Showing posts with label chatgpt. Show all posts
Showing posts with label chatgpt. Show all posts

2023-08-25

Resistance is futile

 

Starship of James T. Kirk, Jean-Luc Picard's predecessor.
Image from Pixabay

“We are the Borg. You will be assimilated. Resistance is futile.” These three sentences gave the crew of the USS Enterprise starship, led by Captain Jean-Luc Picard, a lot of headaches. No, don't drop out now if you don't like Star Trek! As so often, my blog is ultimately about something completely different.

The Borg are a collective life form, consisting of many beings who share one consciousness and therefore no longer have a will or personality of their own. They move through the universe and violently assimilate everyone who can contribute to their pursuit of perfection into their collective. They are very powerful; that is why they tell you right away that it is useless to oppose them. The Borg grow in power as the biological and technological characteristics of their subjects are added to the collective. All Borg are equipped with various technological implants - they must of course be recognizable to the viewer. When they have nothing to do, the Borg are stowed away in a regeneration alcove. While the body is in a kind of sleep, the brain is used for collective tasks.

That's all nice on TV, but in real life living in such a society would be horrible. Although sometimes I wish certain people had a little more collective intelligence and decency. But yes, certainly in Western society we value individuality above everything else, and that includes differences in intelligence and behavior. To some extent that diversity is great; if it becomes willfully extreme, it can hinder a pleasant society.

Artificial intelligence (AI) is on the rise. As a kind of consumer version of AI, ChatGPT has quickly established itself in our society. Many people understand that such a tool can greatly facilitate their lives. Just think of pupils and students, who eagerly use it – often to the sorrow of their teachers. Incidentally, AI detection tools are also being developed, enabling them to check whether someone is submitting work that originated from biological or artificial intelligence. ChatGPT is a 'large language model', which I find difficult to understand. But things got a little clearer earlier this week when a colleague asked me what the term is for a particular phenomenon. I didn’t know that off the top of my head either, so I consulted Google, which also yielded nothing. A language model is much better in understanding what you actually mean to say than a search engine, and ChatGPT came up with the right term.

AI is like dynamite: invented with the best of intentions, often used maliciously. We still got the Nobel Prizes from that. ChatGPT and its ilk follow the same path. You can ask them to look for a security hole so you can close it, but you can also use that to break in. And so lately we often get asked whether we should limit the use of ChatGPT in our organization.

Maybe you shouldn't put such a question to an information security officer. We will perform a risk analysis and, by definition, look at it from the starting point: what could go wrong? Well, I assure you AI is going to come out of that as a major threat. Subsequently, you have to do something with all those identified risks. You may be able to mitigate some of them, and management may accept other risks. With all that, however, we are looking into the bad side, while AI can also be a blessing. I don't want to be the one who stops the introduction of the steam train because it can travel so terribly fast.

A wise long-retired colleague used to say: “A measure without control is no measure.” I may have control over which websites you are allowed to visit with your work laptop and keep you away from ChatGPT, but I can't prevent you from using private devices to do so. At least, not technically; we have all sorts of rules for this from an organizational point of view. And then I can only hope that you know them and that you stick to them.

We need a policy for applying artificial intelligence to our work. From a security perspective, the leakage of information must be taken into account if (too) specific questions are asked of an AI tool. By the way, you can just as easily leak information via search engines. Perhaps AI is not so special for information security officers after all. In any case, it is pointless to resist it: it is there and it will not go away. But it is important that we know what is real and what comes from the collective brain of the computer.

 

And in the big bad world…

 

2023-01-27

Privacy chat - the solution

 

Image from Pixabay

Last week’s Security (b)log came with a challenge: can you spot which paragraphs were written by me, and which by ChatGPT? Well, the blue paragraphs are artificially intelligent, the black ones are mine.

Two weeks ago I read with fascination the (internally published) story of fellow blogger Guido about ChatGPT, the artificially intelligent chatbot that anyone can use. Until now I knew chatbots mainly from companies that want to prevent you from calling them, and instead offer you to exchange thoughts with their always cheerful canned employee via the keyboard. But if I do have a question for a company at all, it rarely falls into a category that Clippy's grandchildren can handle; otherwise I would have found the answer myself in the FAQ.

Do you remember Professor Barnabas's computer from the Spike and Suzy (UK)/ Willy and Wanda (US) comics? It spat out a card with the answer to the question asked. I wanted to experience for myself how this works in practice. January 28 is European Privacy Day, and I promised the privacy colleagues in my team that I would dedicate a blog to it. As an experiment, I outsourced its the writing for once. However, not entirely: the following paragraphs are partly written by ChatGPT, partly by me (in the ChatGPT pieces I only intervened grammatically here and there). Can you recognize who wrote which paragraph? I will give the solution next week.

As a European, I am proud of the European Union and its role in protecting our personal data. With the introduction of the General Data Protection Regulation (GDPR) in 2018, the EU has introduced one of the strictest privacy laws in the world. The GDPR gives consumers more control over their own data and makes companies responsible for protecting those data.

While the GDPR is an important step forward, the battle for our privacy will never end. Technological developments are going faster than ever and with the rise of artificial intelligence and the internet of things, there are new challenges we face. Businesses and governments must continue to adapt to the changing landscape to protect our data.

Let's zoom in on artificial intelligence as a threat to our privacy. Sometimes you can benefit from a company or government agency not knowing everything about you; in countries with an oppressive regime this applies even more than in our western democracy. As long as only people and traditional information systems are involved, things are sometimes overlooked. But what if artificial intelligence were able to link all kinds of sources together in an unprecedented way and make connections that you, as a human being, or a 'dumb' computer, would never have thought of? Is that still fair? Aren't we entitled to a lucky break from time to time, because 'the system' overlooked something?

It is not only the responsibility of companies and governments to protect our privacy. As consumers, we also have a role to play. We need to be aware of our own data and how we share it. We must ask questions about how companies use our data and we must oppose inappropriate practices. Let's work together to protect our privacy so we can feel safe and protected in our digital world.

Another important step is the use of privacy-enhancing technologies, such as Virtual Private Networks (VPNs) and encryption tools. These can help protect our online communications and protect our personal information from being intercepted by hackers or other malicious actors. It is also important to keep abreast of privacy issues and to advocate for stronger privacy protections on a national and international level. For example, by supporting organizations that are committed to defending privacy rights, and by speaking out against government surveillance and data collection practices that threaten our civil liberties.

In 2009, the scientists Murphy and Woods formulated the Three Laws for Responsible Robotics, following the Three Laws of Robotics by the science fiction author Isaac Asimov. The first of their laws reads: “A human may not deploy a robot without the human-robot work system meeting the highest legal and professional standards of safety and ethics.” Maybe we should also apply this law to artificial intelligence, at least with regard to ethics, and to prevent chatbots from threatening our privacy.

 

2023-01-20

Privacy chat

 

Image from deperfectepodcast.nl

Two weeks ago I read with fascination the (internally published) story of fellow blogger Guido about ChatGPT, the artificially intelligent chatbot that anyone can use. Until now I knew chatbots mainly from companies that want to prevent you from calling them, and instead offer you to exchange thoughts with their always cheerful canned employee via the keyboard. But if I do have a question for a company at all, it rarely falls into a category that Clippy's grandchildren can handle; otherwise I would have found the answer myself in the FAQ.

Do you remember Professor Barnabas's computer from the Spike and Suzy (UK)/ Willy and Wanda (US) comics? It spat out a card with the answer to the question asked. I wanted to experience for myself how this works in practice. January 28 is European Privacy Day, and I promised the privacy colleagues in my team that I would dedicate a blog to it. As an experiment, I outsourced its the writing for once. However, not entirely: the following paragraphs are partly written by ChatGPT, partly by me (in the ChatGPT pieces I only intervened grammatically here and there). Can you recognize who wrote which paragraph? I will give the solution next week.

As a European, I am proud of the European Union and its role in protecting our personal data. With the introduction of the General Data Protection Regulation (GDPR) in 2018, the EU has introduced one of the strictest privacy laws in the world. The GDPR gives consumers more control over their own data and makes companies responsible for protecting those data.

While the GDPR is an important step forward, the battle for our privacy will never end. Technological developments are going faster than ever and with the rise of artificial intelligence and the internet of things, there are new challenges we face. Businesses and governments must continue to adapt to the changing landscape to protect our data.

Let's zoom in on artificial intelligence as a threat to our privacy. Sometimes you can benefit from a company or government agency not knowing everything about you; in countries with an oppressive regime this applies even more than in our western democracy. As long as only people and traditional information systems are involved, things are sometimes overlooked. But what if artificial intelligence were able to link all kinds of sources together in an unprecedented way and make connections that you, as a human being, or a 'dumb' computer, would never have thought of? Is that still fair? Aren't we entitled to a lucky break from time to time, because 'the system' overlooked something?

It is not only the responsibility of companies and governments to protect our privacy. As consumers, we also have a role to play. We need to be aware of our own data and how we share it. We must ask questions about how companies use our data and we must oppose inappropriate practices. Let's work together to protect our privacy so we can feel safe and protected in our digital world.

Another important step is the use of privacy-enhancing technologies, such as Virtual Private Networks (VPNs) and encryption tools. These can help protect our online communications and protect our personal information from being intercepted by hackers or other malicious actors. It is also important to keep abreast of privacy issues and to advocate for stronger privacy protections on a national and international level. For example, by supporting organizations that are committed to defending privacy rights, and by speaking out against government surveillance and data collection practices that threaten our civil liberties.

In 2009, the scientists Murphy and Woods formulated the Three Laws for Responsible Robotics, following the Three Laws of Robotics by the science fiction author Isaac Asimov. The first of their laws reads: “A human may not deploy a robot without the human-robot work system meeting the highest legal and professional standards of safety and ethics.” Maybe we should also apply this law to artificial intelligence, at least with regard to ethics, and to prevent chatbots from threatening our privacy.

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

Get out of jail

Image: Unsplash "Get out of jail free." If you land in jail and don’t have this Monopoly card, you can pay a fine to get out. Or y...