@baldur Interesting. Although, worth noting that neither of those examples had anything to do with their LLM tech... it was just bad normal server security practices.
@LouisIngenthron It has everything to do with OpenAI being a badly run company whose services you shouldn't trust and whose assurances aren't worth the bytes wasted to transmit them.
@baldur Agreed, but that's the status quo for every tech company. Users have made it abundantly clear that the prefer convenience over privacy, and the market has delivered that.
@LouisIngenthron This isn’t a privacy question. This is a “can they enforce the bare minimum software security practices required of a modern company” question and for OpenAI the answer is “no, no they can’t”.
@baldur You're right, I should have said "security" rather than "privacy". But still, after Equifax leaked my information to the entire internet, everything else pales in comparison. At this point, we essentially have to operate with the assumption that *nobody* we do business with online has done their due diligence in regard to security.
@LouisIngenthron Absolutely. It shouldn't be leaking private conversations, period. Doesn't matter what those conversations contain.
That this is happening again means there is something seriously wrong with the internal development processes at OpenAI. They keep having security issues
E.g. a leak of private conversations and payment details a year ago https://www.sfgate.com/tech/article/chatgpt-openai-payment-data-leak-17858969.php
Their fix was so shoddy that it was bypassed only days later https://www.securityweek.com/openai-patches-account-takeover-vulnerabilities-in-chatgpt/