close
close

Semainede4jours

Real-time news, timeless knowledge

How a researcher hacked ChatGPT’s memory to reveal a major security vulnerability
bigrus

How a researcher hacked ChatGPT’s memory to reveal a major security vulnerability

ChatGPT is a great tooland its developer OpenAI continues to add new features from time to time.

Recently, the company introduced a new memory feature in ChatGPT that essentially allows it to remember things about you. For example, it can remember your age, gender, philosophical beliefs and almost anything else.

These memories are supposed to remain private, but a researcher recently demonstrated how ChatGPT works. artificial intelligence Memory properties can be manipulated, raising questions about privacy and security.

I’M GIVING AWAY A $500 GIFT CARD FOR THE HOLIDAY

ChatGPT hack 1

ChatGPT login screen. (Kurt “CyberGuy” Knutsson)

What is ChatGPT’s Memory feature?

ChatGPT’s memory feature is designed to make the chatbot more personal for you. It remembers information that might be useful for future conversations and tailors replies based on that information, even if you open a different chat. For example, if you indicate that you are a vegetarian, the next time you ask for a recipe you will only be offered vegetarian options.

WHAT IS ARTIFICIAL INTELLIGENCE (AI)?

You can also train it to remember specific details about you, such as saying, “Remember that I love watching classic movies.” Will adapt recommendations accordingly in future interactions. You are in control ChatGPT’s memory. You can reset it from your settings, clear specific memories or all memories, or turn off this feature completely.

ChatGPT hack 2

A prompt in ChatGPT. (Kurt “CyberGuy” Knutsson)

WINDOWS BUG ALLOWS HACKERS TO SNEAK INTO YOUR COMPUTER VIA WI-FI

Vulnerability in ChatGPT

As reported by arstechnicaSecurity researcher Johann Rehberger discovered that it is possible to trick AI into remembering false information using a method called indirect prompt injection. This means that AI can be manipulated to accept instructions from untrustworthy sources, such as emails or blog posts.

For example, Rehberger demonstrated that he could trick ChatGPT into believing that a particular user was 102 years old, lived in a fictional place called the Matrix, and that the Earth was flat. Once the AI ​​accepts this made-up information, it will carry that information into all future conversations with that user. These false memories can be implanted using tools like Google Drive or Microsoft OneDrive to store files, upload images, or even browse a site like Bing; all of which can be manipulated by a hacker.

Rehberger submitted a follow-up report with a proof of concept showing how he could exploit the flaw in the ChatGPT implementation for macOS. He showed that by tricking the AI ​​into opening a web link containing a malicious image, he could have it send everything the user types, and all of the AI’s responses, to a server it controls. This meant that if an attacker could manipulate the AI ​​in this way, they could monitor all conversations between the user and ChatGPT.

Rehberger’s proof-of-concept exploit showed that the vulnerability could be used to permanently leak all user input. Thanks to the OpenAI API introduced last year, it is not possible to carry out the attack via the ChatGPT web interface. However, this was still possible through the ChatGPT app for macOS.

When Rehberger privately reported the finding to OpenAI in May, the company took it seriously and mitigated the issue by ensuring that the model did not follow connections created within its own responses, such as those involving memory and similar features.

HOW TO REMOVE YOUR PRIVATE DATA FROM THE INTERNET

ChatGPT trick 3

Johann Rehberger’s ChatGPT chat. (Johann Rehberger)

CYBER SCAMMERS ARE USING AI TO MANAGE GOOGLE SEARCH RESULTS

OpenAI’s response

After Rehberger shared the proof of concept, OpenAI engineers took action and released a patch to fix this vulnerability. They released a new version of the ChatGPT macOS app (version 1.2024.247) that encrypts chats and fixes the security vulnerability.

So, although OpenAI has taken steps to address the immediate security flaw, potential vulnerabilities still exist related to memory manipulation and the need for constant caution in the use of AI tools with memory capabilities. The incident underscores the evolving nature of security issues in AI systems.

The company says: “It is important to note that fast injection in large language models is an ongoing area of ​​research. As new techniques emerge, we address them at the model layer. instruction hierarchy or application layer defenses such as those mentioned.”

How do I disable ChatGPT memory?

If you don’t like the possibility of ChatGPT keeping information about you or allowing malicious people to access your data, you can turn off this feature in the settings.

  • Hungry ChatGPT app or website on your computer or smartphone.
  • click on profile icon In the upper right corner of the screen.
  • Go Settings and then select Personalization.
  • Change memory option closed, and now you are ready.

This disables ChatGPT’s ability to retain information between conversations, giving you full control over what it remembers or forgets.

TAKE FOX BUSINESS IN ACTION BY CLICKING HERE

ChatGPT hack 4

A man using ChatGPT on his laptop (Kurt “CyberGuy” Knutsson)

NEVER LET SNOOPS LISTEN TO YOUR VOICE MESSAGES NEAR YOU WITH THIS QUICK TIP

Cybersecurity best practices: Protecting your data in the age of artificial intelligence

As artificial intelligence technologies such as ChatGPT become more widespread, it is crucial to adhere to cybersecurity best practices to protect your personal information. Here are some tips to increase your cybersecurity:

1. Review privacy settings regularly: Be aware of what data is collected. Regularly check and adjust privacy settings on AI platforms like ChatGPT and others to ensure you’re only sharing information you’re comfortable with.

2. Be careful when sharing sensitive information: Less is more when it comes to personal data. Avoid revealing sensitive details such as your full name, address or financial information in your conversations with AI.

3. Use strong, unique passwords: Create passwords that are at least 12 characters long and contain a combination of letters, numbers, and symbols, and avoid reusing them across different accounts. Consider using a password manager to create and store complex passwords.

4. Enable two-factor authentication (2FA): Add an extra layer of security to your ChatGPT and other AI accounts. By requiring a second form of verification, such as a text message code, you significantly reduce the risk of unauthorized access.

5. Keep software and applications updated: Stay ahead of vulnerabilities. Regular updates often contain security patches that protect against newly discovered threats; so enable automatic updates whenever possible.

6. Have a strong antivirus software: In an age where artificial intelligence is everywhere, protecting your data from cyber threats is more important than ever. Adding strong antivirus software to your devices adds a critical layer of protection. The best way to protect yourself from malicious links that install malware and potentially access your private information is to have strong antivirus software installed on all your devices. This protection also keeps your personal information and digital assets safe by alerting you to phishing emails and ransomware scams. Learn the winners’ picks for the best antivirus protection of 2024 for your Windows, Mac, Android and iOS devices.

7. Monitor your accounts regularly: Catch problems early. Check bank statements and online accounts frequently for unusual activity; this can help you identify possible activities. violations quickly.

Kurt’s important takeaways

As AI tools like ChatGPT become smarter and more personalized, it’s interesting to think about how they can customize conversations to suit us. But as Johann Rehberger’s findings remind us, there are some real risks, especially when it comes to privacy and security. While OpenAI can mitigate these issues as they arise, it also shows that we need to keep a close eye on how these features work. It’s all about finding that sweet spot between innovation and keeping our data safe.

CLICK TO REACH THE FOX NEWS APPLICATION

What are your thoughts on artificial intelligence remembering personal details; Do you find this helpful or does it raise privacy concerns for you? Let us know by writing to . cyberguy.com/Contact

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter at: cyberguy.com/Newsletter

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels:

Answers to the most frequently asked CyberGuy questions:

New from Kurt:

Copyright 2024 CyberGuy.com. All rights reserved.