Researcher: ChatGPT's __obi cookie links your off-site shopping data back to your account
新智元 · wechat · 2026-09-21
Independent researcher Buchodi published an investigation (573 points on HN) showing that on Android Chrome, ChatGPT plants a year-long obi cookie under .openai.com with SameSite=none. OpenAI's ad-tracking pixel on merchant sites like Chewy, Wayfair and HelloFresh sends that cookie back along with page paths, countries, cities and plaintext ZIP codes, potentially tying your off-site browsing and purchases to your ChatGPT account.
Key findings: logged-out users get a device-level anonymous ID that persists 27 days; the cookie is classified under the "data analytics" toggle, so turning off "advertising" doesn't block it; Safari and iOS users are unaffected; and the researcher can only prove data reaches OpenAI's servers, not that it is actually joined to accounts. OpenAI did not directly answer his questions. The technique mirrors Facebook's Pixel era, but merging chat history with off-site shopping data into one account is a new privacy frontier.
Related event: ChatGPT Accused of Cross-Site Tracking via __obi Cookie(3 posts)→
More from Safety
- ZuckOff App Detects Nearby Meta Smart Glasses via Bluetooth Fingerprints, Tops 5,000 Downloads — LexiLove · 2026-09-21
- New paper: simple difference-of-means vectors detect reward hacking from LLM internals before it happens — burny_tech · 2026-09-21
- DeepSeek Web Output Style Reportedly Lobotomized by Safe Harbor RLHF — Old_Let6328 · 2026-09-21
- MacBook IMU side channel leaks keystrokes with up to 97.5% accuracy — chaumian · 2026-09-21
- Six principles for thinking about AI risk: the AI Snake Oil case against doom — binarybits · 2026-09-21
- KDE Drafts AI Policy: Use LLMs, But Don't Tell Anyone — carsonfarmer · 2026-09-21