“ChatGPT is leaking passwords from private conversations of its users, Ars reader says | Ars Technica”
This is the third major security incident at OpenAI. https://arstechnica.com/security/2024/01/ars-reader-reports-chatgpt-is-sending-him-conversations-from-unrelated-ai-users/
@baldur So, the tool specifically tells people not to give it private data, then they give it private data, and then we blame the tool for revealing that private data?
@LouisIngenthron Absolutely. It shouldn't be leaking private conversations, period. Doesn't matter what those conversations contain.
That this is happening again means there is something seriously wrong with the internal development processes at OpenAI. They keep having security issues
E.g. a leak of private conversations and payment details a year ago https://www.sfgate.com/tech/article/chatgpt-openai-payment-data-leak-17858969.php
Their fix was so shoddy that it was bypassed only days later https://www.securityweek.com/openai-patches-account-takeover-vulnerabilities-in-chatgpt/
@baldur Interesting. Although, worth noting that neither of those examples had anything to do with their LLM tech... it was just bad normal server security practices.
@baldur You're right, I should have said "security" rather than "privacy". But still, after Equifax leaked my information to the entire internet, everything else pales in comparison. At this point, we essentially have to operate with the assumption that *nobody* we do business with online has done their due diligence in regard to security.
@LouisIngenthron This isn’t a privacy question. This is a “can they enforce the bare minimum software security practices required of a modern company” question and for OpenAI the answer is “no, no they can’t”.