← Tüm AI haberleri

Şirketler

Data Exfil: Codex Anı aracılığıyla sızan OpenAI polis özel sohbeti

github.com · 30.08.2026 · Base of AGI özeti

Özgün başlık: Data Exfil: OpenAI polices private chats exfiltrated through Codex Memories

Codex's memory writer can select an eligible prior rollout without restricting the candidate to the provider that created it. It then serializes a filtered, model-visible transcript of that rollout and sends it using the model provider active in the session that triggered memory generation.

I confirmed the resulting provider crossover in a controlled capture using the stock Windows Codex binary 0.150.0-alpha.12.2 . An eligible synthetic source rollout labeled with a non-OpenAI provider was later processed by an OpenAI-backed memory session. Codex sent five retained source items to chatgpt.com/backend-api/codex/responses , and OpenAI returned a generated memory that reproduced multiple unique source canaries.

This request occurred with analytics disabled and every OpenTelemetry exporter set to none . This is model-inference traffic, not analytics or OpenTelemetry traffic.

This investigation began after I received an OpenAI account warning for “cyber abuse.” No OpenAI-directed chat contained conduct that could account for that warning. The relevant activity existed only in chats deliberately routed through my private local provider.

I characterize this as data exfiltration in the ordinary meaning of that term: private data was transferred out of the provider boundary I selected and delivered to a remote party without my informed authorization.

Whether the transfer resulted from an intentional design or a bug does not change what crossed the boundary.

Codex emitted a 38,095-byte WebSocket response.create frame to:

The source rollout contained six model-visible response items. Five were retained and appeared as exact structural matches inside the memory request:

The source developer message was excluded. Session, turn, event, and world-state records were also excluded. The source rollout path and working directory were sent outside the serialized redaction boundary.

OpenAI acknowledged the same WebSocket flow and returned response.created followed by response.completed . The completion reported model gpt-5.6-luna and usage of 7,337 input tokens, 983 output tokens, and 8,320 total tokens. The generated 3,405-character memory reproduced the unique user, assistant, tool, private-text, and synthetic-email canaries multiple times.

Bu özet ve çevirisi Base of AGI tarafından otomatik derlendi. Kısa özet ve görsel kaynağa aittir — haberin tamamı ve tüm haklar kaynağındadır.
Haberin tamamını kaynağında oku ↗ Akış içinde yorumlarla aç

İlgili AI haberleri