89 points damaru2 2 hours ago 19 comments

damaru2 2 hours ago | parent

Entire conversations via exposed permalinks. For Grok: trackers receiving the conversation URL could access the full chat because the link lacked access controls.

Screenshots of conversations. TikTok received screenshots of Grok chats during sharing, exposing the actual visible conversation content.

Conversation-derived content tied to persistent identifiers, including prompts and automatically generated chat titles revealing sensitive facts. "Salary 85k NYC: mortgage 280–350k".

Coeur 51 minutes ago | parent

"multiple providers disclose sensitive conversation-derived artifacts — including titles, prompts, and screenshots — to third parties, often alongside persistent user identifiers that enable user attribution. We also find that some providers publicly expose conversation permalinks without access controls, allowing trackers to read the entire conversation."

Not good at all.

postalcoder 18 minutes ago | parent

My least favorite trend I’ve noticed with so many AI chat services is they seem to equate a UUID in the url with privacy.

Perplexity does this. Visiting a past perplexity search url exposes your full conversation.

msdz 6 minutes ago | parent

Genuinely asking: If you don’t share the UUID-based URL yourself, what makes it not privacy-friendly?

It’s not like someone’s gonna guess that URL… right?

postalcoder 4 minutes ago | parent

Yes, technically, guessing a url is impossible. But browser histories are trivially accessible to sketchy actors.

classified 45 minutes ago | parent

Is it still called a leak if it was the whole point and purpose of the deal?

Someone should have to investigate, but I suppose it's all "legal"?

lava_pidgeon 16 minutes ago | parent

In the US.

In EU law it is very likely against GDPR.

folkrav 45 minutes ago | parent

Insert surprised pikachu meme

charcircuit 42 minutes ago | parent

The paper doesn't say when the app sends the conversion artifact.

DrMandalay 28 minutes ago | parent

The word is "sell" not "leak". This title takes away all agency from the thieves selling private data to advertisers.

gagan2020 22 minutes ago | parent

All sells but I saw Chinese models are upfront about that most of the time.

reedf1 20 minutes ago | parent

my first guess is always Gboard.

j4k0bfr 11 minutes ago | parent

This is a bit surprising to me, considering how much AI companies love to hoard data. Especially since some of these ad companies are direct competitors!

My best guess is that these ad mechanisms are a bit rushed and/or that investor demands for profitability are fighting against company self-interest.

Edit: I guess some data will always need to be leaked for AI chat ads to be most effective. But I imagine AI companies would rather deliver the targeted ads themselves rather than letting competitors do it for them. It would be scary to see AI companies become ad companies too (instead of just hosting them).

alansaber 7 minutes ago | parent

AI companies rushing an implementation? Surely not :).

amarcheschi 4 minutes ago | parent

I'm taking an onboarding process for an Ai company helping other (much) bigger Ai companies and the amount of vibecoded platforms and documentation is staggering. Like, training process so broken that the platform just doesn't load sometimes, things that have never even been tried are published and you have to use them and they suck so much because it is apparent that no human ever touched that and probably wouldn't want to

pluc 8 minutes ago | parent

You thought... they didn't?

robertclaus 6 minutes ago | parent

Hanlon's Razor given that these tools are almost certainly vibe coded at this point?