1Sep 20 11:18 AM · 4d ago · 1 article · 1 post · 2 sources · development 1 of 2
A report on buchodi.com, cross-posted to Hacker News, describes how chatgpt.com issues a 60-second JWT that is exchanged for a one-year __obi cookie sent cross-site to bzr.openai.com by advertiser pixel code, tying outside browsing to ChatGPT accounts; the author says findings were reproduced on-device and cross-checked against traffic from 936 advertiser pixels across 1,029 hostnames.
“I reproduced the full mechanism on my own phone, verified with two independent capture methods, and cross-checked against several months of observed traffic covering 936 distinct advertiser pixels across 1,029 hostnames.”
buchodi.com report author
OpenAIOperator of ChatGPT and its ad platform ("Bazaar")lmbbuchodi (buchodi.com)Independent researcher and report authornixCraftSecurity/tech commentator (Mastodon)
The whole story articlespoststhe bright band is this development · numbered dots are the others · click one to jump