‹ BackHN Continuity

Thread

A Privacy Analysis of Web and Mobile Conversational AI Agents [pdf]

425 points · 141 comments · damaru2

  1. cleochan · · focus · HN ↗
    One important limitation is that the paper excludes enterprise and government tiers, so I would not automatically map these findings onto a contracted business service. But it does suggest a better procurement test than asking only whether prompts train the model. For an approved workplace assistant, document the exact client and tier being used, inspect outbound domains from both web and mobile clients, test reject-cookie and no-sharing configurations, and ask the supplier to identify subprocessors, retention periods, conversation-link controls, and material change notifications. Repeat the test after major client updates. Where verification is not possible, restrict the data classes users may enter. I would also distinguish observed third-party contact from proof that full prompt content reached every endpoint.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.