4 ms·
Does OpenAI also have access to all github repos via partnership with microsoft?
by faangguyindia 3mo ago
Does OpenAI also have access to all github repos via partnership with microsoft?
- jpollock 3mo agoIt would be _extremely_ surprising if private repos were available via that contract. Corporations wouldn't use GitHub at all if anyone other than those given direct access had read/copy permission.
- t_gamer_kle 3mo agoThey were caught stealing Apple trade secrets, dude. Nothing is beneath them.
- tyre 3mo agoNothing is beneath Altman, maybe, but Satya isn’t that dumb. MSFT cares about OAI but giving access to private data and trade secrets voluntarily would be catastrophic for them. Doesn’t feel like the type of mistake Satya would make.
- theplumber 3mo agoThe AI systems ingest tons of copyrighted data and that is stealing/theft(or so we peasants were told). It’s not like they don’t know they are doing. It looks like MSFT doesnt care that much either.
- faangguyindia 3mo agoHow did book publishers figure out ai stole from them? Can people use a similar way to figure out if their private repos have become part of the training corpus?
- theplumber 3mo agoWell let’s just say it’s not that hard to see that: https://variety.com/2025/digital/news/studio-ghibli-openai-sora2-japanese-trade-group-coda-letter-1236568751/ https://variety.com/2025/digital/news/studio-ghibli-openai-s... Note that everything GPT knows (I.e news etc) is actually from real news websites that never gave GPT rights to use their content. In the pure “American way” OpenAI closed some deals when threatened with lawsuits but of course unless you have the political connections or financials to fight trillion dollars companies stop worrying about your private repo. If it’s in the “cloud” it’s already public just not for everybody.
- mijowi 3mo agoI could see there being different rules for enterprise accounts.
- processunknown 3mo agoIt wouldnt be _that_ surprising since they committed widespread copyright violations building the models, plus the recent Apple IP theft...
- creato 3mo agoDisclosing private repos against the owner's intent is a much more immediate and significant business risk than violating the license of open source code. Maybe that shouldn't be the case, but it is.
- MattGaiser 3mo agoThis speaks to OpenAI's approach to things. But it doesn't speak to Microsoft and Microsoft would need to provide the access.
- faangguyindia 3mo agothis might be relevant about microsoft. Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway: https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government https://www.propublica.org/article/microsoft-cloud-fedramp-c...
- culi 3mo agoAbsolutely not. That would be an absurd violation. If you have Copilot enabled then they can use your interaction data for training but you can turn that off as well
- taywrobel 3mo agoGitHub Copilot engineer here working on identity, safety, and privacy - no, even Microsoft doesn’t have access to all GitHub repos. As years have passed since the acquisition “company” delineations have blurred a bit, but Microsoft employees still need to go through a separate onboarding process to access any GitHub company resources (internal repositories, telemetry, documentation, etc.), and then we have an additional layer of entitlements to gate and audit access to any sensitive data, including user data. Very few employees within GitHub proper even have access to view private repositories, and in the rare cases where that’s done for legal or safety reasons the repository owner is notified. There are currently no OpenAI employees with access to GitHub systems, so there’s about 4 layers of protection in place to prevent private repositories access. We do genuinely take user data protection and privacy seriously.
- anonymousiam 3mo agoHow do you define "access" here? Microsoft has demonstrated that it can delete any GitHub repo at will. Maybe there's some shell entity between corporate "Microsoft" and "GitHub" that's doing the dirty deeds without attribution...
- taywrobel 3mo agoAccess meaning read, modify, delete, etc. Pretty standard definition, unless you know of a different meaning of access I’m not privy to. Microsoft can certainly request that we perform actions against repositories, as can governments, customers, random people on the street, etc. Whether action is taken in those cases is a question for lawyers to fight over, but we have the engineering guardrails in place to require it to be an intentional, audited action. I appreciate the spicy question tho, even if misguided!
- lstodd 3mo agoCan you state with absolute сertainity that no entity outside your github unit can exfiltrate data at will? This is not spicy, this is basic infosec.
- deleted 3mo ago[deleted]