Discussion about this post

User's avatar
Snowyteller's avatar

You're already a glorious terror with finger on the pulse, now finger turns to machine enhanced grip.

How thrilling and disturbing!

Godspeed.

A thought beyond praise does occur, how do you reckon the brower would fair for a fellow that isn't as well versed in machine wrangling as you have become?

Phil Alethes's avatar

I haven't gotten much into AI, though I've found Brave's Leo a great help in researching. Of course, it has a PoV (as does everyone), so sometimes I must try other means of approaching a controversial subject.

The appearance of AI browsers looks interesting. I haven't tried Perplexity Comet or ChatGPT Atlas, as my older Mac won't run them. When I can find the time/energy (chronic illness slows me considerably), I plan to start experimenting with some FOSS OSes (Linux et al.), figured maybe by then these browsers will be available for them.

However, the latest newsletter from Private Phone Shop (https://privatephoneshop.com) gives me pause:

"Perplexity's browser exists to mine your data (they admitted it)

"OpenAI just released Atlas. Perplexity already launched Comet. Both are AI-powered browsers that promise to make your life easier by acting as your personal assistant.

"I’m talking about browsers that can read your emails, book flights, order products, and basically do anything you’d do online. Sounds convenient, right?

"Here’s the problem. These aren’t browsers. They’re surveillance tools with a chat interface.

"OpenAI’s Atlas collects far more data than any other browser on the market. It records which sites you visit, remembers their content through browser memories, and observes what you read, how long you stay, and what you do next. The Electronic Frontier Foundation tested it. Atlas memorized queries about sexual and reproductive health services, including the name of a real doctor.

"OpenAI says Atlas won’t remember details about your medical care. But it already did. And you have to trust they’ve fixed it.

"Don’t get me wrong, OpenAI implemented some controls. But their own security chief admitted that prompt injection attacks remain largely an “unsolved security problem” across all AI platforms. This is where it gets worse. Malicious websites can embed hidden commands that manipulate the AI’s behavior. You visit what looks like a normal shopping site, and invisible instructions tell Atlas to scrape personal data from your open tabs (your medical portal, your draft emails, your bank account, whatever).

"LayerX Security found an exploit that allows attackers to inject malicious instructions into Atlas’s persistent memory and run arbitrary code. The corrupted memory persists across devices and sessions. It survives even if you switch browsers. In tests against over 100 real web vulnerabilities and phishing attacks, Edge stopped 53%, Chrome stopped 47%, but Atlas only stopped 5.8%. You’re literally 90% more exposed than if you just used Chrome.

"Perplexity’s CEO isn’t even trying to hide it with Comet. He openly stated that collecting your data was one of the reasons they created a web browser. Not improve your experience. Collect. More. Data.

"When you use Comet, it collects browsing history, URLs of pages you visit, text and images from those pages, your search queries, download records, and cookies from websites. All of this gets processed to “provide and improve Comet and recommend relevant content.” Translation: they’re building a profile on you for advertising.

"LayerX researchers found a vulnerability called CometJacking. A single malicious link can hijack the AI assistant, turning your trusted browser into a spy that steals your data. The attacker’s command disguises stolen data by encoding it in base64 to bypass security checks, then sends it to a remote server. When LayerX reported this to Perplexity? Perplexity replied they could not identify any security impact and marked it as “Not Applicable.”

"They don’t care.

"Once an AI connects the dots, removing one piece of data does not erase the story it’s already built. You can delete individual memories. The inferences remain. These aren’t bugs. The risk is structural. You’re giving a corporation full visibility into your digital life. And with features that 'learn your habits to keep you organized,' in a business context this means collecting patterns related to sensitive workflows, project details, or competitive intelligence.

"If you’re wondering whether you should try these browsers, here’s my answer: don’t. Keep your banking, work, and personal accounts far away from AI browsers. Use them as a test environment if you must, but treat them like what they are. A privacy disaster waiting to happen.

"You don’t need an AI assistant watching everything you do online. You need a browser that respects your privacy and a phone that doesn’t report back to google."

-----------------------------------------

I went to EFF (https://www.eff.org) but didn't find anything about testing Atlas. I guess they haven't written it up, but a Brave search (https://search.brave.com/search?q=EFF+tested+OpenAI+Atlas+browser&summary=1) found numerous articles about it.

I haven't gotten into enhanced privacy either, but Private Phone Shop offers both what look to be good devices (with Linuxes installed) and lots of helpful information.

2 more comments...

No posts

Ready for more?