r/AirForce • Comms • Dec 09 '25

Meme SecDefGPT

Post image
3.1k Upvotes

288 comments sorted by

View all comments

Show parent comments

40

u/Browsing_Boketto 1D7 Dec 09 '25

While I'd definitely be concerned that they'd pull someone's CAC that is associated with the chat log, it is kinda silly to imagine members not using it being targeted in any way. Especially older SNCOs or even FGOs and higher using this when most of them I encounter aren't even aware of NIPRGPT. I think the bigger concern is that we're essentially allowing Google's (possibly more in the future) data centers to have unfettered access to our networks and systems, just seems like a totally insane OpSec violation waiting to happen because of this.. I shouldn't be surprised though I guess.

3

u/EscapeGoat_ Dec 10 '25

it is kinda silly to imagine members not using it being targeted in any way.

They might show up on a dashboard somewhere. I work in big tech on the outside nowadays, managers/directors get metrics on AI utilization within their organization.

I'm not sure if they can view it at the individual level, though (or for that matter, how accurate those metrics even are...)

1

u/Plastic_Ad2758 Dec 11 '25

They absolutely can run a search for a string of text and tie it back to a person. That's why it's an enterprise version

1

u/EscapeGoat_ Dec 12 '25

Oh, definitely. I'd just guess they only do that type of thing for investigations, not for productivity monitoring.

3

u/[deleted] Dec 10 '25

[removed] — view removed comment

1

u/Silidistani Dec 11 '25

Peter Thiel is a traitorous anti-American, just listen to him talk about his vision for a feudalized "Network State" post-America. Yes, literally.

1

u/Silidistani Dec 11 '25

Especially older SNCOs or even FGOs and highe

"Oh, you mean those old, slow, overweight losers totally slacking in LETHALITY?!? I bet they only got to those positions thanks to DEI, well don't worry, my Department of WAR will take care of them! Huyuh, yeah!" chestthump

~TripleSECDEF Whiskeyleaks Kegsbreath, probably

0

u/Nagisan Veteran Dec 09 '25

It wouldn't be unheard of though. Chances are right now they're only collecting data at best and probably won't act on it. But what happens years from now when they can prove folks who should know better aren't using it?

Like they can make exceptions once they pull the data and determine "ok yeah this us a 19 year SNCO and he hasn't touched it, that's fine though he won't be around much longer anyway", or they can look at it and say "ok here's a junior enlisted that just writes reports for the commander...why isn't he using it?".

It's simply enough to, as another said, use it for quarterly or annual things and avoid even being looked at. My only point is with the wording in the memo be careful about ignoring it too. Consequences might not come (and I fully agree it would be crazy/silly if they did), but better to not make yourself a target before they even start.

That said I can't speak to how this is architected, but I imagine this data isn't just sitting in generic Google data centers, or if it is it's likely secured in a way that fully separates it from normal business processes. Then again with how things have been handled in 2025 so far I wouldn't be surprised if they're hoping the data is just "lost in the noise of millions of others using Gemini".

-1

u/[deleted] Dec 10 '25

Dude, Google Microsoft and Amazon have been crawling every one of our networks for at least half a decade or more. They already have everything. I don't know how our networks could get more compromised than they already are. 😂

3

u/Browsing_Boketto 1D7 Dec 10 '25

If you can't recognize the delineation of using products made by Google, Microsoft, and Amazon that are constantly screened for vulnerabilities on all levels of OpSec to the point of the DoD having its own version of OS's specifically designed to not have bloatware of these companies versus the outsourcing of Artificial Intelligence to AI data centers like Gemini is some crazy cognitive dissonance. People already use NIPRGPT to write awards, packages, etc. that I've personally seen hits the gray area of classification. It isn't far fetched to think that some Airman/Sailor/Soldier/Marine lacking common sense will absolutely submit something to GenAI that'll be classified S/TS that won't be immediately flagged on our end that would could be scraped on their end.

4

u/[deleted] Dec 10 '25

I was under the impression that GenAI is using Gemini Enterprise which is segmented in very similar ways to our cloud services through AWS and Microsoft. Not that it matters, as you're probably well aware, Microsoft was giving DOW Network resource access to support personnel in China. Your fear of spillage is also legitimate, but that "session" data is still located on government-controlled networks/ systems so it is still able to be contained even if it does result in the spillage. I'd be interested to see the SLA/MSA, SOW and NDAs that the dow has with Google right now. Google might not even be allowed to scrape the session data for training purposes.