Zenny
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
rinze@infosec.pub to TechTakes@awful.systemsEnglish · 1 year ago

Slack by default using messages, files etc for building and training LLM models

mastodon.social

external-link
message-square
26
fedilink
67
external-link

Slack by default using messages, files etc for building and training LLM models

mastodon.social

rinze@infosec.pub to TechTakes@awful.systemsEnglish · 1 year ago
message-square
26
fedilink
Michael Simons (@rotnroll666@mastodon.social)
mastodon.social
external-link
Absolutely unbelievable but here we are. #Slack by default using messages, files etc for building and training #LLM models, enabled by default and opting out requires a manual email from the workspace owner. https://slack.com/intl/en-gb/trust/data-management/privacy-principles What a time to be alive in IT. 🤦‍♂️

cross-posted from: https://infosec.pub/post/12406642

Body of the toot:

Absolutely unbelievable but here we are. #Slack by default using messages, files etc for building and training #LLM models, enabled by default and opting out requires a manual email from the workspace owner.

https://slack.com/intl/en-gb/trust/data-management/privacy-principles

What a time to be alive in IT. 🤦‍♂️

  • Steve@awful.systems
    link
    fedilink
    English
    arrow-up
    12
    ·
    1 year ago

    What does this mean regarding their claims that data is encrypted at rest and in transit? https://slack.com/resources/why-use-slack/slacks-enterprise-security-features

    • flere-imsaho@awful.systems
      link
      fedilink
      English
      arrow-up
      22
      ·
      1 year ago
      • ‘at rest’ → we’re using filesystem encryption
      • ‘in transit’ → we’re using TLS

      neither is end-to-end encryption, the data is not private to the service provider.

    • cooljacob204@kbin.social
      link
      fedilink
      arrow-up
      13
      ·
      edit-2
      1 year ago

      That’s just a fancy way of saying they use tls, like the rest of the world.

      They decrypt it once it hits their servers and do whatever they want with it.

      • Steve@awful.systems
        link
        fedilink
        English
        arrow-up
        6
        ·
        1 year ago

        ah ok, so if it’s not at rest and it’s not in transit, what else is it?

        • sc_griffith@awful.systems
          link
          fedilink
          English
          arrow-up
          17
          ·
          1 year ago

          vibing

        • cooljacob204@kbin.social
          link
          fedilink
          arrow-up
          10
          ·
          edit-2
          1 year ago

          In their database lol. I’m sure whatever file storage they use is encrypted but doesn’t matter when you have the keys and can view all the data unencrypted.

          • Steve@awful.systems
            link
            fedilink
            English
            arrow-up
            5
            ·
            1 year ago

            is it that easy to sell this shit to the average CTO?

            • cooljacob204@kbin.social
              link
              fedilink
              arrow-up
              6
              ·
              1 year ago

              Unfortunately corporate security is a joke in many aspects.

            • froztbyte@awful.systems
              link
              fedilink
              English
              arrow-up
              4
              ·
              1 year ago

              there is a type of leader out there that takes gartner magic quadrants seriously and makes decisions from that information

              and they’re not rare.

              • Steve@awful.systems
                link
                fedilink
                English
                arrow-up
                4
                ·
                edit-2
                1 year ago

                I’ve done UX on a few B2B SaaS things and the U meant CTO in most (sanctioned) cases

            • Evotech@lemmy.world
              link
              fedilink
              English
              arrow-up
              3
              ·
              1 year ago

              As long as you can check the boxes to an auditor.

        • self@awful.systems
          link
          fedilink
          English
          arrow-up
          8
          ·
          edit-2
          1 year ago

          you see, your data can never be at rest if they’re constantly using it to train LLM models and exploiting it for other marketing purposes

          …god this is stupid enough that I’m very sure I’m going to hear it in earnest from some AI shithead next time one of our threads hits all

          • Steve@awful.systems
            link
            fedilink
            English
            arrow-up
            9
            ·
            1 year ago

            at rest, in transit, in plunder

        • flere-imsaho@awful.systems
          link
          fedilink
          English
          arrow-up
          7
          ·
          1 year ago

          …in perpetual motion

          • Steve@awful.systems
            link
            fedilink
            English
            arrow-up
            8
            ·
            1 year ago

            they use it for their matrix screensavers

        • froztbyte@awful.systems
          link
          fedilink
          English
          arrow-up
          4
          ·
          1 year ago

          out jogging: that’s you keep data fit. gotta keep it moving. unfit data quickly starts falling into bitrot. that’s what you get by buying a slack subscription - crosstrainers for your data!

          trade secret tho, don’t tell anyone

TechTakes@awful.systems

techtakes@awful.systems

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !techtakes@awful.systems

Big brain tech dude got yet another clueless take over at HackerNews etc? Here’s the place to vent. Orange site, VC foolishness, all welcome.

For actually-good tech, you want our NotAwfulTech community

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 33 users / day
  • 277 users / week
  • 895 users / month
  • 143 users / 6 months
  • 1 local subscriber
  • 1.01K subscribers
  • 294 Posts
  • 6.11K Comments
  • Modlog
  • mods:
  • David Gerard@awful.systems
  • UI: unknown version
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org