• RedSnt 👓♂️🖥️
    link
    fedilink
    17
    edit-2
    15 hours ago

    As one commented below the article, “Recall too I bet”.
    It’s like the dumbest anosmic sheep dog that’ll just show the wolf the way to the sheep.

  • mesamune
    link
    English
    23
    edit-2
    16 hours ago

    No joke I let them know about that in their official discussion board day 1 copilot came out. When they announced it, the first day you could ask it about the contents of private repos and it would just tell you.

    They fixed it but this looks really similar.

  • dohpaz42
    link
    English
    2920 hours ago

    The fact that there are so many “acts” that got violated tells me that those laws are just as shoddy as the fact that Microsoft’s fix didn’t take into account that the AI still has access to private data. Total shit show on all fronts.

  • @[email protected]
    link
    fedilink
    -320 hours ago

    Kind of a nothing burger.

    These repositories, belonging to more than 16,000 organizations, were originally posted to GitHub as public, but were later set to private, often after the developers responsible realized they contained authentication credentials allowing unauthorized access or other types of confidential data. Even months later, however, the private pages remain available in their entirety through Copilot.

    The repo was listed as public and archived. It’s not clear from the article but I suspect that the “private” information is just a copy of what was made public and not the information added after it was made private.

    • @[email protected]
      link
      fedilink
      2920 hours ago

      When a code repository is shut down on github the expectation is that it’s removed. We’re all aware that the internet will never forget that API key you accidentally committed once but the expectation was always that it wouldn’t be github itself doing the remembering and openly sharing it with others.

        • @grue
          link
          English
          1615 hours ago

          “According to the article it was Microsoft and not Microsoft.”

          Do you see now how silly you sound?

          • @[email protected]
            link
            fedilink
            24 hours ago

            From an ownership perspective, sure. But it’s still different from the implication that github is leaking currently private repositories.