Skip to main content

AD_4nXfEPUPaggdlJ2DDvrLaHgKNMSsvOmrWwUTTjpN5ObUCAwj64oLosrWjUjfJKoDSAAhCMZgcaS4-d1Gs0Ay6WwOBQZeAvNgs_W4Saq-pUJpLfaSnY_2cVUi4eKd31Bh84ZEkQjFztQ?key=6dt2-_ir0P4rsg03iDWiCucy

Netskope Global Technical Success (GTS)

Netskope controls for ChatGPT Native Client - Windows OS

 

Netskope Cloud Version - 121

 

Objective

The purpose of this document is to explore Netskope's capabilities for managing and securing the ChatGPT Native Client on Windows OS.

 

Prerequisite

Netskope Inline CASB and SWG license is required

 

Context

ChatGPT is accessible through both its web platform and the Native Client application. While implementing security controls for ChatGPT's web platform is straightforward—thanks to extensive documentation on Netskope's capabilities for applying granular traffic controls.

 

This document focuses on Netskope's ability to manage and secure the ChatGPT Native Client on Windows OS.

 

Findings

  • Netskope acknowledges ChatGPT as a Cloud Application and provides a pre-defined cloud app connector.
  • As of Dec 10, 2024 with Netskope’s ChatGPT predefined connector, customers can exercise control over the following activities:

AD_4nXfnGEhd_7cMn9gRGyjUREI1QEELQGSC73wIKzuFSOlEWIHLXegI-IInSG2wFGnWqMujhD6o1oi8unT1HGxKrG7EGCHWQaMjgx07dRG5mVqnAXQF7e4DHAlAT6uvRZSjy4SL35A4?key=6dt2-_ir0P4rsg03iDWiCucy

Image 1

 

  • As of December 10, 2024, the ChatGPT Native Client is available on four platforms:
  1. Windows
  2. macOS
  3. Android
  4. iOS
  • On my Windows OS machine, I downloaded the ChatGPT Native Client from https://openai.com/chatgpt/download/
  • After installing and launching the application, I observed that logging in is mandatory to access ChatGPT on the Native Client. In contrast, the ChatGPT web version allows limited access without requiring a login.

AD_4nXf8JkiFEjbf2wDdwNUy-07OYVRQSKhu2cQJZ4Fw48ybmfWksBqQGQX7CEGVSyF23wJDTqgUIcR0caYwH50boTi3_hXXyva9BNxIGOF5XGkDwDpZfv6iUkTBR0MMSoknFLwZB3Optg?key=6dt2-_ir0P4rsg03iDWiCucy

Image 2

  • After logging in with my personal Gmail account (a non-ChatGPT plus account), I analyzed the transactions on my Netskope tenant. The Login Activity was detected, and Netskope successfully identified that the login was performed via a Google Gmail account. Additionally, Netskope registered the details of the email ID used for the login.
  • ChatGPT Native Client landing page -

AD_4nXdhAGf_Yxy8_5tGEmsRIo7hr0SGQOspTvcc1nFytaQJ7a9UKNDERz3c0s0jGGTaLAS3rGZdQmWsioPXsbJypnVRcX9tI-0Xp3p5314DBFAd2pw39o2gG6WrGVx87nvl7VOdn-scXw?key=6dt2-_ir0P4rsg03iDWiCucy

Image 3

  • Another difference I noticed is that the ChatGPT Native Client displays different options on AD_4nXem221LZ0fmFW0KpsuDtabssKo4WRVACmIJkgOZPiw9QbIZOcu6xZt_neE4yjvQuVOP6Keu2x3sL93DAw1_J51KU1Cds_aPVCEkzh-y8j3KQk7IYkHKX7S7oXwLAt5B3Ba47Enhgg?key=6dt2-_ir0P4rsg03iDWiCucycompared to the ChatGPT web version. Refer Image 4 & 5

AD_4nXeDDNlxTWWwJChr_YwBPm7H5JIfx3ds_Gk8X5q3lZsuguP-6I65Mf-t4UkvBpCjQiXAmQrTf7gHaHLAcHrtdcd2zP_ProZgR14UjgPqJUJ2cy4iVuCiV86sIkOiQudBZZ8K_MDIOA?key=6dt2-_ir0P4rsg03iDWiCucy

Image 4 - ChatGPT Native Client

 

AD_4nXdYKj43gbtG6fKdC2YlfeSNKrp7GLnJ1Kv3t-md2bVXC4fcyh2NqGG9W-zNXU00QeTdGC1zTKthU2l1Urpn8E46P0aFMCag-VfscbVelDdYJZCRzou3T9qH-eHChZgLEPyAO3ZM?key=6dt2-_ir0P4rsg03iDWiCucy

Image 5 - ChaGPT Web Access

 

  • I created a Realtime policy to block activities such as Post and Upload, and the results are below -

AD_4nXdaH0GZmjgHXylWCqceDVs8rSJ-kpMcnYzrAPla3FVPC9iEFN_v2937Ks7LTIujg9q57ImfSbGmJ-sruB_ZWsdNWH54QzNBCFFm4tMmDYfQKIQYo32s8nZtvWKhxBHWy7GNPhqk?key=6dt2-_ir0P4rsg03iDWiCucy

Image 6

 

Results

Activity - Post

AD_4nXcrhbgonAbBOR93njZXnqVgdxwVdXGR9Lk0dMzTLh3E-lSKvMANg3AATIc7WKzbPnurSaIwbh7xoftmKkd3D_GaohUPzSLOdfCWlRjREb7pxPbmbyOoOEZvmNx15R5ehGPKJq3JAA?key=6dt2-_ir0P4rsg03iDWiCucy

Image 7

 

Activity - Upload

AD_4nXc3G-J2jbhtfqSNeehAiAZg6tuFr3v2sU4299qotfkY5CKx_a0zXSjOM3bUbUCbb3bEXEsNGoWY3m53QHArnGbVlYqXZUsTOi6ZL4E7iUlWu7dS26TKLcO0jJsE2WLWHbmS4l5HsA?key=6dt2-_ir0P4rsg03iDWiCucy

Image 8

 

  • I also test Netskope DLP on ChatGPT Native Client and the result are below-

DLP Profile is to detect the keyword PAN

AD_4nXcMHVn0ISEv2356HOJSe-cov_fqElTtihPsfHLVv2BEOn1MQeL4kafH31RkcB3ow4bLaNXJhJJB_z8XpHneh97aP2bJPxHlXCk2Pe-MoAiJ676WPWKDJ1fsd6DdhA5JxKgIjkeoMw?key=6dt2-_ir0P4rsg03iDWiCucy

Image 9

 

Results

Activity - Post

AD_4nXdNuG5MJEfZAJrbVEZhjNplV4WfoyKbqP1tkb9ncI8EOkKc0jYI3sFSlHtupxj12ZiKkJKPQl-o5KDlTyPGfLnVvN8hp28Frhum4mtGHiR-0oyts3Wr5AsFSPlvbhfWQSzM1cpg3A?key=6dt2-_ir0P4rsg03iDWiCucy

Image 10

 

Activity - Upload (Test File Attached)

AD_4nXe0x7UIKiQX_BNdOyJqju2OI2FlKMoOwSXK6_6VPnhtk771n6uG78NiChtMj26uRg-2HS6R7ASMuazBBf4u5SwI30HXf6k_XAzyvszzj1w_NOUAp08uifr5EgxjRUGxEPZRrIr0fA?key=6dt2-_ir0P4rsg03iDWiCucy

Image 11

 

Conclusion

The chart below illustrates what customers can achieve with Netskope in terms of ChatGPT Web Access and ChatGPT Native Client on Windows OS.

Checks

ChatGPT Web Access

ChatGPT Native Client

Block ChatGPT completely

Yes

Yes

Restrict ChatGPT login to selected domains only 

Yes

Yes

Block Activity - Post Completely

Yes

Yes

Block Activity - Upload Completely

Yes

Yes

DLP on Activity - Post

Yes

Yes

DLP on Activity - Upload

Yes

Yes

Controls on API Integration with Google Drive and Microsoft OneDrive

Yes

Yes

User Alert

Yes

Yes

Activity - Upload ‘File Size detection’

Yes

Yes

Activity - Upload ‘File Name detection’ 

Yes

Yes

 

 

Terms and Conditions

  • All documented information undergoes testing and verification to ensure accuracy.
  • In the future, If any such platform changes are brought to our attention, we will promptly update the documentation to reflect them.

 

Notes

  • This article is authored by Netskope Global Technical Success (GTS).
  • For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.

 

 

What to Read Next?

All about - ‘Generative AI’ Link
All about - ‘WhatsApp’ Link
All about - ‘Youtube’ Link