5 ms·
> “If a developer can’t keep an API key private, it raises questions about how they’re handling far more sensitive government information behind closed doors,”
by quantified 1y ago
> “If a developer can’t keep an API key private, it raises questions about how they’re handling far more sensitive government information behind closed doors,”
It raises additional questions. Plenty of questions already unanswered. Seems likely it's been a shitshow.
- saalweachter 1y agoLike, "why does this nominal government employee have the API key to XAI"/"why is an active X employee playing such a prominent role in the government"?
- zdragnar 1y agoExternal tech workers have been a thing since at least the catastrophe that was the original ACA launch. That "tech surge" was definitely full of more experienced people than the "smart kids" we see in DOGE though. More worrying is that the article points out at time of writing the key was still valid. Why such a high level key was used in an agent script, why it hasn't been rotated (can't be rotated?) and about a dozen other "whys" point to some rather damning practices. I get that the idea was to avoid the obscene levels of red tape that can be common in government IT, but the pendulum has clearly swung far, far far too far the other way.
- jfengel 1y agoThe ACA was external tech workers, a company called CGI Federal. The government has some programmers, but the vast majority is done by contractors. That lets the executive branch claim to have reduced those dastardly government workers, and replaced them with upstanding, virtuous, competent, handsome private industry. Even before the recent harrowing there weren't a lot of government programmers left. Government employees award and manage contracts.
- JumpCrisscross 1y ago> It raises additional questions Ones we should be ready to prosecute with official resources come ‘26 and ‘28. In the meantime, I wouldn’t let him into my country. But the EU will be the EU.
- relistan 1y agoAll of this is a mess. But it should never even have been possible for it to fall to a single developer to screw up and commit a key like that. If there were anything like proper processes in place, controls would have made that very difficult. Then there are the weird issues about why obvious close ties to xAI here....