A Security and AI Fail

  • Comments posted to this topic are about the item A Security and AI Fail

  • At my job we're in the midst of what we suspect is a "feed ALL OF THE DATA to an AI" project.  The reason we only suspect is that we were given a directive to grant read access to nearly all of our databases with no indication as to why other than "this is coming down from higher up, just do it."

    Needless to say, this has raised a lot of concerns about not only the "why" of this requirement, but the "who" and "how is the data being secured on the other end of this connection" as well.  So for now, we're doing what we can to protect sensitive data until we're told not to (legacy application that's got some security issues that were always "we'll look at it later."  Well, it's now "later")

    On our end, we're all fervently hoping the people working on the systems on the far end are thinking about security, because they're pulling from hundreds of other systems (some of which probably ALSO have sensitive info) and creating a really big single-target for any malicious actors.

    (Side note: The organization I work with is only within the USA, so no GDPR applies, only US law)

  • I worked on a project where the company had 2 big vendor contracts.  The sort where you sign up for 10 years for a figure that would keep someone in racing yachts for life.

    Our project was fast, efficient, and effective.  Or it was until the architects discovered we weren't using tech from either of the 2 big vendors.  What followed was Kafkaesque in the extreme.  "Thou shalt use the big vendor tech for which we have paid a ludicrous sum of money".  A project where we thought we were within a few days of deploying to production ended up having 2 years of pointless meetings, technical reviews and bureaucracy thrown at it.  As far as I am concerned, every single one of the architects involved was a millipede with a foot-shooting fetish.

    I've seen projects where there is an insistence on using AI.  The task may be to apply some deterministic formulae to a simple data source.  Doesn't matter.  You have to spend 3 weeks vibe coding and peer reviewing 10,000 lines of slop to deliver a 30-minute feature.

    AI absolutely is a fantastic addition to the toolbox, but no matter how fancy the hammer, you still don't use it to cut boards.

     

  • jasona.work wrote:

    At my job we're in the midst of what we suspect is a "feed ALL OF THE DATA to an AI" project. The reason we only suspect is that we were given a directive to grant read access to nearly all of our databases with no indication as to why other than "this is coming down from higher up, just do it." Needless to say, this has raised a lot of concerns about not only the "why" of this requirement, but the "who" and "how is the data being secured on the other end of this connection" as well. So for now, we're doing what we can to protect sensitive data until we're told not to (legacy application that's got some security issues that were always "we'll look at it later." Well, it's now "later") On our end, we're all fervently hoping the people working on the systems on the far end are thinking about security, because they're pulling from hundreds of other systems (some of which probably ALSO have sensitive info) and creating a really big single-target for any malicious actors. (Side note: The organization I work with is only within the USA, so no GDPR applies, only US law)

     

    Crazy, but not uncommon in plenty of companies I've worked with

  • David.Poole wrote:

    ...

    AI absolutely is a fantastic addition to the toolbox, but no matter how fancy the hammer, you still don't use it to cut boards.

    Well, you can cut them with a hammer. It's just not a clean line

Viewing 5 posts - 1 through 5 (of 5 total)

You must be logged in to reply to this topic. Login to reply