Security researchers have revealed that OpenAI is conducting cross-site user tracking through its advertising platform internally known as 'bazaar.' When users visit ChatGPT, the client generates a random identifier and obtains a JWT tied to the user's account. Subsequently, the client retrieves a cookie named __obi across sites. When users visit third-party websites that have installed OpenAI's ad pixel, this cookie links the user's browsing behavior to their ChatGPT account, enabling OpenAI to access the user's web browsing activities, even those unrelated to inputs in ChatGPT. This discovery has garnered widespread attention and reached the third position on the HackerNews trending list.
