<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Crooks on Dr Paris Buttfield-Addison</title>
    <link>https://hey.paris/tags/crooks/</link>
    <description>Recent content in Crooks on Dr Paris Buttfield-Addison</description>
    <generator>Hugo</generator>
    <language>en</language>
    <copyright>© Dr Paris Buttfield-Addison · I live on the land of the muwinina people. Sovereignty was never ceded.</copyright>
    <lastBuildDate>Tue, 12 Aug 2025 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://hey.paris/tags/crooks/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>CommBank&#39;s AI boyfriend</title>
      <link>https://hey.paris/posts/cba/</link>
      <pubDate>Tue, 12 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://hey.paris/posts/cba/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://commbank.com.au&#34;&gt;CBA&lt;/a&gt; has been naughty, and too reliant on their &lt;a href=&#34;https://www.abc.net.au/news/2025-07-29/commonwealth-bank-says-ai-behind-dozens-of-job-cuts/105586312&#34;&gt;AI boyfriend&lt;/a&gt;. Here&amp;rsquo;s what happened:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A CBA customer contacted bank requesting contact details for &lt;a href=&#34;https://secretlab.sg&#34;&gt;Secretlab&lt;/a&gt; (a company that &lt;em&gt;is not&lt;/em&gt; us, and makes chairs)&lt;/li&gt;&#xA;&lt;li&gt;CBA staff member queried ChatGPT (possibly via their own personal, unauthenticated access to ChatGPT) to obtain phone number for Secretlab (chairs)&lt;/li&gt;&#xA;&lt;li&gt;CBA staff disclosed the retrieved phone number to the requesting customer&lt;/li&gt;&#xA;&lt;li&gt;The retrieved phone number is a number belonging to one of the directors of &lt;a href=&#34;https://secretlab.games&#34;&gt;Secret Lab&lt;/a&gt; (a company that does &lt;em&gt;not&lt;/em&gt; make chairs, and &lt;em&gt;is&lt;/em&gt; us), a customer of CBA, and is used for our CBA account and our Director&amp;rsquo;s CBA account&lt;/li&gt;&#xA;&lt;li&gt;Therefore, CBA disclosed customer &lt;a href=&#34;https://www.commbank.com.au/support/privacy.html&#34;&gt;personal information&lt;/a&gt; to another, unrelated customer, and trusted a third-party LLM (ChatGPT), accessed seemingly unauthenticated on the consumer ChatGPT platform, as a source for data to provide to another customer&lt;/li&gt;&#xA;&lt;li&gt;During investigation, CBA staff replicated the same ChatGPT query process, seemingly on a personal phone, again unauthenticated, and on the consumer ChatGPT platform:&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;figure&gt;&lt;img src=&#34;https://hey.paris/posts/cba/cba-muppet.png&#34;&gt;&#xA;&lt;/figure&gt;&#xA;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Signs indicate this might be routine practice amongst CBA staff&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Oh, and they gave out the phone number for us, Secret Lab (not chairs), to someone looking for Secretlab&amp;rsquo;s (chairs) phone number. So, in the end of all this, they weren&amp;rsquo;t even helpful. LLMs in a nutshell, really.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Don&#39;t use Wise</title>
      <link>https://hey.paris/posts/wise/</link>
      <pubDate>Wed, 14 May 2025 00:00:00 +0000</pubDate>
      <guid>https://hey.paris/posts/wise/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://wise.com&#34;&gt;Wise&lt;/a&gt; has stolen more than $60,000 AUD from us, and refuses to let us access it.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://secretlab.games&#34;&gt;We&amp;rsquo;ve&lt;/a&gt; had a Wise account for around 5 years (since they were called TransferWise). It&amp;rsquo;s been a really useful way to transact in foreign currencies, and pay for things when we&amp;rsquo;re travelling for work.&lt;/p&gt;&#xA;&lt;p&gt;In early-April 2025, Wise asked us to provide some additional information on our Ultimate Beneficial Owners (UBOs) by uploading a statement of shareholders, and the ID of the owners. Perfectly reasonable stuff for an entity that pretends to be a bank to ask for.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
