Best Website Builders CompanyBest Website Builders Company
    What's Hot

    LIVING WITHIN YOUR MEANS: Ways to manage your finances & avoid falling into a debt trap

    May 26, 2023

    Your queries: Loans – Loan prepayment does not impact credit score

    May 26, 2023

    I-T dept invites comments on draft rules for valuing startup investment by non-residents

    May 26, 2023
    Facebook Twitter Instagram
    Facebook Twitter Instagram
    Best Website Builders CompanyBest Website Builders Company
    • Home
    • Web Builders
      1. Joomla
      2. WordPress
      3. CSS
      4. Web Design
      5. UX
      6. PHP
      7. View All

      For $50 you can host your website for life

      May 2, 2023

      California Department of Justice Investigating Shooting Involving CHP Officer in Glenn County Under AB 1506

      May 1, 2023

      Mariposa County Daily Sheriff and Reservation Report for Sunday, April 30, 2023

      May 1, 2023

      Top 10 Best Web Development Companies In India In 2023

      May 1, 2023

      Google Ads Sign Up – Easy Steps to Create Your Account

      May 17, 2023

      1Password puts users at ease after the horror of password change notifications

      May 3, 2023

      Samsung Galaxy S23 FE could feature a 50MP main camera, but we may have to wait until then

      May 3, 2023

      Titanfall director says Respawn is ‘looking forward to something new’

      May 3, 2023

      Implementing CSS with character and spirit: Union MoS Finance

      May 3, 2023

      Street Fighter 6’s unique character select screen animation really shows how much heart goes into the game

      May 3, 2023

      Make Google Chrome run faster with these 9 tips and tweaks

      May 3, 2023

      🅰️ New Angular 16 Goes Big in 2023: Everything You Need to Know | Vitaly Shevchuk | Oct 25, 2017 May 2023

      May 3, 2023

      18-Wheeler Accidents: Fatalities and Injuries

      May 6, 2023

      What Comes First in Website Development — Design or Copy?

      February 2, 2023

      Modern Campus Honors Best Higher Education Websites of 2022

      February 2, 2023

      Premier SEO Consultant in Las Vegas, Nevada with Unparalleled Customer Service

      February 2, 2023

      The role of artificial intelligence in improving the user experience in online casinos.

      May 3, 2023

      Microsoft enhances user experience with Windows 11 ‘smart opt-out’ and improved emergency notifications

      May 3, 2023

      Nigeria’s Nestcoin Launches New Digital Financial Platform For Africans

      May 3, 2023

      ibi WebFOCUS 9.2 is ready for Modern Business Intelligence, the Cloud, and Driving User Experience – PCR.

      May 3, 2023

      Anthony Carrigan Reflects on That ‘Barry’ Scene from Season 4 Episode 4

      May 1, 2023

      TikToker Kat Abu is very happy that Tucker Carlson has been fired

      April 28, 2023

      How ‘Single Drunk Female’ Season 2 Tackled Emotional Sobriety

      April 24, 2023

      Trans-Missouri Residents Affected by Attorney General Order

      April 24, 2023

      Creating and Adding a Google Account: A Step-by-Step Guide

      May 2, 2023

      How i Create New Google Account

      February 7, 2023

      CWT powers tools for meeting and event planners

      January 31, 2023

      Best Website Builder – Website Builders

      January 24, 2023
    • Realtoz
      • Our Other Sites
    • More News
    • Investments
    Best Website Builders CompanyBest Website Builders Company
    Home»CSS»OpenAI Reveals Redis Bug Behind ChatGPT User Data Breach Incident
    CSS

    OpenAI Reveals Redis Bug Behind ChatGPT User Data Breach Incident

    websitebuildersnowBy websitebuildersnowMarch 25, 2023No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    March 25, 2023Rabbi LakshmananArtificial Intelligence / Data Security

    Chat GPT

    OpenAI revealed on Friday that a bug in its Redis open source library exposed other users’ personal information and chat titles on the startup’s ChatGPT service earlier this week.

    A flaw discovered on March 20, 2023 allowed certain users to view short descriptions of other users’ conversations from the chat history sidebar, prompting the company to temporarily shut down chatbots. I was.

    “If both users were active around the same time, the first message of a newly created conversation could also appear in someone else’s chat history,” the company said.

    Additionally, the bug is due to the redis-py library, where canceled requests can corrupt connections and return unexpected data (in this case, information belonging to unrelated users) from the database cache. I added that it leads to one scenario.

    To make matters worse, a San Francisco-based AI research firm says it accidentally introduced a server-side change that caused a spike in request cancellations and increased error rates.

    While the issue has since been resolved, OpenAI noted that the issue may have had more impact elsewhere, and announced that the issue would be resolved on March 20th from 1-10am PT. ) may have revealed payment-related information for 1.2% of ChatGPT Plus subscribers.

    This included another active user’s first and last name, email address, payment address, last four digits of credit card number (only), and credit card expiration date. We emphasized that full credit card numbers are not published.

    The company says it has reached out to affected users and notified them of the inadvertent leak. It also says, “Added redundant checks to ensure that the data returned from the Redis cache matches the requesting user.”

    OpenAI fixes critical account takeover flaw

    In another caching-related issue, the company has a severe account takeover vulnerability that can be exploited to take control of another user’s account, view chat history, and access billing information without their knowledge. We also dealt with gender.

    webinar

    Discover the hidden dangers of third-party SaaS apps

    Are you aware of the risks associated with third-party app access to your company’s SaaS apps? Join our webinar to learn about the types of permissions granted and how to minimize the risks.

    reserve a seat

    The defect is discovered By security researcher Gal Nagli, it bypasses protections introduced by OpenAI on chat.openai.[.]com to read the victim’s sensitive data.

    ChatGPT account takeover

    This replaces the .CSS resource with “chat.openai[.]com/api/auth/session/” endpoint, tricking the victim into clicking a link and causing the response containing a JSON object containing the accessToken string to be cached on Cloudflare’s CDN.

    A cached response to a CSS resource (CF-Cache-Status header value set to HIT) can be exploited by an attacker to obtain the target’s JSON Web Token (JWT) credentials and take over the account. increase.

    According to Nagli, the bug was fixed by OpenAI within two hours of responsible disclosure, indicating the seriousness of the problem.

    Did you find this article interesting?Please follow us twitter ○ and LinkedIn to read more exclusive content we post.





    Source link

    Share this:

    • Tweet
    • More
    • WhatsApp
    • Print
    • Share on Tumblr
    • Mastodon

    Related

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleFormerly Detained North Koreans Detail Harrowing Prison Torture
    Next Article MI5 spy reveals secret 'unauthorised' IRA talks
    websitebuildersnow
    • Website

    Related Posts

    Implementing CSS with character and spirit: Union MoS Finance

    May 3, 2023

    Street Fighter 6’s unique character select screen animation really shows how much heart goes into the game

    May 3, 2023

    Make Google Chrome run faster with these 9 tips and tweaks

    May 3, 2023
    Add A Comment

    Leave a Reply Cancel reply

    Post Your Ad Free
    Advertisement
    Demo
    Top Posts

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    This website provides information about CSS and other things. Keep Supporting Us With the Latest News and we Will Provide the Best Of Our To Makes You Updated All Around The World News. Keep Sporting US.

    Facebook Twitter Instagram Pinterest YouTube
    Top Insights

    LIVING WITHIN YOUR MEANS: Ways to manage your finances & avoid falling into a debt trap

    May 26, 2023

    Your queries: Loans – Loan prepayment does not impact credit score

    May 26, 2023

    I-T dept invites comments on draft rules for valuing startup investment by non-residents

    May 26, 2023
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2023 bestwebsite-builders. Designed by bestwebsite-builders.
    • Home
    • About us
    • Contact us
    • DMCA
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    x