5 ms·
Your second paragraph directly contradicts the first.
by valleyer 3mo ago
Your second paragraph directly contradicts the first.
- LoganDark 3mo agoSince you cannot fix information leakage from LLMs, you must remove the information so that it cannot be leaked. There is no contradiction there.
- valleyer 3mo agoRight, that's the fix. So saying that it's not fixable is incorrect.
- deleted 3mo ago[deleted]
- Gigachad 3mo agoThe LLM is not fixable. Deleting the LLM or crippling it to the point of being useless isn't fixing the bug.
- crote 3mo agoWhy not? If Ford puts a button in their car which blows it up when you press it, removing the button fixes the issue. If your LLM implementation is fundamentally insecure, you'll have a giant gaping security hole until you remove your LLM implementation. The alternative is arguing that having the LLM is worth routinely leaking all your code and secrets and occasionally giving complete strangers full access over your repos. Somehow, I think that's going to be a hard sell.
- jakewins 3mo agoRight, except the researchers are the ones that added the button, pressed it and now are upset at Ford, in your example. GitHub agents don’t have access to unrelated private repos by default, nor respond to public issue comments by default. The researchers manually configured the agent to have access to unrelated private repos and also process untrusted public comments.
- Austiiiiii 3mo agoThis is some very weirdly loaded language for a discussion about security. Applying the same RBAC controls that should be restricting all human requests in a system is not "crippling ... to the point of being useless." There isn't a world where granting a layer of the stack the ability to bypass hardcoded security limitations is a value add.
- deleted 3mo ago[deleted]
- antonvs 3mo agoIt’s not fixable by GitHub, which is what the original comment was asking about.
- rileymat2 3mo agoThere is a major contradiction depending on the definition of “support staff” and the role of the llm in the system which may need access to sensitive data or systems to perform its functions.
- darkvertex 3mo agoExactly. The system should run in a forcibly limited scope of the current repo only or add permissions for scope to include other org/user repos. It can't leak a private repo if it can't open it to begin with.
- antonvs 3mo agoThe point is that Github can’t fix it. It’s the user’s responsibility to not grant access to accounts that shouldn’t have access to the resources in question.