Researcher Says OpenAI’s Ad System Links ChatGPT Accounts to Cross-Site Browsing
Summary
A security researcher says OpenAI has built a cross-site advertising tracking chain through an internal platform code-named Bazaar. According to the report, opening ChatGPT causes the client to generate a random identifier and obtain a JWT token linked to the user’s account. The system then writes a cross-site cookie named __obi. When the user later visits third-party websites carrying OpenAI advertising pixels, browsing activity can be associated with the user’s ChatGPT account. The reported linkage does not depend on what the user has typed into ChatGPT: browsing a site with the relevant pixel could be enough to connect activity to the account. The report therefore alleges that OpenAI’s user profiling may extend beyond ChatGPT conversations into browsing activity across participating sites. The discovery reached third place on Hacker News and prompted discussion among developers. The article does not provide a response from OpenAI or establish the full scope, duration, or legal status of the alleged tracking.