Security researchers uncover openai's cross-site tracking system via ChatGPT
Security researchers have discovered that OpenAI has implemented a cross-site tracking system through its internal advertising platform, 'bazaar.' When users access ChatGPT, the platform generates a random identifier and issues a JWT token tied to the user's account, storing it in a cross-site cookie named '__obi.' This cookie functions as an identity marker, linking users' browsing activity on third-party websites with their ChatGPT accounts.
Notably, this tracking occurs even if users have never engaged with ChatGPT's features, as browsing behavior on sites with OpenAI ad pixels is collected regardless of chat activity. The revelation has sparked significant discussion in the developer community and has ranked third on HackerNews' popular list.
The findings highlight how OpenAI's tracking extends beyond the chat interface, incorporating a vast array of web activity into user profiles.