3 ms·
I've been following XP1 and I don't think they have nefarious goals with this. The extension is even open source (though not sure if the proxy is). Check it out
by deet 4y ago
I've been following XP1 and I don't think they have nefarious goals with this. The extension is even open source (though not sure if the proxy is). Check it out here: https://github.com/dust-tt/dust/tree/main/xp1 https://github.com/dust-tt/dust/tree/main/xp1
I'm working on a somewhat related product (except bringing this assistant capability to all apps on your computer, all browsers, and using mostly on-device ML...waitlist in my profile in case you're curious)
What we've discussed internally is having two modes for the cases where we do need network connection:
1) A turn-key, use-our-OpenAI/HuggingFace/whatever proxy that doesn't store anything, just adds our token and pays for it on your behalf
2) Bring-your-own key for each service
The fact is that most users who just want to use these kinds of productivity tools might not have their own OpenAI/Azure/etc account, so offering option 1 and even defaulting to it is right for most end-users.
I think XP1 is making the right call here with this default, though offering #2 would be nice!
(edit: added Github link to XP1)
- yunwal 4y agoDoes the extension being open-source actually help here? I don't have time to look through the whole thing, but essentially it sounds like I can verify for myself that all of my requests are being sent to dust for them to... store for debugging purposes and not make any money while paying everyone's OpenAI fees? Doesn't seem believable to me.
- deet 4y agoWell, you can verify if it is sending all data all the time, or only when you invoke it for a request. I believe most people are uncomfortable with all data being sent all the time, but more okay with sending some data in the exact cases they choose, since they have control. So I'd argue that the extension being open source helps a lot. You're right that it doesn't guarantee anything for how the server is behaving in the case that you do invoke it though. For that we'd need either transparency into that source code and server operations, or, more likely, a strong privacy policy and maybe SOC2 or other certifications. I believe the reason XP1 is subsidizing this right now is to grow their user base to attract investors, and as they develop their LLM platform, and then probably charge for business users down the road, but they don't seem to state that intention as clearly as they could.
- yunwal 4y agoI mean, you can verify the requests your browser is sending off whether the extension is open-source or not (by using developer tools in your browser or proxying the requests). So I don't think being open-source helps all that much really. I still don't think it's appropriate for them to be using responding to emails as an example in their docs, especially without a warning. If someone went around sharing my private conversations with another person without telling me, I'd lose trust in that person. They'll get away with it because some people don't see sharing data with a software company as the same thing, and it's tough to know when it's happening, but nevertheless, it's sketchy.