top | item 45742657

(no title)

ghm2180 | 4 months ago

Is this the security flaw thingy that stores OAuth or Auth0 tokens in sqllite database with overly permissive read privileges on it?

discuss

order

zmmmmm|4 months ago

no I'm talking about the general concept of having ChatGPT passively able to read sensitive data / browser session state. Apart from the ever present risk they suck your data in for training, the threat of prompt injection or model inversion to steal secrets or execute transactions without your knowledge is extreme.

Terr_|4 months ago

Right, the software is inherently a flaming security risk even if the vendor were perfectly trustworthy and moral.

Well, unless the scenario is moot because such a vendor would never have released it in the first place.