Which is why a private option is so critical. To not fight against human nature, means providing an ability to use the tool in a safe way.
Which is why a private option is so critical. To not fight against human nature, means providing an ability to use the tool in a safe way.
Unless your company really has nothing to hide, it's easy to accidentally dump a company secret or an API key in a chat session. Of course if everyone is aware of this and constantly careful then you may be OK.
If you're copy pasting API keys or such into ANYTHING, you probably shouldn't be a programmer to begin with.
It's like people who use root account key/secret credentials in their codebase. It's not AWSs fault you got a large bill or got hacked, its because you're dumb.
And if you think that there is no special code then you're wrong.
Lots of code expresses buisness strategy that is a competitive advantage/ sensitive.
My org has done a risk assessment and accepted the risk of using such tools; arguing there is no risk is short sighted.
It literally is exactly that. You don't think the code a business creates is "business data"?
Not my place legally or ethically to share code with 3rd parties that I've been paid to read and write.
Your code is not special, but customers data may be. Also, some companies needs to comply to various certifications, and proven leak of source code that was put into some third party tool may be a reason to revoke such certification. Which can cause a serious financial harm to a given company, as it can lead to ex. losing government clients.
This is just the tip of the iceberg.
Uploading code to ChatGPT can be done by trainees.
Productivity isn't everything.
FWIW I don't think the employee should be fired for this or anything, if anything a company could embrace these new technological advances and provide training on using ChatGPT in a more secure manner(ie don't paste your customer's PII into a prompt, etc...).
With this particular employee, using chatGPT has not increased his productivity or the quality of his work by any noticeable degree.
> I don't think the employee should be fired for this or anything
The problem isn't using the technology. The problem is sharing confidential information with an unapproved entity. That is specifically and clearly spelled out as a firing offense, for pretty obvious reasons.
Even if some people feel that it's an overly tight policy, it's a the stated policy and the company has every right to put and enforce whatever rules it wishes about the use of its own data.
Uh, why can't you tell people not to use it...? If security is that important for your company, of course you can tell your employees which tools to use.
A fun fact: in many areas of TSMC, smart phones are banned. No one says "you can't just tell people not to use smart phones."
This does not surprise me at all. What I want to know is how they enforce it.
Unless they have something better than "fear of somebody seeing you using the smartphone", it isn't getting enforced. If they do have something better I want to know what.
No, I'm not joking. One of my high-school classmates works as R&D there. They ask you to pass through a metal detector gate, take away your phone if found, then give your a company phone for emergency call only. It's that strict (at least for R&D. Probably not for management and others).
This is what I'm interested in.
I get it, the guys in bunny suits will probably tolerate being groped and wanded every workday for the rest of their career. I have a hard time beliving the scientific staff and executives tolerate that.
They put a special sticker on all of your cameras and inspect if it is still there on the exit.
2.) Of course, you can tell people not to use it. Unlike people at SV companies apparently, people in government and government contractors accept restrictions like not having phones in secure labs all the time. Start firing or even prosecuting people and people will discover very quickly they don't really need some tool.
And, yes, private versions of this sort of thing helps a lot.