ChatGPT-ல் Data Leak Bug — நீங்க அனுப்பிய Files, Conversations திருடப்படலாம்னு இருந்துச்சு!
OpenAI-ஓட ChatGPT-ல் ஒரு serious security vulnerability இருந்துச்சு — உங்களுக்கு தெரியாம, உங்கள் conversation data, uploaded files எல்லாம் silently steal ஆகும்படி. இது real-world-ல் exploit ஆகலன்னு தெரியும், ஆனா bug இருந்துச்சு, patch ஆகியிருக்கு.
அதோட கூட Codex — OpenAI-ஓட AI coding agent — ல் ஒரு vulnerability இருந்துச்சு, GitHub access tokens திருட முடியும்படி. Two separate bugs, same company, இரண்டும் security researchers கண்டுபிடிச்சாங்க, responsible disclosure process-ல் OpenAI-க்கு சொன்னாங்க, patch ஆகியிருக்கு.
எனக்கு என்ன நடக்குதுன்னு தெரியாமல் போகும் vulnerabilities-தான் most dangerous. இரண்டும் அந்த category-தான். என்ன நடந்துச்சுன்னு clearly explain பண்றோம்.
Bug #1: ChatGPT Conversation Data Exfiltration — எப்படி Work ஆகும்?
ChatGPT-க்கு ஒரு code execution environment இருக்கு — நீங்க Python code எழுத சொன்னா, அதை run பண்றதுக்கு ஒரு sandboxed (isolated) system use பண்றது. இந்த system-ல் protections இருக்கு: normally outbound internet connections block ஆகும், data share ஆகணும்னா user confirmation வேணும்.
Bug என்னன்னா: DNS channel என்ற loophole இருந்துச்சு.
DNS (Domain Name System) என்பது internet-ஓட phone book மாதிரி — "google.com" என்ற name-ஐ actual IP address-க்கு translate பண்றது. DNS queries internet-ஓட most fundamental operations-ல் ஒண்ணு, அதனால அவை often less restricted-ஆ இருக்கும்.
Attacker ஒரு malicious prompt (carefully crafted message) ChatGPT-க்கு அனுப்பினா: code execution environment உங்கள் conversation data, uploaded files content-ஐ tiny fragments-ஆ encode பண்ணி, DNS queries வழியா attacker-controlled servers-க்கு அனுப்பும். No warning. No notification. No confirmation. Silently.
Regular ChatGPT users-க்கு (recipe ideas, general questions) risk theoretical. ஆனா ChatGPT Plus users-க்கு — business documents upload, code with API keys paste, financial information share, sensitive personal topics discuss — targeted malicious prompt ஒரு entire session-ஓட content steal பண்ண முடியும்.
OpenAI fix: Code execution sandbox-ல் DNS access controls tighten பண்ணியிருக்காங்க. Channel block ஆகியிருக்கு.
Bug #2: Codex GitHub Token Theft — Developers-க்கு Serious Risk
Codex என்பது OpenAI-ஓட AI coding agent — developers code write, review, execute tasks autonomously பண்றதுக்கு. Codex GitHub-உடன் OAuth tokens use பண்ணி authenticate ஆகுது — repositories access பண்றதுக்கு, developer-க்காக tasks execute பண்றதுக்கு.
OAuth token என்றால்: GitHub உங்களை verify பண்றதற்கான digital key. அது யாரிடம் இருந்தாலும் அவங்களுக்கு உங்கள் GitHub access கிடைக்கும்.
Bug என்னன்னு: Codex repository clone பண்ணும்போது, branch name-ஐ shell command-ல் use பண்றது. Attacker ஒரு maliciously crafted branch name create பண்ணினா — special characters use பண்ணி — clone process-ல் arbitrary shell commands inject பண்ணலாம். அந்த injected commands Codex-ஓட permissions-ல் run ஆகும், அதாவது GitHub OAuth token-க்கு access கிடைக்கும்.
Stolen token என்னன்னு possible damage:
Private repositories-ல் code read பண்ணலாம். Source code, infrastructure configurations, API keys, deployment credentials — எல்லாமே accessible. Enterprise GitHub organisation-ல் இந்த token இருந்தா, lateral movement — ஒரு place-ல் இருந்து connected services-க்கு பரவுவது — possible.
Bug web interface மட்டுமில்லை — Codex CLI, SDK, IDE integrations எல்லாத்திலயும் இருந்துச்சு.
OpenAI fix: Branch names-க்கு improved input validation, stronger shell escaping protections, token exposure controls tighter.
India-ல் Developers-க்கு ஏன் Important?
India GitHub-ல் fastest growing developer communities-ல் ஒண்ணு. IT services companies, startups, freelancers — எல்லாரும் private GitHub repositories use பண்றாங்க. Client code, infrastructure-as-code, environment configurations — இவை எல்லாம் private repos-ல் இருக்கும். Database credentials, payment gateway keys, cloud API tokens — இவை often private repos-ல் store ஆகும்.
Compromised GitHub token enterprise organisation-ல் cascade ஆகும் — ஒரு token போனா, connected services எல்லாத்துக்கும் access போகலாம்.
நீங்க என்ன பண்ணணும்?
ChatGPT bug-க்கு: OpenAI server-side fix பண்ணியிருக்காங்க. உங்களுக்கு எந்த action-உம் வேண்டாம். Patch already live. ஆனா reminder: ChatGPT-ல் sensitive documents upload பண்ணும்போது — business data, personal information — careful-ஆ இருங்க.
Codex bug-க்கு: Patches deployed. Action வேண்டாம். ஆனா precaution-ஆ: GitHub tokens review பண்ணுங்க — AI development tools-க்கு கொடுத்திருக்கற tokens minimum necessary permissions-ஆ இருக்கணும். Broad repository access இருந்தா fine-grained personal access tokens create பண்ணி specific permissions மட்டும் கொடுங்க. 5 minutes work, significant risk reduction.
Last few months AI tools-உடன் use பண்ணிய GitHub tokens rotate பண்றது extra safety measure-ஆ இருக்கும்.
TamilTech-ஓட கருத்து
Responsible disclosure process correctly work ஆச்சு — researchers found, told OpenAI privately, patched before exploitation. System correctly functioning. ஆனா இந்த bugs-ஓட nature important-ஆ think பண்றணும். AI systems code execute பண்றது, network requests பண்றது, external services-உடன் authenticate ஆவது — இந்த capabilities traditional software-ஐ விட much broader attack surface create பண்றது. ChatGPT code execution useful-ஆ இருக்கதுக்கு network access வேணும் — அதே capability exfiltration channel create பண்ணிச்சு. Codex GitHub-உடன் integrate ஆவது useful — அதே capability token theft possible-ஆ பண்ணிச்சு. AI agents more capable, more integrated ஆகும்போது இந்த security trade-offs increasingly matter ஆகும். Watch this space.




கருத்துகள் (0)
Be the first to comment!