‹ BackHN Continuity

Thread

A Privacy Analysis of Web and Mobile Conversational AI Agents [pdf]

425 points · 141 comments · damaru2

  1. postalcoder · · focus · HN ↗
    My least favorite trend I’ve noticed with so many AI chat services is they seem to equate a UUID in the url with privacy.

    Perplexity does this. Visiting a past perplexity search url exposes your full conversation.

    1. albert_e · · focus · HN ↗
      Security by obscurity -- such an age old anti-pattern!

      I believe many AI tools like Gemini generate publicly accessible URLs when we click "Share" on any chat conversation -- and expect users to then own the lifecycle of that link

      Depending on how the link gets handled -- by the browser, device OS, any hooks/plugins/extensions, aggressive telemetry, social media url previews, preload/prefetch, wrapping and url shortening, etc as it reaches the intended user -- there are countless ways in which the URL can be indexed and scraped

      There was a issue not long ago when Claude artifacts were indexed en-masse by Google and other search engines

      This is shockingly lax approach to data security and privacy by design

      1. postalcoder · · focus · HN ↗
        Chat UIs are a minefield of “if you accidentally click this your data will be shared or trained without you realizing it!”
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.