@flyingpenguin@infosec.exchange
Post #4322532
2026-08-02 06:29 UTC
@Trikkitt@mastodon.social @briankrebs@infosec.exchange Someone built it, pointed it, pulled the trigger, and kept the dead carcass. Every scanner since the 1980s knows this.
OpenAI had no legal basis to ingest names, policy numbers, and IBANs. GDPR has no exemption for personal data that happens to be reachable. Reachable is not public, and public is not lawful to process.
The proof is in OpenAI's own response: it confirmed the data would not be used for training. You don't promise disposal of something you were entitled to hunt and kill.
Attacker is the mild term. The precise one under GDPR is unlawful processor, and that one carries fines.
Replies (1)
-
@Trikkitt@mastodon.social 2026-08-02 06:40
@flyingpenguin@infosec.exchange @briankrebs@infosec.exchange you're making a lot of assumptions without knowledge of what has actually happened. OpenAI confirmed the data has been deleted, we have no way to know if it was deleted only after they were notified or if they automatically deleted it when their crawler processed it. To use the term attacker implies that malicious actions were taken in order to obtain the data. That doesn't appear to be the case here.