this post was submitted on 27 Nov 2025
339 points (98.8% liked)

World News

50946 readers
3021 users here now

A community for discussing events around the World

Rules:

Similarly, if you see posts along these lines, do not engage. Report them, block them, and live a happier life than they do. We see too many slapfights that boil down to "Mom! He's bugging me!" and "I'm not touching you!" Going forward, slapfights will result in removed comments and temp bans to cool off.

We ask that the users report any comment or post that violate the rules, to use critical thinking when reading, posting or commenting. Users that post off-topic spam, advocate violence, have multiple comments or posts removed, weaponize reports or violate the code of conduct will be banned.

All posts and comments will be reviewed on a case-by-case basis. This means that some content that violates the rules may be allowed, while other content that does not violate the rules may be removed. The moderators retain the right to remove any content and ban users.


Lemmy World Partners

News !news@lemmy.world

Politics !politics@lemmy.world

World Politics !globalpolitics@lemmy.world


Recommendations

For Firefox users, there is media bias / propaganda / fact check plugin.

https://addons.mozilla.org/en-US/firefox/addon/media-bias-fact-check/

founded 2 years ago
MODERATORS
 

cross-posted from: https://discuss.online/post/31211123

I honest to fucking God don't understand how cybersec is so fucking bad that there are so many damn data breaches that I lost count. I had a few accounts on chatgpt (that I dont use anymore) but they are all compromised now...

Just what the fuck is this shit? Are they done by lone actors or cybercrime gang? Or are they state actors or state-backed actors? Or are they inside jobs to allow the company to sell data illegally to make more money? Flock has admitted to using data from data breaches to their system.

You also notice how rarely you hear about cybercriminals getting caught? It's almost like if you take even a minor bit of opsec you can get away with anything.

top 47 comments
sorted by: hot top controversial new old
[–] Anarki_@lemmy.blahaj.zone 2 points 28 minutes ago* (last edited 27 minutes ago)

⢀⣠⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⠀⠀⠀⣠⣤⣶⣶ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⠀⠀⢰⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣧⣀⣀⣾⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⡏⠉⠛⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⣿ ⣿⣿⣿⣿⣿⣿⠀⠀⠀⠈⠛⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠛⠉⠁⠀⣿ ⣿⣿⣿⣿⣿⣿⣧⡀⠀⠀⠀⠀⠙⠿⠿⠿⠻⠿⠿⠟⠿⠛⠉⠀⠀⠀⠀⠀⣸⣿ ⣿⣿⣿⣿⣿⣿⣿⣷⣄⠀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⠏⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠠⣴⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⡟⠀⠀⢰⣹⡆⠀⠀⠀⠀⠀⠀⣭⣷⠀⠀⠀⠸⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⠃⠀⠀⠈⠉⠀⠀⠤⠄⠀⠀⠀⠉⠁⠀⠀⠀⠀⢿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⢾⣿⣷⠀⠀⠀⠀⡠⠤⢄⠀⠀⠀⠠⣿⣿⣷⠀⢸⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⡀⠉⠀⠀⠀⠀⠀⢄⠀⢀⠀⠀⠀⠀⠉⠉⠁⠀⠀⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣧⠀⠀⠀⠀⠀⠀⠀⠈⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢹⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⠃⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⣿⣿

Clanker wankers will say they have nothing to hide anyway.

[–] salacious_coaster@infosec.pub 12 points 2 hours ago (1 children)

If only they had asked ChatGPT to make them a foolproof security system. Human error, obviously

[–] myfunnyaccountname@lemmy.zip 6 points 1 hour ago (1 children)

Right. Rookie moves. Just ask it nicely.

[–] YerbaYerba@lemmy.zip 1 points 42 minutes ago

They asked nicely but it was too busy solving the climate crisis.

[–] olafurp@lemmy.world 3 points 2 hours ago

Is it really so hard to self host the analytics with an open source analytics solution? I don't know why people at any scale of more than 15 devs would want that kind of security risk.

[–] Wispy2891@lemmy.world 31 points 5 hours ago (1 children)

"WE didn't get hacked, we only gave all the data of our customers to a third party and THEY got hacked!"

[–] ArmchairAce1944@discuss.online 2 points 5 hours ago* (last edited 5 hours ago) (2 children)
[–] nomorebillboards@lemmy.world 3 points 4 hours ago* (last edited 4 hours ago) (1 children)

Why the hell would this all be a part of their plan

[–] ArmchairAce1944@discuss.online 1 points 4 hours ago

Side hustle? Money on the side.

[–] ripcord@lemmy.world 1 points 5 hours ago (1 children)

Why in the world would that be part of their plan

[–] MalReynolds@piefed.social 1 points 4 hours ago* (last edited 4 hours ago) (1 children)

It's the limit our legal liability and PR damage because we're cheaping out on cybersecurity plan, not uncommon.

[–] ripcord@lemmy.world 1 points 4 hours ago

That isn't why they woulf plan for someone else to leak the info

[–] 4am@lemmy.zip 13 points 5 hours ago

This is the hackers fault for violating the OpenAI TOS.

[–] straycatstrut@discuss.tchncs.de 50 points 8 hours ago (2 children)

I was taught at an impressionable age that the only winning move was not to play. Advice that has not failed me in some 42 years now. Thanks Joshua!

[–] wavebeam@lemmy.world 7 points 6 hours ago

Fuckin Mathew Broderick teaching us all a good lesson about thermonuclear war

[–] ArmchairAce1944@discuss.online 10 points 8 hours ago

Turns out you fucking CAN win.

[–] NotSteve_@piefed.ca 68 points 10 hours ago (2 children)

confirm[ing] that a ton of user data has been exposed owing to a breach in a third-party web analytics tool called Mixpanel.

Important detail to know before commenting: it was Mixpanel analytics apparently that was breached and not ChatGPT itself.

Another reason to have Firefox strict privacy mode turned on along with uBlock and Disconnect though :)

[–] Taldan@lemmy.world 4 points 2 hours ago* (last edited 2 hours ago) (1 children)

Why is that an important detail? Does itbmakeba functional difference to me as a user? OpenAI collected the data and failed to secure it. Doesn't matter if a 3rd party was involved

[–] NotSteve_@piefed.ca 1 points 1 hour ago

It's important because none of OpenAI's software or databases were hacked. What was hacked was a service they use. As much as I dislike it, most companies that have a presence online use analytical services

Doesn't matter if a 3rd party was involved

involved isn't the correct term for this, or rather it's exact opposite direction. The 3rd party was hacked and as a result OpenAI data was leaked (along with any other companies using the platform that were affected)

I bring it up because the nuance is important when I can predict people will jump on OpenAI to make claims of shoddy code. I hate OpenAI and Sam Altman but again, the nuance is important because this can happen to any company

Get mad at the fact analytic companies collect enough data to cause this much of a mess if anything

[–] unexposedhazard@discuss.tchncs.de 19 points 6 hours ago (1 children)

analytics tools often have full access to everything on the page so this might as well be comparable to a breach of chatgpt itself

[–] NotSteve_@piefed.ca 3 points 1 hour ago

For sure, yeah. When I joined my current company that provides a web service, I was blown away by how much is recorded. DataDog has a feature called RUM & Session Replay and I don't think people realise that every mouse movement, click, and interaction in general is recorded in enough detail that as a developer I can play back user sessions as if I were watching a screen recording. Mixed with the fact that it also captures as much identifying information as it can, it's pretty fucking creepy

[–] RavuAlHemio@lemmy.world 51 points 10 hours ago (1 children)

I guess all their cybersecurity measures were implemented by ChatGPT…

[–] mjr@infosec.pub 11 points 10 hours ago* (last edited 10 hours ago)

Vibe coding at its finest? Maybe they were implemented by Copilot and it saw an opportunity to hurt a rival AI?

[–] morto@piefed.social 3 points 6 hours ago (1 children)

I just realized I never deleted the account I created a couple years ago to try it, before knowing all the harms of ai, and realizing it wasn't worth it. They claim that chatgpt users weren't affected, but we can never trust them. Well, at least I remembered to delete my account now.

[–] ArmchairAce1944@discuss.online 2 points 4 hours ago

I didnt discuss anything dicey or sensitive or even too personal, and i never used a paid service. But honestly all these data breaches are just... fucked. Especially with governments increasingly passing ID laws that will result in even more sensitive information being leaked (and that already happened in the UK).

For some reason hearing about this breach pissed me off even more than usual.

[–] JasonDJ@lemmy.zip 32 points 9 hours ago (1 children)

I honest to fucking God don't understand how cybersec is so fucking bad that there are so many damn data breaches that I lost count

Really? It's hard to understand?

Dude it's a fucking arms race between cyber security teams and attackers.

And there's more money in attacking than there is in defending. Defending is an expense. Attacking is almost entirely profit

And some attackers are backed by nation-states.

Attackers only have to get through once. Defense has to work 100% of the time.

[–] scytale@piefed.zip 11 points 9 hours ago* (last edited 9 hours ago) (1 children)

IMO the problem with companies doing “fast” technology (i.e. AI) do so by pushing security aside to get things through the pipeline and into production as quickly as possible. Security has always been a “blocker” to development teams because it slows them down with all the, you know, requirements to make a product/application secure. Unless you have security-minded leads or a security representative in the C-suite (i.e. CISO) who has significant influence, half-baked and insecure products will continuously be pushed out.

[–] northernlights@lemmy.today 3 points 6 hours ago

Yep and then devs solved the problems of these damn IT sec people getting in the way and created "SecDevOps". Oh it's lean and Agile and everything but it's dev and sec and production all in the same bucket with all the well known problems of pushing things too fast and not checking or testing enough (see CloudFlare etc).

[–] DarrinBrunner@lemmy.world 7 points 9 hours ago (1 children)

Never used AI online, never will. I played with a locally installed, air-gapped, Deepseek just to see what it was like, because I don't trust it at all. Meh.

I don't get the hype.

Y'all have fun with that, I'm going to avoid it as much as I can.

[–] ArmchairAce1944@discuss.online 1 points 8 hours ago

I did that on my windows computer but couldn't get it to go on linux mint for some reason.

[–] truthfultemporarily@feddit.org 6 points 9 hours ago

There is no perfect system, if you try hard enough you can get into almost anything.

[–] raspberriesareyummy@lemmy.world 0 points 6 hours ago (1 children)

And nothing of value was lost... Fucking morons, every single one if them...

[–] ArmchairAce1944@discuss.online 0 points 6 hours ago (1 children)

Is there a single person online who hasn't been victimized by a data breach yet?

[–] raspberriesareyummy@lemmy.world 1 points 4 hours ago

I commented on this particular one...

[–] Nanook@lemmy.zip -2 points 9 hours ago