Xorte logo

News Markets Groups

USA | Europe | Asia | World| Stocks | Commodities



Add a new RSS channel

 
 


Keywords

2023-03-24 17:54:39| Engadget

OpenAI was forced to take its wildly-popular ChatGPT bot offline for emergency maintenance on Tuesday after a user was able to exploit a bug in the system to recall the titles from other users' chat histories. On Friday the company announced its initial findings from the incident.In Tuesday's incident, users posted screenshots on Reddit that their ChatGPT sidebars featured previous chat histories from other users. Only the title of the conversation, not the text itself, were visible. OpenAI, in response, took the bot offline for nearly 10 hours to investigate. The results of that investigation revealed a deeper security issue: the chat history bug may have also potentially revealed personal data from 1.2 percent of ChatGPT Plus subscribers (a $20/month enhanced access package). "In the hours before we took ChatGPT offline on Monday, it was possible for some users to see another active users first and last name, email address, payment address, the last four digits (only) of a credit card number, and credit card expiration date. Full credit card numbers were not exposed at any time," the OpenAI team wrote Friday. The issue has since been patched for the faulty library which OpenAI identified as the Redis client open-source library, redis-py.The company has downplayed the likelihood of such a breach occurring, arguing that either of the following criteria would have to be met to place a user at risk:- Open a subscription confirmation email sent on Monday, March 20, between 1 a.m. and 10 a.m. Pacific time. Due to the bug, some subscription confirmation emails generated during that window were sent to the wrong users. These emails contained the last four digits of another users credit card number, but full credit card numbers did not appear. Its possible that a small number of subscription confirmation emails might have been incorrectly addressed prior to March 20, although we have not confirmed any instances of this.- In ChatGPT, click on My account, then Manage my subscription between 1 a.m. and 10 a.m. Pacific time on Monday, March 20. During this window, another active ChatGPT Plus users first and last name, email address, payment address, the last four digits (only) of a credit card number, and credit card expiration date might have been visible. Its possible that this also could have occurred prior to March 20, although we have not confirmed any instances of this. The company has taken additional steps to prevent this from happening again in the future including adding redundant checks to library calls, "programatically examined our logs to make sure that all messages are only available to the correct user," and "improved logging to identify when this is happening and fully confirm it has stopped." The company says that it has also reached out to alert affected users of the issue.This news follows a costly public faux pas committed by Google's rival Bard AI in February when it incorrectly assured Twitter that the JWST was the first telescope to image an exoplanet, as well as revelations that CNET had surreptitiously used generative AI to write financial explainer posts (a week before laying off a sizable chunk of its editorial department). Whether OpenAI will suffer the same market-based repercussions as its competitors remains to be seen. This article originally appeared on Engadget at https://www.engadget.com/openai-says-a-bug-leaked-sensitive-chatgpt-user-data-165439848.html?src=rss


Category: Marketing and Advertising

 

Latest from this category

27.04Apple has reportedly resumed talks with OpenAI to build a chatbot for the iPhone
26.04The FTC accuses Amazon of using Signals auto-deleting messages to erase evidence
26.04Drake deletes AI-generated Tupac track after Shakurs estate threatened to sue
26.04Aaron Sorkin is working on a Jan. 6-focused follow-up to The Social Network
26.04Samsung's Galaxy S24 Ultra falls to a new low, plus the rest of the week's best tech deals
26.04Nikons Z8 is a phenomenal mirrorless camera for the price
26.04Some of our favorite Bose headphones and earbuds are back to all-time low prices
26.04Apple's 13-inch MacBook Air with the M3 chip has never been cheaper
Marketing and Advertising »

All news

27.04Apple has reportedly resumed talks with OpenAI to build a chatbot for the iPhone
27.04United States: Top Five Labor Law Developments For March 2024 - Jackson Lewis
27.04United States: Privacy Versus Cyber What Is The Bigger Risk? - Jackson Lewis
27.04Pilots forced to return to New York after emergency slide falls off a Delta Air Lines plane
26.04140,000 people did their taxes with the free IRS direct file pilot, but the programs future is unclear
26.04Dead whistleblower accused Boeing of safety breaches
26.04The FTC accuses Amazon of using Signals auto-deleting messages to erase evidence
26.04Drake deletes AI-generated Tupac track after Shakurs estate threatened to sue
More »
Privacy policy . Copyright . Contact form .