‹ BackHN Continuity

Thread

A Privacy Analysis of Web and Mobile Conversational AI Agents [pdf]

425 points · 141 comments · damaru2

  1. aitoolcrux · · focus · HN ↗
    This is exactly the kind of rigorous analysis the AI industry needs. From our hands-on testing of 500+ AI tools, we've seen the same pattern: most conversational agents ship with telemetry baked in, and very few disclose what's actually being collected beyond the standard "we may use your data to improve our services" boilerplate.

    The prompt-injection angle is particularly concerning — it's not just about passive tracking, it's about the agent's context window becoming an attack surface. When a customer support agent pulls in untrusted web content or email threads, every loaded prompt becomes a potential data exfiltration channel.

    More tools need to follow the local-first model (like tools that run entirely on-device or via self-hosted infrastructure) as the default for sensitive workflows.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.