5 ms·
As others have already said, think about what you're doing when you use this. If you connect a not-selhosted LLM to this, you're effectively uploading chat mes
by echoangle 2y ago
As others have already said, think about what you're doing when you use this.
If you connect a not-selhosted LLM to this, you're effectively uploading chat message with other people to a third-party server. The people you chat with have an expectation of privacy so this would probably be illegal in many jurisdictions.
- tuananh 2y agoremoved. my bad.
- cirego 2y agoI believe echoangle’s concern is about the security and privacy of the LLM using the data, not the MCP server itself.
- tuananh 2y agoah right. my bad.
- cirego 2y agoSorry, I should have added my second thought. Your original comment about isolating MCP servers is also good! These are tools where the AI may tell you it’s doing one thing and then accidentally do another (I had an LLM tell me it would make a directory using mkdir but then called the shell command kdir (thankfully didn’t exist)). Sandboxing MCP servers is also important!
- greenavocado 2y ago> The people you chat with have an expectation of privacy so this would probably be illegal in many jurisdictions. Name one
- echoangle 2y agoGermany. You have a "allgemeines Persönlichkeitsrecht" (general personal rights?) that prevents other people from publishing information that's supposed to be private. Here's a case where someone published a facebook dm for example: https://openjur.de/u/636287.html https://openjur.de/u/636287.html
- greenavocado 2y agoSo here's the deal with German law on this topic - there's actually a big difference between sharing someone's DM and running LLM tools on social media conversations. The OLG Hamburg case from 2013 (case number 7 W 5/13) establishes that publishing private messages without permission violates your personality rights ("allgemeines Persönlichkeitsrecht"). While we don't have specific LLM court rulings yet, German data protection authorities have been addressing AI technologies under GDPR principles. The Bavarian Data Protection Authority (BayLDA) and the Hamburg Commissioner for Data Protection have both issued opinions that automated AI processing of personal communications requires explicit legal basis under Article 6 GDPR, unlike simple sharing which falls under personality rights law. The German Federal Commissioner for Data Protection (BfDI) has indicated that LLM processing would likely be evaluated based on purpose limitation, data minimization, and transparency requirements. In practice, this means LLM tools could legally process conversations if they implement proper anonymization techniques, provide clear user notices, and follow purpose limitations - conditions not required for the simpler act of sharing a message. The German courts distinguish between publishing content (governed by personality rights) and processing data (governed by data protection law), creating different standards for each activity. While the BGH (Federal Court) hasn't ruled specifically on LLMs, their decisions on automated data processing indicate they would likely allow such processing with appropriate safeguards, whereas unauthorized DM sharing remains almost always prohibited under personality rights jurisprudence regardless of technical implementation.
- echoangle 2y agoIt sounds like you agree with me that the posted tool would not be legal to use in Germany then? Or am I misreading this comment? Your initial „name one“ comment sounded like you didn’t believe there would be a jurisdiction where it is illegal.
- idiotsecant 2y agoI would argue that there is no expectation of privacy for messaging apps without end to end encryption. There is always the man in the middle listening.
- miroljub 2y agoMeta claims WhatsApp is end-to-end encrypted. It's up to you to trust Meta or not, but people who trust them do have an expectation of privacy.
- trelbutate 2y agoWhatsApp has end-to-end encryption
- joolss 2y agoYes, but it also has a back door so it is of no use.
- echoangle 2y agoLegally, there absolutely is. Because by law, the messaging app operator also can't just publish the stuff you write in a chat. Even some disclaimer in the terms of service probably wouldn't work if people would generally assume the chat to be private. And it also doesn't even matter because WhatsApp claims to be E2E-encrypted.
- hombre_fatal 2y agoThat's irrelevant here because the OP is running the LLM on one of the ends, so it's decrypted that same as when you're reading the chat convo yourself. It also misses the mark because you're talking about an eavesdropper intercepting messages and the OP is the receiver sharing the messages with a third party themself.
- dvrp 2y agoYour information is gone the moment you utter words. I can also copy and paste the messages people send me.
- echoangle 2y ago> I can also copy and paste the messages people send me. Sure you can, but the people can sue you if you paste it into something public. I don't know if you're making some deep philosophical comment but this is something people have been sued and lost for before.
- piltdownman 2y agoExcept basically all of Europe is one-party consent, and things like tech support call centres are already doing variants of this for years.
- echoangle 2y agoOne-party-consent only means you can legally record something, it doesn't necessarily mean that you're allowed to share it with (non-government) third parties later. It could be legal to record and use as evidence in court later, but that doesn't mean you're allowed to share it with some AI company.
- piltdownman 2y agoThey TOS utilisation of the data under 'Quality and Training purposes', with implied consent by engagement with the service in question - the breadth and application of which has never had a test case to my knowledge.