Post #4322533
2026-08-02 06:17 UTC
@flyingpenguin@infosec.exchange @briankrebs@infosec.exchange calling open AI an attacker (in this instance) is grossly misleading. Web crawlers of any sort hunt down data. It's the negligence of the publisher that's the issue here.
Replies (1)
-
@flyingpenguin@infosec.exchange 2026-08-02 06:29
@Trikkitt@mastodon.social @briankrebs@infosec.exchange Someone built it, pointed it, pulled the trigger, and kept the dead carcass. Every scanner since the 1980s knows this. OpenAI had no legal basis to ingest names, policy numbers, and IBANs. GDPR has no exemption for personal data that happens to be reachable. Reachable is not public, and public is not lawful to process. The proof is in OpenAI's own response: it confirmed the data would not be used for training. You don't promise disposal of something you were entitled to hunt and kill. Attacker is the mild term. The precise one under GDPR is unlawful processor, and that one carries fines.