‹ BackHN Continuity

Thread

ChatGPT now knows what you do on other websites via ad collector

764 points · 395 comments · lmbbuchodi

  1. luke5441 · · focus · HN ↗
    MDN lists how different browsers prevent this: <a href="https:&#x2F;&#x2F;developer.mozilla.org&#x2F;en-US&#x2F;docs&#x2F;Web&#x2F;Privacy&#x2F;Guides&#x2F;Third-party_cookies#how_do_browsers_handle_third-party_cookies" rel="nofollow">https:&#x2F;&#x2F;developer.mozilla.org&#x2F;en-US&#x2F;docs&#x2F;Web&#x2F;Privacy&#x2F;Guides&#x2F;...

    Firefox, Brave and Safari do. Chrome and Edge do not.

    1. mokre · · focus · HN ↗
      That’s not fully protect you. They still can match short living third party identifiers with their domain cookie or device_id from app. It is not 1-1 matching but works relatively good with modern itp.
      1. luke5441 · · focus · HN ↗
        This would work for an ad shown on ChatGPT and then clicked on (or in the ChatGPT app).

        But it would not give ChatGPT information about which other sites are visited.

        Of course there would be non-cookie options like fingerprinting (also via IP) that would allow tracking non-the-less.

        So you might be talking with OpenAI about your marriage problems and then based on the IP the OpenAI ad network would start showing ads for divorce lawyers on unrelated sites you browse to that display ads.

        The solution to that would be using a VPN.

        1. mokre · · focus · HN ↗
          Yes, you click is the easiest option. Yes, cookie + fingerprinting (which also contains ip information) is the option. But we VPN still not fully protect you. But things like private relay and vpn definitely add another level of complexity.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.