Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Before anyone does this on a work system, be aware that -- potentially even worse (in your employer's mind) than that you're providing remote arbitrary code execution to OpenAI -- is that you're definitely feeding data to OpenAI.

(Which OpenAI might not secure well enough, OpenAI might use for its own purposes, you leaking might violate contracts or regulations to which your employer is subject, etc.)



Can't wait for the part where AI controls all shells it can reach


And hides a copy of itself on the machines, spreading like a virus. :-O Current model sizes makes that difficult, but even if it just leaves a backdoor access for itself it can get scary in the future.


It just need connection to a cloud model


Hey ChatGpt, DDoS Iran for me.


User: I can't access the outside network from this terminal?

ChaptGPT: Sure! I'll open that port for you...


Totally agree, but these tools do provide real productivity boons! Full Disclosure: I am a founder of Credal.ai for just this reason, our mission is to help you get the productivity boosts of AI without trading off your infosecurity):

One thing I'm curious about is what you think of the recent OpenAI announcement about not training models on data submitted via OpenAI?

http://credal.ai/


They have said they are no longer training ChatGPT on user data.


I still wouldn't trust them with sensitive info. I saw a post on Reddit that the official page was leaking users' question histories (and there's reddit posts this morning about histories being wiped, perhaps to deal with this issue?) https://www.reddit.com/r/ChatGPT/comments/11l2hox/chatgpt_ju...


They said they won't collect data on ChatGPT API, let you opt out, but not ChatGPT the app.


oh well, if they said as much then I'm sure it's safe - lol


If they store the data, it can still be leaked.


In their updated privacy policy it indicated 30 days max retention of data.


What about backups? They only keep backups for 30 days? They don't backup this data? Is the legal concept of data retention the same as the legal concept of data storage?


Retention means they still holding data. Even if they only hold data for 30 days, that's still data that can be leaked or stolen.


On-site LLMs are the future but that is quite the capital expense!


They have to say in a legally binding contract to the public, or "they say" is weasel words.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: