Microsoft hits Alt+F4 on internal ChatGPT access over security jitters, irony ensues
(2023/11/10)
- Reference: 1699626793
- News link: https://www.theregister.co.uk/2023/11/10/microsoft_blocks_chatgpt/
- Source link:
In what would be delicious irony, Microsoft is reported to have temporarily pulled internal access to OpenAI's ChatGPT over security fears.
Not only has Microsoft invested $13 billion into OpenAI, it is weaving the company's generative AI products into vast swathes of the Windows and Office software portfolio.
Employees at the software biz have access to the GenAI tool internally, yet for about an hour yesterday, staff trying to access ChatGPT on company devices were instead rerouted to a notification that the website was blocked by Microsoft.
[1]
"Due to security and data concerns a number of AI tools are no longer available for employees to use," Microsoft stated on the internal website, as revealed by [2]CNBC .
[3]
[4]
The risk of feeding sensitive data to LLMs, including ChatGPT, was highlighted earlier this year by the UK's [5]GCHQ spy agency. "Do loose prompts sink ships?" Yes, the report concluded. The thinking is that LLMs can ingest sensitive queries and incorporate them into future versions in some way.
In April, [6]Samsung temporarily banned staff from using ChatGPT after classified information reportedly leaked to the service, including in-development semiconductor information. The ban was lifted after three weeks.
[7]Child psychiatrist jailed after using AI to make pornographic deep-fakes of kids
[8]DDoS-like attack brought down OpenAI this week, not just its purported popularity
[9]What to do with a cloud intrusion toolkit in 2023? Slap a chat assistant on it, duh
[10]FTC interrupts Copyright Office probe to flip out over potential AI fraud, abuse
JPMorgan Chase, Verizon, and Apple also blocked internal use.
We asked Microsoft to comment and a spokesperson told us they were looking into our query. The Windows maker told the [11]Wall Street Journal that the internal restriction was made in error.
[12]
In a bid to turn negative press into something more useful, Microsoft added that it positively encourages internal and customer use of Bing Chat Enterprise, which uses ChatGPT Enterprise, as it offers more robust privacy protections.
We also asked OpenAI to comment.
In other related news this week, [13]OpenAI was brought down by a suspected distributed denial of services (DDoS) attack . Signs that trouble was brewing were spotted on November 7 when the service was interrupted for more than two hours. The following day, OpenAI reported a major outage, and yesterday normal service resumed.
[14]
"We are dealing with periodic outages due to an abnormal traffic pattern reflective of a DDoS attack," OpenAI said yesterday.
Criminals linked to Russia today [15]claimed responsibility , though this is unconfirmed at the time of writing. ®
Get our [16]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZU5hszeGOAu29wug1kp-fwAAAAk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.cnbc.com/2023/11/09/microsoft-restricts-employee-access-to-openais-chatgpt.html
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZU5hszeGOAu29wug1kp-fwAAAAk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZU5hszeGOAu29wug1kp-fwAAAAk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2023/03/15/gchq_warns_against_sensitive_corporate/
[6] https://www.theregister.com/2023/04/06/samsung_reportedly_leaked_its_own/
[7] https://www.theregister.com/2023/11/10/child_psychiatrist_sentenced_ai/
[8] https://www.theregister.com/2023/11/09/chatgpt_ddos_openai/
[9] https://www.theregister.com/2023/11/09/predatorai_infostealer_chatgpt/
[10] https://www.theregister.com/2023/11/09/ftc_ai_regulation/
[11] https://www.wsj.com/tech/microsoft-temporarily-blocked-internal-access-to-chatgpt-citing-data-concerns-c1ca475d
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZU5hszeGOAu29wug1kp-fwAAAAk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://www.theregister.com/2023/11/09/chatgpt_ddos_openai/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZU5hszeGOAu29wug1kp-fwAAAAk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://www.bloomberg.com/news/articles/2023-11-09/russia-linked-hackers-claim-credit-for-openai-outage-this-week
[16] https://whitepapers.theregister.com/
Not only has Microsoft invested $13 billion into OpenAI, it is weaving the company's generative AI products into vast swathes of the Windows and Office software portfolio.
Employees at the software biz have access to the GenAI tool internally, yet for about an hour yesterday, staff trying to access ChatGPT on company devices were instead rerouted to a notification that the website was blocked by Microsoft.
[1]
"Due to security and data concerns a number of AI tools are no longer available for employees to use," Microsoft stated on the internal website, as revealed by [2]CNBC .
[3]
[4]
The risk of feeding sensitive data to LLMs, including ChatGPT, was highlighted earlier this year by the UK's [5]GCHQ spy agency. "Do loose prompts sink ships?" Yes, the report concluded. The thinking is that LLMs can ingest sensitive queries and incorporate them into future versions in some way.
In April, [6]Samsung temporarily banned staff from using ChatGPT after classified information reportedly leaked to the service, including in-development semiconductor information. The ban was lifted after three weeks.
[7]Child psychiatrist jailed after using AI to make pornographic deep-fakes of kids
[8]DDoS-like attack brought down OpenAI this week, not just its purported popularity
[9]What to do with a cloud intrusion toolkit in 2023? Slap a chat assistant on it, duh
[10]FTC interrupts Copyright Office probe to flip out over potential AI fraud, abuse
JPMorgan Chase, Verizon, and Apple also blocked internal use.
We asked Microsoft to comment and a spokesperson told us they were looking into our query. The Windows maker told the [11]Wall Street Journal that the internal restriction was made in error.
[12]
In a bid to turn negative press into something more useful, Microsoft added that it positively encourages internal and customer use of Bing Chat Enterprise, which uses ChatGPT Enterprise, as it offers more robust privacy protections.
We also asked OpenAI to comment.
In other related news this week, [13]OpenAI was brought down by a suspected distributed denial of services (DDoS) attack . Signs that trouble was brewing were spotted on November 7 when the service was interrupted for more than two hours. The following day, OpenAI reported a major outage, and yesterday normal service resumed.
[14]
"We are dealing with periodic outages due to an abnormal traffic pattern reflective of a DDoS attack," OpenAI said yesterday.
Criminals linked to Russia today [15]claimed responsibility , though this is unconfirmed at the time of writing. ®
Get our [16]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZU5hszeGOAu29wug1kp-fwAAAAk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.cnbc.com/2023/11/09/microsoft-restricts-employee-access-to-openais-chatgpt.html
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZU5hszeGOAu29wug1kp-fwAAAAk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZU5hszeGOAu29wug1kp-fwAAAAk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2023/03/15/gchq_warns_against_sensitive_corporate/
[6] https://www.theregister.com/2023/04/06/samsung_reportedly_leaked_its_own/
[7] https://www.theregister.com/2023/11/10/child_psychiatrist_sentenced_ai/
[8] https://www.theregister.com/2023/11/09/chatgpt_ddos_openai/
[9] https://www.theregister.com/2023/11/09/predatorai_infostealer_chatgpt/
[10] https://www.theregister.com/2023/11/09/ftc_ai_regulation/
[11] https://www.wsj.com/tech/microsoft-temporarily-blocked-internal-access-to-chatgpt-citing-data-concerns-c1ca475d
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZU5hszeGOAu29wug1kp-fwAAAAk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://www.theregister.com/2023/11/09/chatgpt_ddos_openai/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZU5hszeGOAu29wug1kp-fwAAAAk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://www.bloomberg.com/news/articles/2023-11-09/russia-linked-hackers-claim-credit-for-openai-outage-this-week
[16] https://whitepapers.theregister.com/
Doctor Syntax
Microsoft to customers: Do as I say, not as how I do.
Was literally talking about so-called "AI" the other day to a teacher.
They want to use Bing Copilot on their 365 account, because they "use it on their personal account".
Dug into it, it requires complete access to your 365 account. Not gonna happen.
Triggered a discussion, but the old-fogies in the room including myself were quite adamant about this:
- If it is given access to data, we have to account for how, when and why we are processing that data with AI, and tell people whose data it is.
We can't just let it run around a 365 account which has access to all sorts of privileged data and then hand-wave about how we're processing it or what it can or can't do with that data. We have to assume it is actually accessing it all... because it can. We have to assume it's using all the data when processing... because it can. And without access to the source code or knowing how it works and what it does with that data, we can't take responsibility for it.
Now imagine when things pop up like "How did you make that hiring decision? What data on my client did you have and how was that processed and by whom?" and now you a potential timebomb on your hands.
Sorry, but it's very simple - don't give AI any access, data or capability that you don't want it to have. The same as any human user on such a system.
The old fogies and the techs realised that, within seconds of receiving the request, but the other people were still on the "Yes, but it's Microsoft" and "Other places are doing it" etc. bandwagons.