ChatGPT's Computer History faces a significant privacy issue.
The feature retains interaction data on a local basis, but OpenAI has indicated that those files are not encrypted.
OpenAI has previously explained how the Computer History feature in ChatGPT allows the Mac app to track user activities across applications and websites. It does this by logging interaction events such as clicks, typing, and switching apps, rather than capturing screenshots or recordings. However, a troubling aspect highlighted in OpenAI's official documentation is that the files storing this history are not encrypted.
Your Mac history is saved in plain text
According to OpenAI, the Computer History feature temporarily keeps interaction events on the Mac and removes those files after 48 hours. It then generates local memories as plain-text Markdown files. Notably, OpenAI explicitly mentions that these files are not encrypted and may be accessible to other programs running under the same macOS user account.
This is significant because the Computer History feature aims to provide a comprehensive overview of a user's activities on their Mac, similar to Microsoft’s Recall feature for Windows. It does not capture the screen, audio, or video, but the interaction data can still indicate which applications and websites were used, what documents were interacted with, and potentially other sensitive actions.
The main concern lies in what may already be on the Mac
The primary risk does not necessarily come from someone breaching ChatGPT. Instead, it could stem from malware or other malicious applications already operating under the same macOS user account. If that software can access the local files, the absence of encryption could offer it an additional source of information regarding the user's activities.
There is also a broader issue with providing AI systems this much context. Malicious instructions embedded in websites or other content could potentially impact what an AI perceives in its history, heightening the risk of prompt injection in addition to the fundamental data exposure.
Fortunately, Computer History is an opt-in feature, and OpenAI provides users with options to exclude specific apps and websites as well as to delete entries. This approach is certainly more favorable than covertly recording everything. However, the documentation clearly points out the trade-off: the more ChatGPT retains about your Mac, the greater the likelihood of sensitive information being left behind. And when that data is not encrypted, it's a consideration that merits careful thought prior to activating the feature.
Other articles
ChatGPT's Computer History faces a significant privacy issue.
ChatGPT's latest Computer History feature keeps Mac activity stored locally; however, OpenAI has cautioned that these files are not encrypted and could potentially be accessible to other applications.
