Quinnypig,
@Quinnypig@awscommunity.social avatar

I'm sorry Slack, you're doing fucking WHAT with user DMs, messages, files, etc? I'm positive I'm not reading this correctly.

isotopp, (edited )
@isotopp@chaos.social avatar

@Quinnypig

As a multinational, of course everybody at Salesforce is having a mandatory annual GDPR compliance training.

Passing that training means any Slack/Salesforce employee knows that what they are trying to do is illegal. That means the illegal act was done with intent.

Now they are going to find out in the most expensive way how illegal exactly. Invest in popcorn futures, I say.

Viss,
@Viss@mastodon.social avatar

@Quinnypig https://slack.com/trust/data-management/privacy-principles

so slack is destroying privacy and every single customer nda for ...

auto complete and emoji suggestions?!

quantensalat,
@quantensalat@astrodon.social avatar

@Viss @Quinnypig Autocompleting your competitors' designs sounds super convenient

RichiH, (edited )
@RichiH@chaos.social avatar

@Quinnypig The opt-out is also weasel-wordy, as you can opt out from Global models -- are there non-global ones?

If you are covered under the GDPR, Article 28 allows you to audit them to a reasonable degree and request a Data Protection Impact Assessment (DPIA/TIA) under Article 35.

RichiH,
@RichiH@chaos.social avatar

@Quinnypig for what it's worth, our purchasing people are already reaching out to SlackForce to get confirmation either way.

sintrenton,
@sintrenton@todon.nl avatar

@RichiH @Quinnypig

I sent the mail and got this text with the confirmation. Not sure how comforted I feel...

May 17, 2024, 7:24 AM PDT

Thank you for reaching out to Slack support. Your opt-out request has been completed.

For clarity, Slack has platform-level machine learning models for things like channel and emoji recommendations and search results. We do not build or train these models in such a way that they could learn, memorize, or be able to reproduce some part of customer data. Our published policies cover those here (https://slack.com/trust/data-management/privacy-principles), and as shared above your opt out request has been processed.

Slack AI is a separately purchased add-on that uses Large Language Models (LLMs) but does not train those LLMs on customer data. Slack AI uses LLMs hosted directly within Slack’s AWS infrastructure, so that customer data remains in-house and is not shared with any LLM provider. This ensures that Customer Data stays in that organization’s control and exclusively for that organization’s use. You can read more about how we’ve built Slack AI to be secure and private here: https://slack.engineering/how-we-built-slack-ai-to-be-secure-and-private/.

Kind regards,

RichiH,
@RichiH@chaos.social avatar

@sintrenton @Quinnypig that completely sidesteps why they would have that verbiage then. Giving themselves permission, but stating in the present tense they're not doing it seems weasely

cantstopthesignal,
@cantstopthesignal@mastodon.social avatar

@RichiH yes, appears so:
“If you opt out, Customer Data on your workspace will only be used to improve the experience on your own workspace and you will still enjoy all of the benefits of our globally trained AI/ML models without contributing to the underlying models.”

HighlandLawyer,
@HighlandLawyer@mastodon.social avatar
kamenrunner,
@kamenrunner@freeradical.zone avatar

@Quinnypig “This had made many people very angry and has been widely regarded as a bad move."

chunshek,
@chunshek@mastodon.online avatar

@Quinnypig
Thanks for this. We will be jumping ship to Mattermost ASAP.

WanderingPoltergeist,
WanderingPoltergeist avatar

I'm floored by Slack getting drunk on the idea of LLMs enough to compromise the privacy of customer data for the purpose of training an LLM! This should be an opt-in due to the nature of how much sensitive information will flow into training an LLM...I hope this move bites them in the ass.

axleyjc,
@axleyjc@federate.social avatar

@Quinnypig
Taken from the book, "How to torpedo a SaaS business in record time."

demofox,
@demofox@mastodon.gamedev.place avatar

@Quinnypig yikes. All sorts of NDA'd info, trade secrets, unpublished research, secret game projects etc etc just right there sucked up into an LLM.

dgentry,
@dgentry@mastodon.social avatar

@Quinnypig Amazing how quickly prompt escapes rocketed to the top of infosec concerns. Disruption!

Viss,
@Viss@mastodon.social avatar

@Quinnypig holy fuck - how many NDAS is this going to break for people? how many lawsuits is this going to create?

steely_glint,
@steely_glint@chaos.social avatar

@Viss @Quinnypig The best fun is it will invalidate patents - since 3rd parties will know about your design decisions before you register.

joelanman,
@joelanman@hachyderm.io avatar

@Quinnypig alt: **Contact us to opt out. **If you want to exclude your Customer Data from Slack global models, you can opt out. To opt out, please have your org, workspace owners or primary owner contact our Customer Experience team at feedback@slack.com with your workspace/org URL and the subject line ‘Slack global model opt-out request’. We will process your request and respond once the opt-out has been completed.

clacke,

@Quinnypig <pikachu_surprised_face.png> Of course they are.

sarah,
@sarah@phpc.social avatar

@Quinnypig @shochdoerfer No, I'm sure you readt that correctly.

I have a model for the world of AI. Imagine the most ridiculous thing possible, then assume the company is doing that thing. It usually pans out.

shochdoerfer,
@shochdoerfer@phpc.social avatar

@Quinnypig ping @heiglandreas something to consider for the phpug slack

heiglandreas,
@heiglandreas@phpc.social avatar

@shochdoerfer @Quinnypig I'm already drafting a Goodby message.... 😕

Di4na,
@Di4na@hachyderm.io avatar

@Quinnypig I will simply say that a lot of Account Managers at Salesforce are going to have a really long weekend.

stullekovski,
@stullekovski@chaos.social avatar
nrohluap,
@nrohluap@ioc.exchange avatar

@Quinnypig “Didja SEE what happened with Reddit’s IPO price when they announced a deal? We could get rich TOO!”

peterainbow,
@peterainbow@mstdn.social avatar

@Quinnypig that won't be GDPR compliant in the EU

vwbusguy,
@vwbusguy@mastodon.online avatar

@peterainbow @Quinnypig Not in the UK, which is no longer in the EU.

18+ peterainbow,
@peterainbow@mstdn.social avatar

@vwbusguy @Quinnypig actually will be the case in the UK as we still have GDPR, of course just like the EU whether it gets challenged is another question, after all how long did the stupidity with the cookie questions go on for and actually are still going on for, but I was trying to be positive when I'm actually not,all of this is a sideshow to climate horror that is with us and the rest of the shitshow

pete_wright,
@pete_wright@nlogic.systems avatar

@Quinnypig
holy smokes - is there a handy link for this so i can shoot this to my teams infosec and compliance departments. what a disaster.

bradk,
@bradk@mastodon.social avatar
serpentroots,
@serpentroots@hachyderm.io avatar
fuzzychef,
@fuzzychef@m6n.io avatar

@Quinnypig link/details? Having trouble finding this.

pcambra,
@pcambra@drupal.community avatar
VileLasagna,
@VileLasagna@mastodon.gamedev.place avatar

@Quinnypig Oh yeah, I'm sure that the people who use the tool specifically made for internal business and work comms are all thrilled to find that all of their comms are being logged by an external service, amazing stuff!

gsuberland,
@gsuberland@chaos.social avatar

@Quinnypig uhhhhh that is a disastrous idea

Viss,
@Viss@mastodon.social avatar

@gsuberland @Quinnypig i can literally hear every single computer security company on earth screaming at the same time right now.

because im one of them

screaming into this fucking feedback email address.

Haste,
@Haste@mastodon.social avatar

@Viss @gsuberland @Quinnypig

The one company every exec assumes would never be so foolish enough

f4grx,
@f4grx@chaos.social avatar

@Viss @gsuberland @Quinnypig there is not a single private company you can trust with your private data now. Not. a. Single. One. You can rather trust they will fuck you up with some ai crap.

tyil,

@f4grx @Viss @gsuberland @Quinnypig There never was a private company you could trust for that to begin with. If you want to have any control, you host your own solutions using completely free software.

dancast,
@dancast@wandering.shop avatar

@Viss @gsuberland @Quinnypig The number of Slack instances in which credentials have been shared is all of them

Viss,
@Viss@mastodon.social avatar

@dancast @gsuberland @Quinnypig it'll be interesting to see how much business they lose because of this

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • ngwrru68w68
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • megavids
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • provamag3
  • JUstTest
  • All magazines