Monday, July 8, 2024

ChatGPT’s much-heralded Mac app was storing conversations as plain text

https://arstechnica.com/ai/2024/07/chatgpts-much-heralded-mac-app-was-storing-conversations-as-plain-text/

"the OpenAI ChatGPT app on macOS is not sandboxed and stores all the conversations in plain-text in a non-protected location," meaning "any other running app / process / malware can read all your ChatGPT conversations without any permission prompt."...

macOS has blocked access to any user private data since macOS Mojave 10.14 (6 years ago!). Any app accessing private user data (Calendar, Contacts, Mail, Photos, any third-party app sandbox, etc.) now requires explicit user access.

OpenAI chose to opt-out of the sandbox and store the conversations in plain text in a non-protected location, disabling all of these built-in defenses.

OpenAI has now updated the app, and the local chats are now encrypted, though they are still not sandboxed. (The app is only available as a direct download from OpenAI's website and is not available through Apple's App Store where more stringent security is required.)"

 

 

Cybersecurity is not a cost of doing business, it's a sine qua non. Inadequate cybersecurity costs businesses dearly. CDK car-dealer software attack may have cost more than $600M

  "Massive car dealer ransom attack is mostly over after 2 weeks of work-arounds CDK outage likely slumped June auto sales, may have co...