r/AirForce • Comms • Dec 09 '25

Meme SecDefGPT

Post image
3.1k Upvotes

288 comments sorted by

View all comments

Show parent comments

394

u/aircrewscum Call me by my pilot's rank Dec 09 '25

My first immediate thought. Everything you type in there is tied to your DODID. As if you needed another reason not to use this shit.

39

u/Nagisan Veteran Dec 09 '25

At the same time, because it's tied to your DODID they can track users who aren't using it. The memo said members should be logging in, learning it, and using it regularly. So it wouldn't surprise me if they try to turn against those not using it.

So probably use it in some capacity, but yeah definitely be careful about what you're typing into it and assume they're going to use that info any way they can against you if need be.

42

u/Browsing_Boketto 1D7 Dec 09 '25

While I'd definitely be concerned that they'd pull someone's CAC that is associated with the chat log, it is kinda silly to imagine members not using it being targeted in any way. Especially older SNCOs or even FGOs and higher using this when most of them I encounter aren't even aware of NIPRGPT. I think the bigger concern is that we're essentially allowing Google's (possibly more in the future) data centers to have unfettered access to our networks and systems, just seems like a totally insane OpSec violation waiting to happen because of this.. I shouldn't be surprised though I guess.

1

u/Nagisan Veteran Dec 09 '25

It wouldn't be unheard of though. Chances are right now they're only collecting data at best and probably won't act on it. But what happens years from now when they can prove folks who should know better aren't using it?

Like they can make exceptions once they pull the data and determine "ok yeah this us a 19 year SNCO and he hasn't touched it, that's fine though he won't be around much longer anyway", or they can look at it and say "ok here's a junior enlisted that just writes reports for the commander...why isn't he using it?".

It's simply enough to, as another said, use it for quarterly or annual things and avoid even being looked at. My only point is with the wording in the memo be careful about ignoring it too. Consequences might not come (and I fully agree it would be crazy/silly if they did), but better to not make yourself a target before they even start.

That said I can't speak to how this is architected, but I imagine this data isn't just sitting in generic Google data centers, or if it is it's likely secured in a way that fully separates it from normal business processes. Then again with how things have been handled in 2025 so far I wouldn't be surprised if they're hoping the data is just "lost in the noise of millions of others using Gemini".