/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers detail how a side channel can be used to read encrypted responses from AI assistants, except Google's Gemini; OpenAI and Cloudflare made mitigations

All non-Google chat GPTs affected by side channel that leaks responses sent to users.  —  AI assistants have been widely available …

Ars Technica Dan Goodin

Context & Ripple Effects

This report adds a transport-layer privacy problem to contemporaneous scrutiny of AI-assistant safeguards: earlier coverage found limited protections against election-disinformation generation in Gemini and ChatGPT. The distinction matters because this issue concerns the confidentiality of responses in transit rather than what a model is willing to generate.

Google's Gemini is the reported exception, while OpenAI and Cloudflare had already moved to mitigate exposure. That makes implementation choices around delivering assistant output—not only model behavior—a security differentiator.

First-order effects

  • Users of affected non-Google chat assistants face potential exposure of responses despite encryption if the side channel is exploitable in their delivery path.
  • OpenAI and Cloudflare must operate and validate their mitigations; Gemini's reported immunity gives Google a narrower immediate exposure on this specific issue.

Second-order effects

  • AI-assistant providers and the infrastructure companies serving them will face pressure to review encrypted-response handling, especially where customers assume transport encryption alone protects output confidentiality.
  • Security comparisons among assistant platforms will increasingly turn on the surrounding application and delivery stack, not just the model's safety controls.

Third-order effects

  • If similar flaws recur, AI security evaluation is likely to broaden from model misuse and prompt defenses to end-to-end confidentiality across the systems that deliver model output.
  • The episode points toward AI services being assessed as integrated applications: a strong model-level control may not offset weaknesses in network, browser, or infrastructure layers.

The trend: As AI assistants become routine interfaces, their security posture is increasingly determined by the full delivery stack as much as by the model itself.

Discussion

  • @quinnypig Corey Quinn on x
    Honestly, with all the slap and tickle companies are playing with service terms around AI sharing, “don't tell the chatbot anything you wouldn't want to be public” is good advice.
  • @cmiller__ Caleb Miller on x
    Yikes. You probably shouldn't be trusting remote chatbots with sensitive info anyways, but beware of eavesdropping now, despite the encryption. I assume this could be fixed with smart token padding, or batching. Hopefully a solution is rolled out soon. https://arstechnica.com/...
  • r/cybersecurity r on reddit
    Hackers can read private AI-assistant chats even though they're encrypted
  • r/singularity r on reddit
    Hackers can read private AI assistant chats even though they're encrypted |  Ars Technica |  All non-Google chat GPTs affected by side channel that leaks responses sent to users
  • r/technews r on reddit
    Hackers can read private AI assistant chats even though they're encrypted