TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Over 100k ChatGPT Account Credentials Made Available on the Dark Web

170 点作者 _bohm将近 2 年前

25 条评论

munchausen42将近 2 年前
Ok so to summarize: Credentials have been stolen using a rather common malware from some people that didn&#x27;t protect their computers properly. A subset of those credentials were related to OpenAI - while at the same time this malware (or malware like this) is used to steal gmail-, outlook-, amazon-, facebook- and all other kinds of credentials of services where potentially sensitive information is often entered.<p>Wow, we really are at the point where you just need to insert &quot;ChatGPT&quot; into some boring random headline to make it news :)
评论 #36421098 未加载
评论 #36421357 未加载
评论 #36420875 未加载
评论 #36422665 未加载
评论 #36421193 未加载
评论 #36420551 未加载
评论 #36420682 未加载
FrameworkFred将近 2 年前
I can admit to smirking a little when I read the article, knowing that some bad actor in the world has spent even a little time and attention poring over my collection of stupid chats, looking for valuable corporate secrets, and finding that each and every one of my conversations ends with &quot;now express this as a limerick.&quot;
评论 #36421635 未加载
评论 #36420547 未加载
评论 #36420229 未加载
评论 #36420328 未加载
评论 #36420392 未加载
Eisenstein将近 2 年前
It seems to me that this these are credentials harvested from malware on people&#x27;s machines, not credentials stolen from OpenAI. The relevance to ChatGPT is only because people use the chats for personal&#x2F;business info and the logs are retained.
评论 #36419934 未加载
评论 #36419961 未加载
评论 #36420533 未加载
schappim将近 2 年前
Title buried the lede: OpenAI has not been breached. Credentials were stolen from infected computers.
miketery将近 2 年前
While yes an annoyance, we should reflect on how far we&#x27;ve come when this type of thing causes little to no disruption.<p>Most of us use unique passwords, a smaller portions uses unique emails per account, and in the future we will use public keys (passkeys).<p>Security is getting better I&#x27;m optimistic.<p>However we have to continue to push on providing as little information to these companies (i.e. they don&#x27;t need my name, DOB, etc.). And in the future I look forward to where I store this information, and provide it just in time as needed for the specific use cases (i.e. it might be processed and checked by a 3rd party but it&#x27;s never stored).
评论 #36419697 未加载
评论 #36419811 未加载
TheRealPomax将近 2 年前
A ChatGPT account has your email address, and a password, so unless folks are using ChatGPT to discuss their personal information against the warning you get every single time you log in, this is mostly just more proof that everything you log into will be hacked. Which isn&#x27;t really news. Unfortunately, what it&#x27;s <i>not</i> is an article that explains how &quot;what they got&quot; translates into &quot;and this is what they could do with that data&quot;, so I&#x27;m not sure I understand the value of this data. What ramifications would this have for folks whose account got compromised?
评论 #36419726 未加载
评论 #36419967 未加载
评论 #36420459 未加载
Fervicus将近 2 年前
I feel like I am the only person not using ChatGPT due to privacy concerns. My conversations becoming public is half my concern. The other half is the information being used against me by companies&#x2F;government.
评论 #36420217 未加载
评论 #36420395 未加载
评论 #36420441 未加载
ineedasername将近 2 年前
It’s unclear from the article because it does not directly state the vector of attack, just the tools used. But it looks like this is <i>not</i> a breach of OpenAI systems, and instead is the product of malware on user machines that happened pickup ChatGPT credentials, among any other things it deemed valuable on the user’s machines. Is this a correct understanding?
rl3将近 2 年前
One feature OpenAI really needs is the ability to force logout accounts across all devices. It doesn&#x27;t have that currently, at least not with ChatGPT.<p>As of a month ago, sessions were still staying active even after a password change.<p>A little device&#x2F;session management portal would be nice. Pretty standard these days.
mpeg将近 2 年前
If your machine is compromised, OpenAI credentials are the least of your worries.
binarymax将近 2 年前
Has OpenAI started notifying people about the breach? I haven’t received anything. Does this mean my creds were not part of the leak or does it mean OpenAI isn’t disclosing anything?
评论 #36420225 未加载
评论 #36420197 未加载
评论 #36420219 未加载
mcmcfly将近 2 年前
Would be nice if users could actually register for 2FA.<p>&gt; <i>As of Monday, June 12 2023, new 2FA&#x2F;MFA enrollments are temporarily paused.</i><p><a href="https:&#x2F;&#x2F;help.openai.com&#x2F;en&#x2F;articles&#x2F;7967234-does-openai-offer-multi-factor-authentication-mfa-two-factor-authentication-2fa" rel="nofollow noreferrer">https:&#x2F;&#x2F;help.openai.com&#x2F;en&#x2F;articles&#x2F;7967234-does-openai-offe...</a>
activiation将近 2 年前
If only hackers could insert some fake data in my online accounts (hope they don&#x27;t read what I posted)
gexla将近 2 年前
It&#x27;s as if this is a trap to see who actually read and comprehended the article. 3rd paragraph in...<p>&gt; &quot;Logs containing compromised information harvested by info stealers are actively traded on dark web marketplaces,&quot; Group-IB said.<p>Though the 4th paragraph makes it more obvious.
droopyEyelids将近 2 年前
I wonder if these dark web account credential people ever get access to lexisnexus. That seems like a real sensitive data source that could be leaking a lot of stuff on people.
mensetmanusman将近 2 年前
I have been using iCloud&#x27;s new burner email feature recently, and signed up for the gpt pro account with it. My worries are low :)
jasonjmcghee将近 2 年前
I expect better of tomshardware.com - this is clickbait and I think this deserves a flag and shouldn&#x27;t be on the front page.
评论 #36422126 未加载
Havoc将近 2 年前
Very poorly written article. Hard to tell what exactly happened vs headline vs various parts of the body of text
jacknews将近 2 年前
Can I have one please?<p>OpenAI still &quot;not available in your country&quot;.
h0ek将近 2 年前
Would be cool to have 2fa there. But not available.
loufe将近 2 年前
If you&#x27;ve got a credit card attached to your account, remove it and change your password.
评论 #36420347 未加载
评论 #36419754 未加载
评论 #36419812 未加载
tmaly将近 2 年前
ChatGPT does offer 2FA<p>I use it.
coding123将近 2 年前
people still use passwords over oauth?
评论 #36422140 未加载
mehdix将近 2 年前
I think the AI gold rush has just begun, and we are yet to see much more.
axegon_将近 2 年前
Not entirely surprising. OpenAI has been lurking around the startup realm despite having the finance and people: for years they had no product to bring money in and they had to do something about it. ChatGPT was the perfect place to turn things around and they did. But often when you try to push a product to market, you are forced to cut corners. And in my experience, the most common corners to cut are tests and security. &quot;This is well more than enough&quot; is a very convenient way to lie to yourself and call it a job-well-done.
评论 #36419660 未加载
评论 #36420105 未加载
评论 #36419809 未加载