Live data from Hacker News

Microsoft says bug causes Copilot to summarize confidential emails

bleepingcomputer.com

41–50 of 85 posts

Re: Microsoft says bug causes Copilot to summarize confidential emails

#42

> However, this ongoing incident has been tagged as an advisory, a flag commonly used to describe service issues typically involving limited scope or impact. How is having Copilot breach trust and privacy an “advisory”? Am I missing something?

If you inflate severity, people simply ignore incident warnings.

What's the actual action needed here by a security team? None. You can hate it or not care but the end of the day there's no remediation or imminent harm, just a potential issue with DLP policies. Don't make it look like a 0-day that they actually have to deal with.

Re: Microsoft says bug causes Copilot to summarize confidential emails

#44

Seems like every day there's another compelling reason to switch to Linux. Microsoft is doing truly incredible work this year!

Apple not doing much better, but from the other end. Microsoft releasing overly ambitious features with disastrous consequences. Apple releasing features so unambitious it's hard to remember they're there.

Don't forget Apple handwaving serious security issues of their devices - users still cannot even check if their devices are compromised and only thing Apple can do here is "lockdown mode" - which again, after compromise is likely useless anyway.

Re: Microsoft says bug causes Copilot to summarize confidential emails

#46
post #20

There are two issues I see here (besides the obvious “Why do we even let this happen in the first place?”): 1. What happened to all the data Copilot trained on that was confidential? How is that data separated and deleted from the model’s training? How can we be sure it’s gone? 2. This issue was found; unfortunately without a much better security posture from Microsoft, we have no way of knowing what issues are curre…

> "The Microsoft 365 Copilot 'work tab' Chat is summarizing email messages even though these email messages have a sensitivity label applied and a DLP policy is configured." I'd add (3) - a DLP policy is apparently ineffective at its purpose: monitoring data sharing between machines. ( https://learn.microsoft.com/en-us/purview/dlp-learn-about-dl... ). Directly from the DLP feature page: > DLP, with collection policie…

> a DLP policy is apparently ineffective at its purpose

/Offtopic

Yes, MSFT's DLP/software malfunctioned, but getting users to MANUALLY classify things as confidential is already an uphill battle. These are for the rare subset of people that are aware of and compliant with NDAs/Confidentiality Agreements!

Re: Microsoft says bug causes Copilot to summarize confidential emails

#47
post #20

There are two issues I see here (besides the obvious “Why do we even let this happen in the first place?”): 1. What happened to all the data Copilot trained on that was confidential? How is that data separated and deleted from the model’s training? How can we be sure it’s gone? 2. This issue was found; unfortunately without a much better security posture from Microsoft, we have no way of knowing what issues are curre…

All the vendors paraphrase user data, then use the paraphrased data for training. This is what their terms of service say. They have significant experience in this. Microsoft software since the 2014, for the most part, is also paraphrased from other people's code they find laying around online.

> Microsoft software since the 2014, for the most part, is also paraphrased from other people's code they find laying around online.

That was pretty funny and explains a lot.

I wish I could do more :(

Instead I always break things when I paraphrase code without the GeniusParaphrasingTool

Re: Microsoft says bug causes Copilot to summarize confidential emails

#50
post #35

Microsoft somehow sees a future where LLMs have access to everything in your screen. In that dystopia, adding "confidential" tags or prompt instructions to ignore some types of content is never going to be enough. If you don't want LLMs to exfiltrate content then they cannot have access to it, period.

Microsoft wants access to everything in your screen (as well as the contents of your personal files) and feeding that to an LLM just makes it easier for them to profit from that data
Post reply on HN