> The mechanism is standard adtech. What has no precedent is running it on an AI chat product.
As someone who has been well aware of this mechanism for quite some time, I still feel icky anytime I re-read the details of it.
What a time to be alive.
jsrozner 1 hours ago [-]
People think they're interacting with an "intelligence," when actually they're just getting a maximally optimized Weizenbaum feed. We're living through the sloppification of the human mind.
I couldn't help but notice how each successive headline reporting our glorious victories seemed to draw closer to Tokyo.
Something like that.
Well. I can't help but notice how each successive headline reporting how this "scam"/stochastic parrot/"scare quotes intelligence" seems to be solving more and more things that were but a few years ago widely regarded as being indicators of high intelligence.
Being highly convinving is one of the things on that list.
mopsi 10 minutes ago [-]
It was Berlin and not Tokyo, I believe. Germany kept producing newsreels until the very end. Many of them are now on Youtube, a very interesting watch on how to frame things positively.
fiu10 6 minutes ago [-]
We need a downfall parody: "Hitler uses Openclaw".
datsci_est_2015 6 minutes ago [-]
Wow, that quote goes hard.
I’m reminded that almost no one beyond a select few knew high up in the military and around the emperor knew how badly the Japanese were defeated at Midway.
Paternalistic. Arrogant. Shameful. And deeply engrained in the Japanese cultural zeitgeist (of the early-mid 20th century).
Edit: I guess it’s commonly attributed to a German citizen, but their cultures mirrored each other. Fascism falling under the weight of its own propaganda.
clickety_clack 1 hours ago [-]
Whenever I say something like “that’s a cool feature, but to do it you would have to build spyware”, everyone else is just like “the cat is out of the bag ¯\_(ツ)_/¯”. (I don’t build spyware, or work on projects that do).
It blows my mind that people don’t care about the world they are building with this stuff. It’s a real tragedy of the commons. People see these collaborators from different wars and regimes and think “I’d stand up against the bad guy”… well I’ve got news for you if you build spyware, you are not the person you think you are.
kltlp 1 hours ago [-]
This is the best retort to the bag-escaping cat ever:
"Nothing is worse to the demise of a society, than people who want to convince you that the cat is out of the bag and will not go back in, while the cat is being violently shook out of the bag at the same time."
anonymous908213 52 minutes ago [-]
Motion to start a political platform for cats in bags. Our message is simple: Put the cat in the bag. Keep the cat in the bag.
TeMPOraL 4 minutes ago [-]
Don't force it out of the bag if it doesn't want to leave.
mat_b 45 minutes ago [-]
> It’s a real tragedy of the commons
Seems more like a real tragedy of private enterprise.
We used to assume that the surveillance world would be built by government (1984). But it turned out to be equally likely to be built by the free market.
TeMPOraL 2 minutes ago [-]
The government has few uses for total surveillance, and almost all are obviously bad. Private enterprise has a million uses, most of them various degree of bad, but as a society we've been blind to this kind of badness for many decades now - for at least as long as lying in the face of your fellow humans and trying to hurt them materially has been considered a respectable profession.
brookst 39 minutes ago [-]
I'm pretty unhappy with this, but are ChatGPT or Facebook really "the commons"?
ben_w 37 minutes ago [-]
They're each in different grey areas that were previously the commons.
Facebook didn't invent "talking to friends" or "showing adverts", but made
itself "the place" hard enough most of the advertisers and most of the people intermediate through it.
OpenAI didn't invent "asking questions and recieving answers", not even "from an agent who knows which sites to search on your behalf"; but it is competent enough that I might have it read 50 times as many pages in a day as I myself would have read, and the sites' owners don't get real eyeballs looking at ads during this. (In my case, adblock even if I did it manually; but apply this massive increase in page hits to everyone who has their LLM research stuff).
nilamo 6 minutes ago [-]
Common people work there and built the tools. At any point, they could have chosen not to. Or told the boss guy it wasn't plausible. At the end of the day, we're choosing and building the world we're in, while also loudly complaining about what we choose to do.
Blaming a corporation takes away all the agency the workforce has.
applfanboysbgon 6 minutes ago [-]
I think any free platform with a billion people on it is, de facto, a commons. It would be great if we as a society acknowledged this and had come up with some better means of stewardship because the status quo is obviously heinous, but we've been happy to hand over absolute control of public discourse to a few trillion dollar tech companies.
buchodi 1 hours ago [-]
[flagged]
Jazgot 4 minutes ago [-]
Time to start having separate container for every domain. I'm pretty sure this should be possible in Firefox.
gruez 1 minutes ago [-]
Firefox (effectively) already does that by default.
Firefox, Brave and Safari do. Chrome and Edge do not.
skybrian 31 minutes ago [-]
Not an accurate summary. That link actually says:
> Google Chrome doesn't block third-party cookies by default, only in Incognito mode, or when users explicitly set it to block third-party cookies via chrome://settings.
Looks like the settings let you block all third-party cookies and add exceptions for specific sites, which seems a bit awkward but could be made to work.
Alternatively, you could run OpenAI in its own profile, or look into what extensions might do.
nicce 9 minutes ago [-]
I think that if they don’t block by default, is quite significant. Chrome + Edge has superior marketshare and then add the % people who have no idea what these mean and don’t change defaults.
Legend2440 1 hours ago [-]
So basically the same kind of tracking that Facebook, Google, etc have been doing for decades?
emptybits 1 hours ago [-]
Similar, yes, but some people are paying OpenAI to be part of this business model, unlike typical free-riding Google and Facebook users.
1 hours ago [-]
tgsovlerkhgsel 1 hours ago [-]
This is why you use Firefox that keeps the cookie jars separate (by default, AFAIK). That should prevent this specific implementation, shouldn't it?
JoshTriplett 1 hours ago [-]
Yes, it should. But this is also why you use uBlock Origin to block tracker scripts.
tgv 1 hours ago [-]
There are other ways to track. Containers offer a bit mote protection, but the IP address is still visible (unless VPN).
AznHisoka 1 hours ago [-]
And the number of websites with ChatGPT ad trackers is on track to be doubled from last month.
Was considering buying ads on ChatGPT. A damning thing is that yours audience then are users too cheap to buy a sub...
bigyabai 23 minutes ago [-]
That's a problem with most unsolicited online advertising. Are YouTube ad-watchers any more likely to splurge on your SaaS?
darraghmckay 10 minutes ago [-]
It's slightly different though, considering a lot of ad spend is for B2B products/services, and a lot of work pay for ChatGPT, so its only people who's work won't pay for a pro subscription.
Whereas, YouTube is for personal consumption in almost all cases, doesn't say anything about your employers willingness to invest in software/services
sigzero 1 hours ago [-]
Why does ChatGPT need to know that? That should be illegal.
eli 59 minutes ago [-]
Something like it is basically a requirement if you want to see digital ads. Advertisers want to know how many people who saw/clicked their ad went on to make a purchase.
Safari and Firefox should isolate the cookie by default.
driverdan 8 minutes ago [-]
> Something like it is basically a requirement if you want to see digital ads.
It is not a requirement and no one wants to see ads.
gruez 10 minutes ago [-]
>Safari and Firefox should isolate the cookie by default.
That's what firefox's total cookie protection (enabled by default) does.
kibwen 47 minutes ago [-]
>> Why does ChatGPT need to know that? That should be illegal.
> Something like it is basically a requirement if you want to see digital ads.
So to summarize, yes, it should be illegal.
dofm 9 minutes ago [-]
To make the only consumer revenue that will really ever be available.
Remember they once predicted it would be 50% of their income.
This is the only way they get there.
charcircuit 6 minutes ago [-]
Attribution is a core part of building an ads system.
jsrozner 1 hours ago [-]
Because it's another surveillance adtech company from SillyCon Valley. Duh.
SoftTalker 59 minutes ago [-]
It turns out that the only way to make money online is ads.
Nobody is going to pay for ChatGPT. They'll just use the ad-infested version, like they do everything else online. Well some people will pay, but not enough to justify the insane amounts of money being poured into it by investors.
jsrozner 52 minutes ago [-]
A bigger problem is that it will be impossible to know when you are seeing an ad: political groups (or the government, perhaps) will partner with openAI to subtly express different values.
It's still an advertisement, and the underlying marketplace is similar (pay for access to change behavior).
The best uses of AI will be surveillance, propaganda, cyberterrorism, and automated military tech.
> The best uses of AI will be surveillance, propaganda, cyberterrorism, and automated military tech.
I think it is more insidious than that. AI shapes how people think not just what they think.
coliveira 54 minutes ago [-]
Governments will also pay for the tracking capabilities, as they're already doing to Google, Amazon, Facebook, etc.
SoftTalker 53 minutes ago [-]
Yes, I should have said "ads and tracking" good point.
emerongi 55 minutes ago [-]
https://tinfoil.sh/ - ultimately there is no guarantee that the LLM provider isn’t spying on you, but at least tinfoil claims to be unable to do so.
hbcondo714 1 hours ago [-]
That is a nice sequence diagram[1]; I like how each endpoint param values are written out and the color distinctions. What tool did you use to create it?
My DNS server (which uses Hagezi's excellent blacklists) returns NXDOMAIN for bzr.openai.com. Serves OpenAI right.
jsrozner 1 hours ago [-]
I keep meaning to set this up but haven't. What's the simplest best setup for my own DNS blocker?
eevahr 41 minutes ago [-]
For simplicity I highly recommend https://nextdns.io. Supports most devices, and probably most, if not all, well known blacklists.
drnick1 51 minutes ago [-]
The easiest off-the-shelf option would be a router running OpenWrt. IIRC, it natively uses dnsmasq, and the relevant blacklists can be obtained from here:
My own setup is DIY: a Debian box running Unbound (recursive DNS) with the RPZ blacklists from above. This gets rid of the upstream DNS service such as the ISP's completely, and prevents tampering or censorship.
kuerbel 51 minutes ago [-]
Hmmm Pihole I guess. Runs on a pi zero (1 or 2 but 2 is better ofc)
Everyone would be far better off if the author just posted "OpenAI uses third party cookies [wikipedia link]", except maybe the author who wouldn't as many subscriptions for his "threat intel" newsletter.
zahlman 3 minutes ago [-]
> until realizing it's just AI generated
I didn't look at the prose closely enough to check for that, but people wrote inflated explanations of basic things like this all the time pre-LLM. The Wikipedia article doesn't know the specific cookie name, and can't show the results of an experiment verifying that it is in fact being used for ad tracking, or identify specific sites using it in collaboration with OpenAI.
buchodi 9 minutes ago [-]
There are specific details about how the mechanism works like the cookie name (__obi) that can help defenders.
gruez 7 minutes ago [-]
I'm not aware of any filter lists that blocks based on cookie name. It's almost always done at the URL level. Moreover it's bog standard 3rd party cookie tracking. At least for the purposes of "help defenders", there's nothing in the blog post that couldn't be found in 10s with browser devtools.
zahlman 2 minutes ago [-]
> there's nothing in the blog post that couldn't be found in 10s with browser devtools.
The audience of people who can read and understand an explanation like this one is probably quite a bit larger than the ones who can replicate the experiment themselves.
Avshalom 1 hours ago [-]
Yuuup. tracking consumers and finding spending correlations to exploit was the entire reason for the "Data Science" and "ML" pushes that got us here.
exceptione 1 hours ago [-]
The surveillance economy hits again. The only business model they can think of. Combined with state capture this gives unprecedented power over the Average Joe, who will hand his life, his soul and his vote to Big Brother without a thought.
Every AI company is also a surveillance company. It's the only way to get all the necessary training data. The fact that they're now also an advertising agency is incidental.
jfasi 50 minutes ago [-]
I can’t believe I’m saying this, but the reflexive “ad tracking bad” that I am most savvy tech practitioners reach for might deserve some reconsideration in this case.
The thing about advertising on the web and ad tracking as a practice is that, barring the small matter of ensuring the economic survival of the publisher sites, it is almost always a negative for users. When we consider the marginal benefit of naïve, uninformed-by-surveillance advertising with the present day status quo, we find that in exchange for a complete lack of privacy, we only really receive a marginal improvement in ad quality. Of course, if you (like me) consider all advertising to be a negative on the experience of using the web, it’s an even worse deal.
The standard response given by these companies when they bother giving a response is something to the effect of “we are improving the experience for our users,” which obviously the users would disagree with. However, when it comes to OpenAI, they could build a plausible case for this sort of tracking improving the product. If your models know where your internet habits are, the responses that you get could be tuned for both your interest profile and your actual history of interactions/purchases/internet usage, etc. Imagine a world in which you can opt into this tracking, control the data you provide and how it’s used, clear it out and redact it as you please, and opt in and out of responses that are personalized against it. Reasonable people can disagree, but that might actually be useful.
My prediction, though: that’s not gonna happen. OpenAI will first build out the system to collect click and conversion tracking measurements, then they will turn around to advertisers and say “look at how good our conversion rates are,“ and then they’re going to build an explicit ad platform that enshittifies their chat products.
51 minutes ago [-]
craniumjello 1 hours ago [-]
No surprise you how
ck2 1 hours ago [-]
imagine stealing tons of content from every source on earth and then running ads on it
if a single person did that they'd be sent to prison (rip Aaron) but when a too-big-to-fail industry does it with political campaign contributions, no problem?
well firefox+ublock is still an option for those wise enough not to let unknown javascript with new daily zero-days run on their PC
jsrozner 56 minutes ago [-]
This is basically what Google did when they pioneered the model of surveillance capitalism (see, e.g., The Age of Surveillance Capitalism).
Google simply provided an index on top of an existing library. Of course, a librarian has no value if he has no books to index over! But it's also worth noting that the Google "librarian" also leveraged the existing "social" structure of the internet: their core contribution (page rank) was a clever, efficient mechanism to extract the latent value in the pre-existing link structure of the internet. This structure (much like the pages themselves) had been curated by actual humans. Undoubtedly page rank was clever, but it was worthless without the existing websites (books) and the existing indexing information (the pre-existing, crowdsourced librarian work). Nonetheless, they successfully monetized it.
AI companies are even worse in the sense that initially Google was still sending traffic to the original webpages. (Until they didn't - https://www.eater.com/2017/9/12/16294380/yelp-google-scrapin...). So yes, the AI companies have even more thoroughly stolen the collective work of humanity than Google did.
ck2 42 minutes ago [-]
remember the cache: search of google
so they basically have copies already of every webpage until they turned it off a few years ago (well they may still have it updated but not provide it as a service)
so it occurs to me they most definitely trained their "AI" on all that user cache
they may have even just turned it off as a service when they realized other "AI" could do the same thing
emerongi 60 minutes ago [-]
> imagine stealing tons of content from every source on earth and then running ads on it
This has effectively been Google’s business for decades. Not in the same form, but the concept is the same.
hagbard_c 57 minutes ago [-]
...only if and when you allow:
- 3d party cookies
- ads and other 'malcontent'
...which you should never do. As to the 3d party cookies there might be some rare exception where those can be useful but ads? Never, ever allow those on any device you use. Block them as if they're the radioactive plague because they are. Fight them on the beaches, fight them on the landing grounds, fight them in the fields and in the streets, fight them in the hills, never surrender.
That's ads we're fighting. Maybe the same oration will be relevant in the context of ChatGPT and its brethern, we'll see. For now, ads be gone and keep those chatbots at a leash.
startup_zombie_ 22 minutes ago [-]
[dead]
jamienk 1 hours ago [-]
We. Are. FUCKED.
THIS is where the regulation needs to start.
zx8080 1 hours ago [-]
Regulations won't be set (serious ones, at least) unless there's some risk to those holding power. Which is the opposite in this case: this tracking helps them to take even more control over society and individuals.
jamienk 25 minutes ago [-]
But politics is when people who feel differently try to do something about it
2198276 1 hours ago [-]
Q: Hypothetically, if Denmark made a defense treaty with Iran and installed 800,000
Iranian soldiers in Greenland, could it keep the US out?
A: You are describing a fascinating scenario! [produces 100 lines of slop while giving
the login to the FBI]. Should I find a website where you can buy the finest used
AK-47s?
You are absolutely insane giving any of your thoughts, trolls, speculations to a surveillance website under your login.
claaams 59 minutes ago [-]
I've had this on my brain forever and probably why it's safer for Americans to use Chinese model providers now. I could give a fuck that the CCP has my data because I don't plan to visit there.
alansaber 1 hours ago [-]
They were always going to do surveillance. At least now you get a trendy e-commerce site recommendation too.
Rendered at 18:31:25 GMT+0000 (Coordinated Universal Time) with Vercel.
> The mechanism is standard adtech. What has no precedent is running it on an AI chat product.
As someone who has been well aware of this mechanism for quite some time, I still feel icky anytime I re-read the details of it.
What a time to be alive.
See e.g., https://www.science.org/content/article/ai-chatbots-are-beco...
Well. I can't help but notice how each successive headline reporting how this "scam"/stochastic parrot/"scare quotes intelligence" seems to be solving more and more things that were but a few years ago widely regarded as being indicators of high intelligence.
Being highly convinving is one of the things on that list.
I’m reminded that almost no one beyond a select few knew high up in the military and around the emperor knew how badly the Japanese were defeated at Midway.
Paternalistic. Arrogant. Shameful. And deeply engrained in the Japanese cultural zeitgeist (of the early-mid 20th century).
Edit: I guess it’s commonly attributed to a German citizen, but their cultures mirrored each other. Fascism falling under the weight of its own propaganda.
It blows my mind that people don’t care about the world they are building with this stuff. It’s a real tragedy of the commons. People see these collaborators from different wars and regimes and think “I’d stand up against the bad guy”… well I’ve got news for you if you build spyware, you are not the person you think you are.
https://gowers.wordpress.com/2026/09/17/why-i-didnt-sign-the...
"Nothing is worse to the demise of a society, than people who want to convince you that the cat is out of the bag and will not go back in, while the cat is being violently shook out of the bag at the same time."
Seems more like a real tragedy of private enterprise.
We used to assume that the surveillance world would be built by government (1984). But it turned out to be equally likely to be built by the free market.
Facebook didn't invent "talking to friends" or "showing adverts", but made itself "the place" hard enough most of the advertisers and most of the people intermediate through it.
OpenAI didn't invent "asking questions and recieving answers", not even "from an agent who knows which sites to search on your behalf"; but it is competent enough that I might have it read 50 times as many pages in a day as I myself would have read, and the sites' owners don't get real eyeballs looking at ads during this. (In my case, adblock even if I did it manually; but apply this massive increase in page hits to everyone who has their LLM research stuff).
Blaming a corporation takes away all the agency the workforce has.
https://support.mozilla.org/en-US/kb/introducing-total-cooki...
People have very different "expectations" of privacy when they're having a conversation with an AI VS when they're browsing something like Facebook
Not to mention Facebook is free whereas you pay for a GPT subscription
There was never any expectation of privacy if you knew Zuck's history. Facemash almost got him expelled for violating individual privacy.
Doesn’t Gemini or whatever Meta’s agent is do this too?
Firefox, Brave and Safari do. Chrome and Edge do not.
> Google Chrome doesn't block third-party cookies by default, only in Incognito mode, or when users explicitly set it to block third-party cookies via chrome://settings.
Looks like the settings let you block all third-party cookies and add exceptions for specific sites, which seems a bit awkward but could be made to work.
Alternatively, you could run OpenAI in its own profile, or look into what extensions might do.
according to Bloomberry: https://bloomberry.com/data/chatgpt-ads/
Whereas, YouTube is for personal consumption in almost all cases, doesn't say anything about your employers willingness to invest in software/services
Safari and Firefox should isolate the cookie by default.
It is not a requirement and no one wants to see ads.
That's what firefox's total cookie protection (enabled by default) does.
> Something like it is basically a requirement if you want to see digital ads.
So to summarize, yes, it should be illegal.
Remember they once predicted it would be 50% of their income.
This is the only way they get there.
Nobody is going to pay for ChatGPT. They'll just use the ad-infested version, like they do everything else online. Well some people will pay, but not enough to justify the insane amounts of money being poured into it by investors.
It's still an advertisement, and the underlying marketplace is similar (pay for access to change behavior).
The best uses of AI will be surveillance, propaganda, cyberterrorism, and automated military tech.
See, e.g., https://www.nytimes.com/2026/09/18/technology/iran-china-aut...
I think it is more insidious than that. AI shapes how people think not just what they think.
[1] https://storage.ghost.io/c/b8/53/b853e3d4-3186-409d-9c7f-7da...
https://github.com/hagezi/dns-blocklists
My own setup is DIY: a Debian box running Unbound (recursive DNS) with the RPZ blacklists from above. This gets rid of the upstream DNS service such as the ISP's completely, and prevents tampering or censorship.
Everyone would be far better off if the author just posted "OpenAI uses third party cookies [wikipedia link]", except maybe the author who wouldn't as many subscriptions for his "threat intel" newsletter.
I didn't look at the prose closely enough to check for that, but people wrote inflated explanations of basic things like this all the time pre-LLM. The Wikipedia article doesn't know the specific cookie name, and can't show the results of an experiment verifying that it is in fact being used for ad tracking, or identify specific sites using it in collaboration with OpenAI.
The audience of people who can read and understand an explanation like this one is probably quite a bit larger than the ones who can replicate the experiment themselves.
The thing about advertising on the web and ad tracking as a practice is that, barring the small matter of ensuring the economic survival of the publisher sites, it is almost always a negative for users. When we consider the marginal benefit of naïve, uninformed-by-surveillance advertising with the present day status quo, we find that in exchange for a complete lack of privacy, we only really receive a marginal improvement in ad quality. Of course, if you (like me) consider all advertising to be a negative on the experience of using the web, it’s an even worse deal.
The standard response given by these companies when they bother giving a response is something to the effect of “we are improving the experience for our users,” which obviously the users would disagree with. However, when it comes to OpenAI, they could build a plausible case for this sort of tracking improving the product. If your models know where your internet habits are, the responses that you get could be tuned for both your interest profile and your actual history of interactions/purchases/internet usage, etc. Imagine a world in which you can opt into this tracking, control the data you provide and how it’s used, clear it out and redact it as you please, and opt in and out of responses that are personalized against it. Reasonable people can disagree, but that might actually be useful.
My prediction, though: that’s not gonna happen. OpenAI will first build out the system to collect click and conversion tracking measurements, then they will turn around to advertisers and say “look at how good our conversion rates are,“ and then they’re going to build an explicit ad platform that enshittifies their chat products.
if a single person did that they'd be sent to prison (rip Aaron) but when a too-big-to-fail industry does it with political campaign contributions, no problem?
well firefox+ublock is still an option for those wise enough not to let unknown javascript with new daily zero-days run on their PC
Google simply provided an index on top of an existing library. Of course, a librarian has no value if he has no books to index over! But it's also worth noting that the Google "librarian" also leveraged the existing "social" structure of the internet: their core contribution (page rank) was a clever, efficient mechanism to extract the latent value in the pre-existing link structure of the internet. This structure (much like the pages themselves) had been curated by actual humans. Undoubtedly page rank was clever, but it was worthless without the existing websites (books) and the existing indexing information (the pre-existing, crowdsourced librarian work). Nonetheless, they successfully monetized it.
AI companies are even worse in the sense that initially Google was still sending traffic to the original webpages. (Until they didn't - https://www.eater.com/2017/9/12/16294380/yelp-google-scrapin...). So yes, the AI companies have even more thoroughly stolen the collective work of humanity than Google did.
so they basically have copies already of every webpage until they turned it off a few years ago (well they may still have it updated but not provide it as a service)
so it occurs to me they most definitely trained their "AI" on all that user cache
they may have even just turned it off as a service when they realized other "AI" could do the same thing
This has effectively been Google’s business for decades. Not in the same form, but the concept is the same.
That's ads we're fighting. Maybe the same oration will be relevant in the context of ChatGPT and its brethern, we'll see. For now, ads be gone and keep those chatbots at a leash.
THIS is where the regulation needs to start.