This thing is an absolute security nightmare. The concept of opening up the full context of your authenticated sessions in your email, financial, healthcare or other web sites to ChatGPT is downright reckless. Aside from personal harm, the way they are pushing this is going to cause large scale data breaches at companies that harbour sensitive information. I've been the one pushing against hard blocking AI tools at my org so far but this may have turned me around for OpenAI at least.
Yeah, I think there are profound security issues, but I think many folks dug into the prompt injection nightmare scenarios with the first round of “AI browsers”, so I didn’t belabor that here; I wanted to focus on what I felt was less covered.
It's bad too, yes. But not as bad, because MS is a profitable company with real enterprise products, so they have some reputation and compliance to maintain. SamAI is a deeply unprofitable company, mostly B2C oriented, with no other products to fall back to except for LLM. So it is more probably that Sam will be exploiting user data. But in general both are bad, that's why people need to use Firefox, but never actually do so, due to some incorrect misconception from decade ago.
>MS is a profitable company with real enterprise products, so they have some reputation and compliance to maintain.
On the contrary, it could be the case that Microsoft ritually sacrifices a dozen babies each day in their offices and it would still be used because office.
no I'm talking about the general concept of having ChatGPT passively able to read sensitive data / browser session state. Apart from the ever present risk they suck your data in for training, the threat of prompt injection or model inversion to steal secrets or execute transactions without your knowledge is extreme.
This thing is an absolute security nightmare. The concept of opening up the full context of your authenticated sessions in your email, financial, healthcare or other web sites to ChatGPT is downright reckless. Aside from personal harm, the way they are pushing this is going to cause large scale data breaches at companies that harbour sensitive information. I've been the one pushing against hard blocking AI tools at my org so far but this may have turned me around for OpenAI at least.