‹ BackHN Continuity

Thread

A Privacy Analysis of Web and Mobile Conversational AI Agents [pdf]

425 points · 141 comments · damaru2

  1. postalcoder · · focus · HN ↗
    My least favorite trend I’ve noticed with so many AI chat services is they seem to equate a UUID in the url with privacy.

    Perplexity does this. Visiting a past perplexity search url exposes your full conversation.

    1. msdz · · focus · HN ↗
      Genuinely asking: If you don’t share the UUID-based URL yourself, what makes it not privacy-friendly?

      It’s not like someone’s gonna guess that URL… right?

      1. postalcoder · · focus · HN ↗
        Yes, technically, guessing a url is impossible. But browser histories are stored in cleartext and trivially accessible to sketchy actors.

        I also accidentally paste random stuff into input boxes all the time.

        1. msdz · · focus · HN ↗
          Good points, thanks.

          Although I think at the point of some on-device program reading your browser history against your will, you’re gonna have bigger problems.

          1. kjs3 · · focus · HN ↗
            You already have bigger problems then. Most people have given any number of plugins, etc., access to peek at browser history, clipboards, etc and didn't realize it. Run an ad blocker? VPN? Check out the permissions those sorts of things have on your device.
            1. lukan · · focus · HN ↗
              I want to get rid of whatsapp. Well, since years, but now the need increased.

              On android it is possible to give permissions "once" "while using the app" "always".

              But whatsapp now only accepts the full camera access. If you set "ask every time" to indeed only make a picture once and then no camera access anymore, it refuses and sends you to the permission dialoge.

              1. kjs3 · · focus · HN ↗
                So they aren't even pretending to not say "screw you and your privacy". Glad I don't have need, increasing or otherwise, to use Whatsapp.
    2. albert_e · · focus · HN ↗
      Security by obscurity -- such an age old anti-pattern!

      I believe many AI tools like Gemini generate publicly accessible URLs when we click "Share" on any chat conversation -- and expect users to then own the lifecycle of that link

      Depending on how the link gets handled -- by the browser, device OS, any hooks/plugins/extensions, aggressive telemetry, social media url previews, preload/prefetch, wrapping and url shortening, etc as it reaches the intended user -- there are countless ways in which the URL can be indexed and scraped

      There was a issue not long ago when Claude artifacts were indexed en-masse by Google and other search engines

      This is shockingly lax approach to data security and privacy by design

      1. postalcoder · · focus · HN ↗
        Chat UIs are a minefield of “if you accidentally click this your data will be shared or trained without you realizing it!”
      2. kevindamm · · focus · HN ↗
        The same assumptions are true about giving any human that shareable link. They could pass it on to anyone, screenshot it, paste it into their own session. This has been true since before "share with link" permissions on Docs and elsewhere.

        If you click "provide a shareable link" you should decide (and behave) as though that made it public.

        I'm not saying it's good privacy posture on the side of the companies, but how else do you think that would work if there isn't any authentication step for the person viewing it? Even with authentication, "three may keep a secret, if two of them are dead."

        1. [deleted] · · focus · HN ↗

          [deleted]

    3. someonebaggy · · focus · HN ↗
      Isn't that equivalent to a password? Knowing my password exposes my full data.
      1. wtetzner · · focus · HN ↗
        You don't store your password in the URL.
        1. someonebaggy · · focus · HN ↗
          I store my session token in a cookie, which is even worse because it's sent with every request.
          1. bsharper · · focus · HN ↗
            Not in a URL generally, and if it is the only people who can see the full URL are the receiver and the sender if HTTPS is properly enabled.
          2. SahAssar · · focus · HN ↗
            It's not. The cookie only gets sent to the domains/servers you specify and is not accidentally exposed via browser history or copying a link.
      2. layerv-ai · · focus · HN ↗
        not as bad since the blast radius is only your chat vs. knowing your password exposes all your data.

        however - agree that this is not great - espeically if chat TTL is long. someone who gets your URL can read everything you're asking (eg. by sniffing your network/accessing your browser history)

    4. 40four · · focus · HN ↗
      It certainly doesn’t expose it to anyone else besides you (when you are logged in), unless you explicitly select the share option.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.