‹ BackHN Continuity

Thread

A Privacy Analysis of Web and Mobile Conversational AI Agents [pdf]

425 points · 141 comments · damaru2

  1. postalcoder · · focus · HN ↗
    My least favorite trend I’ve noticed with so many AI chat services is they seem to equate a UUID in the url with privacy.

    Perplexity does this. Visiting a past perplexity search url exposes your full conversation.

    1. someonebaggy · · focus · HN ↗
      Isn't that equivalent to a password? Knowing my password exposes my full data.
      1. wtetzner · · focus · HN ↗
        You don't store your password in the URL.
        1. someonebaggy · · focus · HN ↗
          I store my session token in a cookie, which is even worse because it's sent with every request.
          1. bsharper · · focus · HN ↗
            Not in a URL generally, and if it is the only people who can see the full URL are the receiver and the sender if HTTPS is properly enabled.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.