7 ms·
What did OpenAI do wrong here? As far as I can tell they're guilty of requiring logins?
by bestcoder69 3y ago
What did OpenAI do wrong here? As far as I can tell they're guilty of requiring logins?
- omeze 3y agoIt's not requiring logins per se -- this is the second mishap I'm aware of related to their consumer product surface area (the first being users' chat data going to other users). Just seems like a distraction, if the goal is to do fundamental AI research.
- lolinder 3y agoI think you're missing the point: this isn't a mishap that has anything to do with OpenAI. If you are a company that has usernames and passwords, then your login information is for sale because your customers have malware on their computers. OpenAI didn't do anything wrong here besides have a ton of users, many of which had malware on their computers. From the article: > However, the ChatGPT parent company clarified the compromised login credentials were not the result of any OpenAI data breach. Instead, they were the by-product of commodity malware-based log harvesting.
- owl57 3y ago> If you are a company that has usernames and passwords > didn't do anything wrong here besides have a ton of users Passwords aren't a trivial part of this. OpenAI offers login with Google/Apple/MS. Managing their own passwords as well wasn't a mandatory part of the product, but a trade off: they probably got more users, but also more complexity and risks.
- SV_BubbleTime 3y agoFederation has a privacy risk, and I fully support non-federated logins. But still no, a malware thst grabs passwords doesn’t mean you can blame a company for using passwords.
- warbeforepeace 3y agoHe didn't read the article. Headline and comment.