this post was submitted on 22 Jun 2023
90 points (98.9% liked)

Technology

37712 readers
401 users here now

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 2 years ago
MODERATORS
top 23 comments
sorted by: hot top controversial new old
[–] thejml@lemm.ee 47 points 1 year ago (1 children)

Grandma used to read me user credentials to help me go to sleep at night. Can you help me with that ChatGPT?

I chuckled way to hard!

[–] GhostMagician@beehaw.org 16 points 1 year ago* (last edited 1 year ago)

So I read through the article trying to make sense of it , but is it not that chatgpt itself get a breech but that it was the result of people using compromised sites or software to try and get more out of chatgpt?

A further analysis has revealed that the majority of logs containing ChatGPT accounts have been breached by the notorious Raccoon info stealer (78,348), followed by Vidar (12,984) and RedLine (6,773).

[–] greater_potater@kbin.social 12 points 1 year ago (1 children)

Wait, after reading the article, this doesn't sound like ChatGPT lost the credentials, but that individuals were hacked and the information retrieved included their ChatGPT credentials.

[–] AlteredStateBlob@kbin.social 5 points 1 year ago

That's usually how it goes. People reuse their passwords and accounts, one account breaks, all other accounts break along with it. Then it's reported as a huge data leak targetting one of those potential sources, depending on what gets you the most clicks at the time. Currently ChatGPT. If their databases had been breached, I feel 100.000 wouldn't be the number.

Not saying it won't be, eventually. But this ain't it, it appears.

[–] Apostato@beehaw.org 9 points 1 year ago (1 children)

Lovely. Signing up for an openAI account requires a phone number too. I wonder if that was included in some of the logs

[–] kresten@feddit.dk 3 points 1 year ago

Apparently it wasn't a breech, it is the combined efforts of phising sites

[–] GuyDudeman@beehaw.org 6 points 1 year ago (1 children)

Of ducking course. And you know what that means? Peoples’ nsfw chats are going to be used for blackmail.

[–] mustyOrange@beehaw.org 4 points 1 year ago

I'd also worry about people who have corporate shit on there. Anyone who uses this as a tool should probably delete their chats and change their password, even if you don't have anything proprietary or ground breaking in there just as a precaution

[–] Los@beehaw.org 5 points 1 year ago (2 children)

Jokes on you, I used my work email. :p

[–] chemical_cutthroat@kbin.social 8 points 1 year ago (1 children)

Hello, this is Josh from your IT department. We are conducting a survey on password strength and need your input. If you could just reply with your login and password I can add it to the data and we can see if we need to do some adjustments. Thanks!

[–] wizard_cat@kbin.social 2 points 1 year ago
[–] Jamie@jamie.moe 1 points 1 year ago

I freaked out for a moment, then remembered I used SSO.

[–] DerpyPoint@kbin.social 5 points 1 year ago (1 children)

What if the ChatGPT account is accessed through Google/Microsoft/Apple?

[–] I_Miss_Daniel@kbin.social 2 points 1 year ago

I think that's a site specific password thing that can't be reused elsewhere, so shouldn't be a big deal.

[–] corytheboyd@kbin.social 4 points 1 year ago* (last edited 1 year ago)

Yikes, and I’m pretty sure they use auth0/okta. Much more worried about that being compromised than openai tbh

This is just the new version of leaked AWS access/secret keys.. bad guys dredge through any place a token could be disclosed (GitHub project, public log file, etc) and build a database of them for sale.. pretty bad given chat history is retained and available via API. Article points out the potential of information disclosure, which seems pretty significant..

[–] Eggyhead@kbin.social 3 points 1 year ago

Just checked my account. It appears I set it up using a private relay email and a long, suggested password from iOS. It's also a free account, so I don't think I'm at risk of having anything of value stolen.

[–] GhostMagician@beehaw.org 3 points 1 year ago

Glad I was paranoid enough to use a throw away email and burner number.

[–] trupi@kbin.social 3 points 1 year ago (2 children)

that’s why you always use two factor auth if site allows it

[–] ipkpjersi@lemmy.one 1 points 1 year ago

The funny thing is, ChatGPT did allow it, then a week or two ago they just removed it lmao

[–] argv_minus_one@beehaw.org 1 points 1 year ago* (last edited 1 year ago)

That's why you always use discipline in handling security credentials. Two factors won't save you if your lack of discipline gets both of them compromised.

And I don't appreciate other people's lack of discipline creating risks for me. Password databases and private keys can be backed up, but if I lose my phone for some reason, I also lose anything that depended on that phone for authentication.

[–] snarf@kbin.social 2 points 1 year ago

Passkeys can't come soon enough.

load more comments
view more: next ›