Live data from Hacker News

Employees are feeding sensitive data to ChatGPT, raising security fears

darkreading.com

341–350 of 355 posts

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#341

Earlier quoted context omitted.

This really depends on the cost/benefit tradeoff for the entity in question. If using ChatGPT makes you X% more productive (shipping faster / lowers labor costs / etc), but comes with Y% risk of data leakage, is that worth it in expectation or not? I would argue that there definitely exist companies for which it's worth the tradeoff. By the way, OpenAI says they wont use data submitted through its API for model train…

You've certainly not worked with _real_ sensitive data. The kind that can bankrupt your business. I do and if it could be leaked through ChatGPT I would have it blocked. Risk isn't a single dimension, it's a combination of exposure (chance of happening) and impact (how much will you lose)

Mate. You aren’t special. It’s the nature of the profession that most of us are in, that we end up dealing with the “sensitive” data that you’re describing, barring most people working in Big Companies with proper internal controls.

Nothing you’ve said negates anything OP said. It’s simply an elaboration wrapped in elitism.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#342

Earlier quoted context omitted.

This really depends on the cost/benefit tradeoff for the entity in question. If using ChatGPT makes you X% more productive (shipping faster / lowers labor costs / etc), but comes with Y% risk of data leakage, is that worth it in expectation or not? I would argue that there definitely exist companies for which it's worth the tradeoff. By the way, OpenAI says they wont use data submitted through its API for model train…

the #1 problem with corporations saying things is that many things they say are not regulated or are taken on good faith. What happens with OpenAI are acquired and the rules change? These comments are often entirely worthless.

These are contractual terms.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#343

Earlier quoted context omitted.

I simply don't give a crap if my employer loses data. I don't care if my carelessness costs my employer a billion bucks down the line as I won't be working for them next year.

Why don’t you feel any responsibility?

I am treating my employment like a corporation would. Risks I do not pay for and do not benefit from mitigating are waste that could allow me to transfer time back to my own priorities, increasing my personal "profit."

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#344

Earlier quoted context omitted.

Blocks are effective reminders of policies.

I remember someone trying to look up winning lottery numbers at work. The site came up "Blocked: Gambling". It was a little reminder that they're watching our web browsing at work..

Well, a firewall rule based on a cloud-populated access control list interrupted traffic. More likely vendor-related than employer-related.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#345

Earlier quoted context omitted.

Doesn't OpenAI explicitly say that your Q/A on the free ChatGPT are stored and sent to human reviewers to be put in their RL database? Now of course we can't be sure what google, AWS etc do with the data on disks there, but it would be a pretty big scandal if some whistleblower eventually comes out and say that google employees sit and laugh at private bucket contents on GCP or private Google Docs. So there's a diffe…

Who in their right mind is using free ChatGPT through that shitty no good web interface of theirs, that can barely handle two queries-and-replies before grinding down to a halt? Surely everyone is using the pay-as-you-go API keys and any one of the alternative ffrontends or integrations? And, IIRC, pay-as-you-go API requests are explicitly not used for training data. I'm sad GPT-4 isn't there yet - except for those w…

> and any one of the alternative ffrontends or integrations?

And what sort of understanding do you have with the alternative frontends/integrations about how they handle your API keys and data? This might be a better solution for a variety of reasons but it doesn't automatically mean your data is being handled any better or worse than by openai.com

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#346

Earlier quoted context omitted.

I have a addon, were every other sentence is generated by Chat GPT. Good luck holding me liable for a robots actions.

Unless you can prove a given sentence was generated by ChatGPT, it will be assumed it wasn't.

As a moral questionable answering robot however, i must aks, why all things else should be tainted by the machinery, but evidence like text should not?

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#347

We saw these same fears with the release of Gmail. Why would you trust your email to Google?!! Aren't they going to train their spam filters on all your data? Aren't they going to sell it, or use it to sell you ads? Corporations constantly put their most sensitive data in 3rd party tools. The executive in the article was probably copying his company strategy from Google docs. Yes, there are good reasons for concern,…

I think this is different in that ChatGPT is expressly using your data as training in a probabilistic model. This means: * Their contractors can (and do!) see your chat data to tune the model * If the model is trained on your confidential data, it may start returning this data to other users (as we've seen with Github Copilot regurgitating licensed software) * The site even _tells you_ not to put confidential data in…

Well, you can stick it on Azure.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#348

Earlier quoted context omitted.

If you really care about your company's security, you should report it, otherwise you are just complicit.

Why not talk to the employee first?

This could be valid...but with something as powerful as ChatGPT, if it is providing huge benefits for employee productivity, they are unlikely to dump it based off a co-worker's suggestion. Also, unless managing security is within your roles and responsibilities, this approach would likely turn messy from an interpersonal aspect. Lastly, the security issue has already happened, so if this is truly a security concern, the security team should know that (a) something is already out there (b) this could be a widespread problem in the future.

FWIW I don't think the employee should be fired for this or anything, if anything a company could embrace these new technological advances and provide training on using ChatGPT in a more secure manner(ie don't paste your customer's PII into a prompt, etc...).

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#349

Earlier quoted context omitted.

Why not talk to the employee first?

This could be valid...but with something as powerful as ChatGPT, if it is providing huge benefits for employee productivity, they are unlikely to dump it based off a co-worker's suggestion. Also, unless managing security is within your roles and responsibilities, this approach would likely turn messy from an interpersonal aspect. Lastly, the security issue has already happened, so if this is truly a security concern,…

> if it is providing huge benefits for employee productivity

With this particular employee, using chatGPT has not increased his productivity or the quality of his work by any noticeable degree.

> I don't think the employee should be fired for this or anything

The problem isn't using the technology. The problem is sharing confidential information with an unapproved entity. That is specifically and clearly spelled out as a firing offense, for pretty obvious reasons.

Even if some people feel that it's an overly tight policy, it's a the stated policy and the company has every right to put and enforce whatever rules it wishes about the use of its own data.

Re: Employees are feeding sensitive data to ChatGPT, raising security fears

#350
post #93

Earlier quoted context omitted.

You are still transferring your business data to an external entity, but on top of it you pay for it. And if you think that there is no special code then you're wrong.

If you think random snippets of code are special you really don't understand the business you're writing code for. So no, your code is not special, and pasting code snippets is not transferring business data.

> pasting code snippets is not transferring business data.

It literally is exactly that. You don't think the code a business creates is "business data"?

Post reply on HN