That said, I was very confused at the word "unapproved" in the title, wondering who was "approving" them. The actual tweet uses "unreleased", which makes much more sense.
That said, I was very confused at the word "unapproved" in the title, wondering who was "approving" them. The actual tweet uses "unreleased", which makes much more sense.
Pretty much any business who accept user-generated plugins follow this same process, so I struggle to find much nefarious there (unlike some others in this discussion thread).
What is silly is that the server will gladly execute plugins for a "normal" end user that aren't in the correct state. That's a classic application security fail.
Can you explain what the security issue is here? The normal user modifies requests, chooses to use an unreleased plugin, then...?
Pray tell what a client side only tool that you have to modify requests to access will do that is dangerous?
Plugins don’t just “return data” they perform arbitrary actions. [0] “Unreleased” presumably in some cases means “not adequately tested” regarding the instructions to the model as to when and how to use the API that the plugin wraps. An ubreleased plugin is effectively untested code wrapping an exposed, possibly read/write, API.
[0] examples given on the OpenAI plugins docs website include “booking a flight, ordering food, etc.”
You modify the request made, to display unverified plugins.
You turn one on (at random ? You just see a plugin that tells you they're going to invest all of your money in an ETF and give you 300%, and you just click it ?)
You give that plugin everything it needs to interact with the things that matter. You let it login to your bank account and your Robinhood account.
Then you get surprised when "untested" or harmful code gets executed when you run the hidden plugin ?
Do you blame the person who gave you a knife and told you to only use it on vegetables when you cut yourself trying to cut a slab of metal ?
(Of course, to be fair, the basic model OpenAI uses creates exposure that doesn't even go through OpenAI, which would worry me from the start, and really dedicated API users could just implement ReAct and their own actions against any API, but that's higher effort and not particularly facilitated by OpenAI.)
No, we know that the unlisted ones that are accessible are the ones that weren’t supposed to be publicly published that are in limited testing.
> No possibility of the being internal testing tracks, or of having no testing tracks and OpenAI just telling you to handle it on your own for testing (by not publishing it, for example)
I mean, no, because OpenAI publishes what the testing setup is, so we know that the case isn’t “no testing tracks and OpenAI just telling you to handle it on your own for testing (by not publishing it)”.
And its not clear how you could test it without using the OpenAI published approach; since we don’t know whether OpenAI tunes on the information, or references it in the hidden prompt somehow. Only in that latter case could an external party even in theory test before exposing the plugin, and that would require detailed information that OpenAI hasn’t provided in its developer information.
The plugins aren't code, they're a pointer to a public document with a link to your companies API.
Effectively, they are—they are API pointers, sure, but also instructions to the AI model on how and when to use the API. That part is, effectively, code, and in an unreleased plugin its code that likely isn’t fully tested to the plugib supplier’s satisfaction to be ready for use outside of the limited set of testers.
That’s the whole point of the limited test process, to allow getting the instructions right before exposingthe plugin to general use.
The user who deliberately hacks their way into using a test plugin and sees bad results is going to see bad results but that's not a security problem.
Yeah, the basic model (because it involves publicly publishing untested instructions, which amount to code) is a security problem for the plugin supplier.
OpenAI not doing server-side validation of the closed-test-groups that it advertises for unreleased plugins magnifies the risk, but eliminating it wouldn't eliminate the fundamental problem entirely.
(The OpenAI failure here isn't failing the end user, its failing what they represent to the plugin supplier.)
This breaks that confidentiality.
I suspect they probably just don't care. They are working on a very very well done language model, not trying to protect customers data. In anything customers data is their data. And having more of it in any form is better for them.
If anything it's probably a security issue that people are using ChatGPT as it is. And certainly a security issue if you are using ChatGPT behind firewalls or VPNs.
Pasting in random proprietary code samples asking for help fixing it, is WAY more of a security issue then some terrible API authentication that they clearly don't care about.
holy shit our bar is low.
As long as you don’t care if it’s secure and you just want to hide something visibly!
My guess is OpenAI does not really care if people use these.
Well it is called artificial intelligence. But in all seriousness, they no doubt have brilliant people working there. I don’t however consider them to be a tech company, at least in the traditional sense. Scientific? Absolutely, but their nonprofit roots are really showing through.