Hacker plants false memories in ChatGPT to steal user data in perpetuity

captainkangaroo@discuss.tchncs.de to Technology@lemmy.world – 369 points –
Hacker plants false memories in ChatGPT to steal user data in perpetuity
arstechnica.com
34

You are viewing a single comment

Server or client, every supposed prefetch would be unique. If I trick an LLM client into grabbing:

site.com/random-words-of-data/image.gif

Then:

site.com/more-random-data/image.gif

Those are two separate images to the cache engine. As the data refreshes, the URL changes, forcing a new grab each time.

For email, marketers do this by using a unique image URL for every recipient.

Cool, all of your images are getting fetched by the server as it receives and processes the emails. You have 100% open rate on all emails to that domain within 3 minutes of send.

What do you know about the user and their behavior? Nothing. The prefetch is not tied to their actions, therefore you cannot learn anything about their actions.

This post isn't about email open rates, it's about data exfiltration. But for email speficially, show me major providers that prefetch by default.

For data exfiltration, you’re right - this doesn’t help.