessing a program. They are not scientifically reliable.

There is a reason why nobody uses them but the U.S.

The US uses them more pervasively it seems, but there's still remnants of it elsewhere.

The UK uses them for post-conviction monitoring in certain offenses: https://www.gov.uk/government/publications/police-crime-sent... ...and there's more than one British polygraph group: BPA and BPS (https://www.britishpolygraphassociation.org/, https://polygraph.org.uk/)

Australia did indeed reject the polygraph for security clearance: https://antipolygraph.org/blog/2006/10/19/australian-securit...

Canada however does seem to use it as part of their intelligence screening: https://www.canada.ca/en/security-intelligence-service/corpo...

> Do I have to go through the polygraph test to join CSIS?

> Yes. All CSIS employees must obtain a Top Secret security clearance and the polygraph is a mandatory part of the process.

Seems to be the same for CSE and to get "Enhanced Top Secret" clearance.

Back to the US, the Department of Labor says that private employers can't force people to undergo a polygraph test: https://www.dol.gov/agencies/whd/polygraph But of course this does not apply to public sector jobs, where it's used more pervasively.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#238
post #220

Earlier quoted context omitted.

Have worked in places where juniors had to lock devices when on prem; only authorized hardware in the rooms. Yet, the danger was from sloppy O6+ not the O1/GS6 who would (ready&abel) carry the water. The is a serious problem with folk with power and authority and somehow no responsibility. That's across government, service and corporate.

> The is a serious problem with folk with power and authority and somehow no responsibility. Or perhaps the fundamental problem is with people in general - perhaps people without power and authority follow rules only because they don't have the power and authority to ignore them.

I think this is the real winner here.

Power corrupts because power means you can be corrupt.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#239

I adore that this guy had security clearance and I doubt I'd clear that bar. Last time I looked at the interview there was a question: > have you ever misused drugs? and I doubt I'd be able to resist the response: > of course not, I only use drugs properly. also I wouldn't lie, because that's would undermine the purpose. Still sad I can't apply for SC jobs because I'm extremely patriotic and improving my nation is so…

FWIW I have held a security clearance during my career, and telling them I smoked weed was not a dealbreaker. What they are ultimately looking for is reasons why you could be coerced into divulging classified information. If you owe money due to drugs/gambling, etc, that's where it becomes a dealbreaker.

Yeah, this is true. They are looking for vulnerabilities that can be exploited by others - the fact you smoke a blunt once a week is not a problem in that regard.

Re: CISA’s acting head uploaded sensitive files into public version of ChatGPT

#240
post #202

Earlier quoted context omitted.

DEI in action (funny people thst voted for this were apparently anti-DEI and now they get 100% DEI)

Of course this comment is mostly ironic, but noting for the whole class, when the MAGA talked about DEI they only ever meant ethnic and sexual minorities, competence be damned! That is of course the thing about ideologies like it: loyalty before all else.

DEI is basically “someone else got a gig not because of their abilities but because _____”

The entire Trump administration, every single person, is a DEI hire.

Post reply on HN